Live data from Hacker News

Deliveroo users are getting defrauded

newstatesman.com

111–120 of 354 posts

Re: Deliveroo users are getting defrauded

#111
post #87

Earlier quoted context omitted.

This doesn't work in Germany, for example. If you charge back, they'll just put you into a central register (called Schufa) that will basically make it impossible for you to get a credit or even to rent an apartment.

It's not a charge back in that sense when you report fraud or card theft. And I suppose that the effect you describe results from abusive requests from charge backs. I doubt you will be refused a mortgaged because you were a victim of theft in the past...

> I doubt you will be refused a mortgaged because you were a victim of theft in the past...

Don't be so certain about this. The credit reporting agencies are evil, nasty blackboxes and it is not transparent how your score is influenced, even by fraudulent stuff.

Re: Deliveroo users are getting defrauded

#112
post #81

Earlier quoted context omitted.

> I can't remember every giving explicit consent for this and AFAIK under GDPR just covering this in a Privacy Policy is not enough. I don't believe Deliveroo is obligated to tell you who they send such information to. They are however obligated to tell you that they gather such information and, should they share it with a third party, ensure that said third party is GDPR compliant and sign a data processing agreemen…

Actually, under the GDPR, they must gain permission to process your information for any marketing purposes. This should be on an opt-in basis. Sounds like an issue to me.

No, it's not that clear cut. This is the relevant text:

https://gdpr-info.eu/art-6-gdpr/

Specifically, section 1 (b) and all of section 4. Deliveroo clearly needs location data; that they happen to be sending it to Braze is fine if they signed a DPA. So the question is, is the data sent to Braze exclusively for marketing? More critically: If it is collected regardless of consent, does marketing-specific processing still follow consent? (Collecting data is a more specific type of data processing)

As I said there's probably a good case to be made that the data sent is too accurate.

I'll note that I'm a bit cynical here since these are fairly minor issues compared to the much more egregious shit GDPR sets out to fix. There's definitely a potential cleanup there, but like, every single company has nasties like these hiding under the carpet. The regulation itself doesn't help these cases much unless people act on them and demand the cleanup.

Re: Deliveroo users are getting defrauded

#113
post #49

Earlier quoted context omitted.

But what you going to do with 3 £100+ takeaway orders back to back? You can hardly resell it!

You can find some places that would take fake order in exchange of easy money. Or create a shadow platform where people people can order on Deliveroo with crypto currencies.

Now you’ve gone from petty theft and wire fraud and tacked on criminal conspiracy and god knows what else. This could easily get someone 10 years in jail, right?

Not even that hard to investigate because there’s a complete paper trail after a fraud is reported of what was ordered, who delivered it, and where it was delivered.

Re: Deliveroo users are getting defrauded

#114
post #4

Earlier quoted context omitted.

From my experience with Deliveroo, you can pretty much order at any address, wait for the delivery person at the doorstep and retrieve your order without actually living there.

But what you going to do with 3 £100+ takeaway orders back to back? You can hardly resell it!

>but what you going to do with 3 £100+ takeaway orders back to back

Eat it.

When I was in college if the pizza guy was in the lobby (invariably trying to call someone who wasn't picking up their phone) very long it was customary to ask him what he was delivering and buy it if you wanted it.

Re: Deliveroo users are getting defrauded

#115
post #98

Fun fact about Deliveroo. A lot of your drivers aren't the registered driver. It's really common practice for a citizen or someone with a work visa to register and then rent their phone to someone desperate with no work visa. So your driver is often making almost nothing while someone else sits on their ass and collects cash for doing nothing and then Deliveroo again sits on their ass providing poor service collectin…

> It's really common practice for a citizen or someone with a work visa to register and then rent their phone to someone desperate with no work visa Do humans really have such low morality and ethics? I just can't picture a person who does this to another human being...

Sadly, disavowal doesn’t make it any less true.

Re: Deliveroo users are getting defrauded

#116

Earlier quoted context omitted.

I've started using privacy.com after I saw a post here on HN about it. It's pretty nice. Basically you link up your bank account and they create debit cards for any online vendors you use, and you can set limits, destroy cards etc. I usually put monthly / transactional limits. Like with Uber Eats I know I only spend x amount, if anybody tried to use my Uber Eats card for 100 USD it would decline it. But also it locks…

> I've started using privacy.com Which is US only. Is there anything like it for the UK?

Not sure about multiple cards, but Revolut give you a virtual debit card you can turn off and on, put restriction on, etc.

Re: Deliveroo users are getting defrauded

#118
I am wonder if good fraud detection is one of things routinely ignored by unicorns trying to get explosive growth. First, we had ridersharing companies where drivers could start rides without their customers. Then were digital wallets getting hacked left, right and center (in India).

Re: Deliveroo users are getting defrauded

#119

Earlier quoted context omitted.

UK banks are already very good about refunding fraudulent transactions and associated fees: https://www.fca.org.uk/consumers/unauthorised-payments-accou... "In most cases the bank must refund the payment without undue delay and by the end of the business day following the day on which it became aware of the problem, unless it has reasonable grounds for suspecting that you have acted fraudulently." "When your bank ref…

I would be very careful on this one. Some providers are interestingly stubborn when it comes to charge backs and can hold on to the (fraudulent) vendors side even if you're clearly right. Monzo in the UK is a prime example for that. An internet vendor charged me more than he should and refused to void the transaction (basically text-book fraud) and I filled for a charge back with monzo. I was extremely confident that…

You didn’t file for a chargeback with Monzo, because they don’t offer credit cards. There’s less protection generally with debit cards.

Generally guidance is that you are entitled to a refund from the bank only if you did not authorise a particular transaction.

Re: Deliveroo users are getting defrauded

#120
post #9

By the sounds of it this is a simple credential reuse attack (it's even states as such in the article) so I really don't see where these accusations of a "data breach", and "encryption, which appears not to have been in place” come from. If these fraudulent transactions are the result of credential reuse I really don't see the GDPR violation here.

Don't see it either. Nobody said there was an actual breach. Of course a change of delivery address/email/phone or when combined with unusual orders (large amounts) should be flagged and cause 2FA or some other mechanism to request confirmation to the account holder of record.
Post reply on HN