Live data from Hacker News

Deliveroo users are getting defrauded

newstatesman.com

161–170 of 354 posts

Re: Deliveroo users are getting defrauded

#161
post #60

I'm not surprised by this response from Deliveroo. Their focus lately has definitely moved away from customer satisfaction. I discovered recently that drivers are allowed - without penalty - to reject an order when they reach the pickup location if they see the receipt and decide it is too far to travel [1]. As a customer you just see your food go: `Assigning Driver -> Driver En Route to Pickup -> Driver Arrived at P…

I think I’m old fashioned but I just don’t understand the appeal of these food delivery services. My friend’s son uses Postmates to order fast food and it seems absurd to me. I must be missing something about theses services given their popularity. Do you mind explaining why you use them?

I think I’m old fashioned but I just don’t understand the appeal of these food delivery services.

"Old-fashioned"? Nice try, Grandpa. I'm approaching retirement, and delivery of restaurant food has been a thing since before I was born. Hell, Domino's was founded in 1960.

Re: Deliveroo users are getting defrauded

#162

“Deliveroo takes online security very seriously. Sadly fraudsters rely on the fact that people reuse the same passwords on multiple online services to try and gain entry to different accounts across the web.” Yeah! Blame it on your customers! Way to go! Sigh! Another gig economy service I'm damn sure never to use.

That's not even an excuse. There are solutions out there that mitigate the fact people reuse the same passwords.

I'd love to see a more specific version of Troy Hunt's "have I been pwned" API which explicitly blocked user/password combinations which had been leaked.

The catch is, you'd have to store the pairs together which then makes you a target, so in practice the best you can really do is what's on offer already -- check that the password hasn't been leaked (and maybe if the email address has a high HIBP leak count).

That solution would seem to force people into password managers and random high-entropy passwords or passphrases...

Re: Deliveroo users are getting defrauded

#163
Calling the police seems like an important thing the author didn't seem to do. This is not a nuisance, it's a crime. I am less interested in fining Deliveroo, rather I would like to see them forced to cooperate with law enforcement to prosecute thieves.

Re: Deliveroo users are getting defrauded

#164
Maybe I'm missing the point but how did the fraud take place to begin with? Somebody fished the author's Deliveroo account and used it to buy a lot of food? If so what would be the right way for Deliveroo to solve the issue? I mean if they just swallow the cost and reimburse her with no questions asked it seems easy to abuse, I could just order a lot of food then later complain that my account has been breached. Then again that's pretty much what Amazon does in these situations in my experience but not everybody has Amazon's deep pockets...

That's not to say that their current response (or lack thereof) isn't bad, it's more that I'm not sure what would be a good response in this situation.

I'm also not sure how Deliveroo could be considered liable if the breach is on the user's side (phished password) rather than a server-side vulnerability. If I offer an online service and one user gets their password stolen, would I be liable for that? If so, what should I do if somebody claims that their account was stolen? What if they're actually lying to get access to a legit account?

Re: Deliveroo users are getting defrauded

#165
post #17

This is poor form from Deliveroo - their fraud detection seems particularly lacking, and fobbing customers off for months at a time is not good enough. However the article is unnecessarily sensationalist in banding around GDPR data breaches. Much of the article intimates there has been a Deliveroo data breach, whereas in fact the most likely explanation is attackers reusing passwords leaked from other breaches. This…

Also the hackers managed to change the user's email, which Deliveroo could have easily prevented by sending an email first to the original email address. It's hard to prevent people from using bad passwords, but there are a few easy things they can do to prevent hackers from completely taking over accounts.

I've seen a few services which do this as a matter of course. Sadly few allow the email address change to be rescinded without a customer-service call. By that point, the account may already be in fraudulent use.

Re: Deliveroo users are getting defrauded

#166
post #157

Another good reason to use a fintech bank account such as Monzo [1] or a credit card such as Tandem [2] or a virtual card that can forward transactions onto any other card such as Curve [3]. All of these services can give you a push notification every time a transaction is made on your account so that you are immediately made aware and are able to cancel them. You can block the card from within the app immediately. 1…

Amex has the same thing and their customer protections are generally better than the Fintech companies. Although Amex is not so common in the U.K. Do any UK credit card companies offer consumer and fraud protection above the norm? Amex would immediately side with me if I showed them the Deliveroo communication. Another Citi VISA I had offered 18 months warranties on laptops and other electronics if I used the card.

The only one I've needed to claim against was Curve. I lost my wallet and my card was used in a McDonalds. I knew immediately and froze the card. Curve then refunded me a week later, when I contacted them.

Thanks for letting me know about Amex doing this. Might provide better customer service and many places do accept it.

Re: Deliveroo users are getting defrauded

#167
post #164

Maybe I'm missing the point but how did the fraud take place to begin with? Somebody fished the author's Deliveroo account and used it to buy a lot of food? If so what would be the right way for Deliveroo to solve the issue? I mean if they just swallow the cost and reimburse her with no questions asked it seems easy to abuse, I could just order a lot of food then later complain that my account has been breached. Then…

Standard security practices: not allow delivery to a new address without reconfirming credit card details, sending email confirmation upon login from a new location/device, and in the more extreme cases, 2 factor auth.

Re: Deliveroo users are getting defrauded

#168

Another good reason to use a fintech bank account such as Monzo [1] or a credit card such as Tandem [2] or a virtual card that can forward transactions onto any other card such as Curve [3]. All of these services can give you a push notification every time a transaction is made on your account so that you are immediately made aware and are able to cancel them. You can block the card from within the app immediately. 1…

I agree. I'd also add that my experience with fintech services, in regards to fraud detection, has been excellent.

I've been using Revolut for the past year. Just 2 weeks ago, they detected a potential fraudulent transaction with - you guess it - Deliveroo, for an amount of £25 (I don't live in the UK). The transaction, as well as my card, was immediately blocked. I then received a push message asking me to confirm whether the transaction was fraudulent - pushing "Confirm" triggered the expedition of a new card to my address. In contrast to legacy banks for which it is still recommended you call on the phone to notify you're going abroad, this is excellent service.

Re: Deliveroo users are getting defrauded

#169
post #60

I'm not surprised by this response from Deliveroo. Their focus lately has definitely moved away from customer satisfaction. I discovered recently that drivers are allowed - without penalty - to reject an order when they reach the pickup location if they see the receipt and decide it is too far to travel [1]. As a customer you just see your food go: `Assigning Driver -> Driver En Route to Pickup -> Driver Arrived at P…

I think I’m old fashioned but I just don’t understand the appeal of these food delivery services. My friend’s son uses Postmates to order fast food and it seems absurd to me. I must be missing something about theses services given their popularity. Do you mind explaining why you use them?

There are certain things that really don't make sense for delivery, like McDonald's. I could drive there, go through the drive-thru, and be home by the time someone else is picking it up. Most other restaurants do make sense for online ordering and delivery. Most of the time I just go and get the food myself as I'm usually just too cheap to pay the delivery fee and tip and longer wait. I'll order pickup and can go get it myself for a couple bucks of gas at most and at least I'll know it's as hot and fresh as it can be.
Post reply on HN