Live data from Hacker News

Deliveroo users are getting defrauded

newstatesman.com

291–300 of 354 posts

Re: Deliveroo users are getting defrauded

#292
post #273
post #52

Earlier quoted context omitted.

> This is basically the sole "feature" of credit cards I value. Any time I'm buying something from > somewhere that might act poorly, I use a credit card for the free leverage I have in a disagreement. But without a credit card, they wouldn't even have been able to get your money without authorisation. I don't see how something like this would have been possible with a system that requires explicit authorisation per…

> But without a credit card, they wouldn't even have been able to get your money without authorisation. I don't see how something like this would have been possible with a system that requires explicit authorisation per payment. I don't understands your point. Are you saying the ideal scenario would be to fill the cards information each time? The fact that it's a credit card doesn't change that it was prefilled, a de…

They could require the CVV when delivering to a new address - it's only three digits. But we're talking about a company that doesn't even refund obviously fraudulent transactions, so never mind.

Re: Deliveroo users are getting defrauded

#293

Perhaps worth mentioning, since it's nowhere in the article, that the first thing to do is not to spend hours on the phone with Deliveroo (or whoever else) but to call your bank to report the transactions as fraudulent and to block your card. That will probably get you a refund quicker (the transactions will likely be held until clarified) and will stop any further fraud. As for Deliveroo's support team... Not very g…

Please note that when you do this in a dispute, they are probably going to block you from using their service in the future.

Re: Deliveroo users are getting defrauded

#294

Perhaps worth mentioning, since it's nowhere in the article, that the first thing to do is not to spend hours on the phone with Deliveroo (or whoever else) but to call your bank to report the transactions as fraudulent and to block your card. That will probably get you a refund quicker (the transactions will likely be held until clarified) and will stop any further fraud. As for Deliveroo's support team... Not very g…

Please note that when you do this in a dispute, they are probably going to block you from using their service in the future.

I've never heard of this happening but why would you want to keep using them anyway?

Re: Deliveroo users are getting defrauded

#295
post #137

Earlier quoted context omitted.

Do you have a source for that? If that is the case then pretty much every major website is in breach. Credential stuffing is rampant and very easy to do these days. It's not the website's fault that the user gave out their password. However, I do agree that Deliveroo needs to do more to protect users against this. 2-factor authentication, email confirmation from a new IP, re-entry of card details when ordering to a n…

In the UK, the ICO guidelines are "A personal data breach means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data." The key part being "unauthorised disclosure of, or access to, personal data." So does credential stuffing qualify - In my opinion yes, as it is unauthorised access to personal data. They then go on to say "Wh…

That would be an interesting development. It means that either:

- is it illegal to not have 2FA; I’m not against that, but it feels… excessive;

- every website, including small irrelevant ones, with a password (like HN) needs to crawl the darker internet to check for leaked lists of email/passwords; that would make those unsavoury forums crawl with solution vendors; it would also make it illegal to not find the most obscure ones; in other words, a non-option;

- ban the use of any password listed on https://haveibeenpwned.com/Passwords which feels more manageable, but… does the service offer an API?

Which one feels the most likely to happen in the short term?

Re: Deliveroo users are getting defrauded

#296
post #294

Earlier quoted context omitted.

Please note that when you do this in a dispute, they are probably going to block you from using their service in the future.

I've never heard of this happening but why would you want to keep using them anyway?

As someone else mentioned.. if you do this with Steam, you could get blocked from accessing all your past purchases. If you did this with your ISP, you may not have other high-speed ISPs to choose from.

Re: Deliveroo users are getting defrauded

#297
post #262

Earlier quoted context omitted.

It depends on how "unauthorized" is defined. Does it actually define "unauthorized" somewhere else in the statute?

I think unauthorised has a fairly clearly defined definition in the English language (without permission or authority). And I’m fairly sure that’s the definition already used in courts of law. So in the absence of any contradicting definition in GDPR (and there isn’t) I would be pretty confident that is the definition that would be used. But even so I struggle to think of a definition where accessing someone else’s a…

For what it’s worth, it’s very common for close people to share their Deliveroo account, a bit like Netflix.

I would never but one of my two housemates was very confused why they couldn’t have my password so that they could look at the menu and each add their option to the order. (The third housemate was also a developer so he was surprised that I could remember it and I got sermoned about 1Pass over pizza.)

I also have heard of cases of close (female) friends who know each other’s password; when one had a health incident (miscarriage), the other took upon herself to order for the first one, to comfort her. She tried from her own account but failed (couldn’t remember the name of the restaurant), so connected to her grieving friend’s account, changed it to use her debit card. It was fully appreciated, but a surprise.

“Authorised” in that sense falls somewhere between:

- I know who those people are;

- we are part of the same household;

- I know that they can have access to my account;

- they made sure that I know they are on my account;

- I actively allowed them to be on my account right now;

- the device is shared.

Re: Deliveroo users are getting defrauded

#298
post #60

I'm not surprised by this response from Deliveroo. Their focus lately has definitely moved away from customer satisfaction. I discovered recently that drivers are allowed - without penalty - to reject an order when they reach the pickup location if they see the receipt and decide it is too far to travel [1]. As a customer you just see your food go: `Assigning Driver -> Driver En Route to Pickup -> Driver Arrived at P…

I think I’m old fashioned but I just don’t understand the appeal of these food delivery services. My friend’s son uses Postmates to order fast food and it seems absurd to me. I must be missing something about theses services given their popularity. Do you mind explaining why you use them?

Deliveroo isn’t real. Nothing is real. We are all just brains in vats attached to wires with simulations on the other end. The person in charge of maintaining you is a cruel god. Sometimes he injects your brain with an anxiety-inducing drug, just to make you suffer and think that perfectly good food is unacceptable because it was cooked an hour ago.

The rest of us don’t get injected with that drug, so we focus on the more positive aspects of the food and more generally enjoy our existence.

Re: Deliveroo users are getting defrauded

#299

Earlier quoted context omitted.

I've started using privacy.com after I saw a post here on HN about it. It's pretty nice. Basically you link up your bank account and they create debit cards for any online vendors you use, and you can set limits, destroy cards etc. I usually put monthly / transactional limits. Like with Uber Eats I know I only spend x amount, if anybody tried to use my Uber Eats card for 100 USD it would decline it. But also it locks…

> I've started using privacy.com Which is US only. Is there anything like it for the UK?

You can use Curve https://www.curve.app/

Re: Deliveroo users are getting defrauded

#300
post #15

Earlier quoted context omitted.

Problem is most vendors will then block you from ever using their service again. Might not be such a big bummer, after all they're helping people steal your money. But here it was through Apple Pay, so it may have bigger ramifications to block the card.

I don't see a problem by being blocked from a service I would never use again anyways. Plus the following dialogue: what was your name?...I am reporting you to xyz state attorney general's consumer fraud division is incredibly effective.

I've got to ask, when have you _EVER_ said this and had it actually result in what you wanted?

I worked in call centers for years and we laughed at people like you for a whole multitude of reasons.

The main reason being once you say this I'm no longer obligated to help you. Since you've decided to make this a legal situation instead of a customer service one you'll now need to talk to our team of lawyers that are on retainer. Anytime you call or email you'll get auto routed to our legal department forever who will go out of their way to not help you.

The reality is that people make legal threats dont actually follow through because they aren't people that understand the law or how it works, if they did they'd be taking actual legal action against us, not making idle threats to people making $19 dollars an hour.

Post reply on HN