4 ms·
"One use case provided is that a customer service worker walks away from their computer and then a roommate grabs the machine to use its internal search tool an
by mister_tee 5y ago
"One use case provided is that a customer service worker walks away from their computer and then a roommate grabs the machine to use its internal search tool and see what a celebrity has been buying on Amazon. But just four cases have actually been identified in which imposters accessed such data. And the result for workers of implementing the software is a constant feeling that someone is watching over them."
Not to backseat design (ok, to backseat design), but shouldn't it be the case that access would already be scoped to accounts relevant to active tasks, and not every one of the 300M+ active customer accounts, especially without some sort of escalation or break-glass? That rationale for this software is likely invented, right?
"It’d be one thing if these workers were well paid, but they’re not."
quick survey -- this would still be put on the "bad ways to treat your workers" list, correct?
- BiteCode_dev 5y agoRight, no need for a keylogger for that, your computer should be activated by your badge, which you need to move around.
- jjulius 5y agoThe quote in question mentions a roommate using the computer, implying working from home. No need for a badge to move around your own residence.
- BiteCode_dev 5y agoYeah but similar techniques can be used. Like a yubikey with fingerprints to do important things, a bt ring that needs to be close to the computer to keep it unlocked, etc. The idea is that you can solve the problem without having to spy in your employees every move, and focus on securing important operations.
- lupire 5y agoIf your roommate has your laptop, they probably have your yibikey.
- BiteCode_dev 5y agoDefinitly no. My laptop may lie around in my absence, my key is on my keyring and I take it when I close the door to go outside. Besides, even in the unlikely event they have the key, they still don't have my fingerprints to activate it. This also doesn't address the BT ring. If you have to worry about your room mate acquiring all of that, your threat model doesn't allow for remote work as the adversary will bypass the keylogger too. You are working for a retailer, not the militaries.
- mattlondon 5y agoAgreed. That sort of data should not just be a few clicks away and with only a reliance on honesty and will power to stop abuse. You need to have this sensitive data locked down appropriately so that people cannot just unilaterally access it on a whim. There should be an audit trail back to some rationale for access (e.g. support case) that enables access, and if the data is sensitive enough it should use multi-party auth. Keyloggers are not going to stop someone who is using someone else's computer already - they are WHY they are using someone else's computer!
- bpodgursky 5y agoIf you think about how phone support works, it would be pretty challenging to prevent the support staff from being able to access an arbitrary account. You'd have to set up a system where the phone tech could not access the account data unless the customer relayed the right name, SSN, or whatever other validation that they were the right person (people forget passwords!). But this means you need to be able to look up an account by some kind of PII, or at least ask the customer to cite some recent purchases (to prove ownership)... in which case the tech has to be able to see the purchases to validate them! Anyway, I'm sure there's some path here to make it mostly possible, but I don't think it's easy and I'm sure it's a higher-friction customer support experience.
- dannyw 5y agoThis is trivial to solve: only initiate phone calls using your own backend. get the customer to request an immediate call. Even better, callbacks on demand mean no hold music. Just waiting time for the call.
- mister_tee 5y agoyes, I sort of assumed--maybe incorrectly--that these employees/contractors handle chats and calls that were initiated from the help center and a logged-in account. agree with grandparent that incoming cold calls would be more challenging in terms of both authenticating the caller (some places I've called just seem to match phone number) and limiting access to information.
- corobo 5y agoI still lock my machine whenever I get up and I live alone This sounds like someone's solving a lack of training with code
- meibo 5y agoYou only write code once, Amazon replaces its entire expendable workforce once a year.