Live data from Hacker News

Deliveroo users are getting defrauded

newstatesman.com

301–310 of 354 posts

Re: Deliveroo users are getting defrauded

#301
post #157

Earlier quoted context omitted.

Amex has the same thing and their customer protections are generally better than the Fintech companies. Although Amex is not so common in the U.K. Do any UK credit card companies offer consumer and fraud protection above the norm? Amex would immediately side with me if I showed them the Deliveroo communication. Another Citi VISA I had offered 18 months warranties on laptops and other electronics if I used the card.

Do all Amex cards have this? I've never seen this feature offered by them. Edit: apparently they stopped doing this for average cardholders 15 years ago and it's a corporate-card-only thing now called 'Amex Go'

Amex recently detected a fraudulent charge on my card, and sent me an email with a "click here" button which, after I confirmed my identity, triggered the issuance of a new card in the mail in a couple of days.

I should note I have a "Starwood Preferred Guest" Amex card, but that is not a corporate card. It may be that the SPG card has additional features that a regular card would not.

Re: Deliveroo users are getting defrauded

#302
post #295

Earlier quoted context omitted.

In the UK, the ICO guidelines are "A personal data breach means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data." The key part being "unauthorised disclosure of, or access to, personal data." So does credential stuffing qualify - In my opinion yes, as it is unauthorised access to personal data. They then go on to say "Wh…

That would be an interesting development. It means that either: - is it illegal to not have 2FA; I’m not against that, but it feels… excessive; - every website, including small irrelevant ones, with a password (like HN) needs to crawl the darker internet to check for leaked lists of email/passwords; that would make those unsavoury forums crawl with solution vendors; it would also make it illegal to not find the most…

Remember part 2 of that section:

"establish the likelihood and severity of the resulting risk to people’s rights and freedoms. If it’s likely that there will be a risk then you must notify the ICO;"

So if it's a small irrelevant website, there isn't likely to be a high or severe risk to that "breach", so they should be ok.

In terms of options, I think there are more, mostly around sites getting more sophisticated at defending against credential stuffing attacks - treat logins as more suspicious if they are from a new device, new ip, use a password that you know is in a breach list (have i been pwned), etc. and put in place a 2nd factor like email confirmation of the login even if they haven't turned on 2FA. Or at least restrict access to sensitive parts of your site if the login was suspicious until you can verify it was an authentic login.

Re: Deliveroo users are getting defrauded

#303

Earlier quoted context omitted.

Students will do all kinds of "harmless" under the table stuff to get/save a little extra spending money. That's different to me than an person desperate for money to pay rent or buy food.

That's certainly true and they are illegally working. But maybe your image of a student might be a bit narrow? There's a large industry in Europe of language schools. You pay the school/country a few thousand euros/pounds and in return you get a student visa + basic language course. Not all, but many students are coming from pretty bad places in the hope of somehow landing a work visa(Italy and Portugal will grant ci…

In portugal you need more than just "ancestry", unless it's relatively close relatives (grandparent).

You would need to speak Portuguese, and prove an effective tie to portugal, for example participating in Portuguese cultural activities, groups or organizations

Re: Deliveroo users are getting defrauded

#304
post #107

Earlier quoted context omitted.

I’ve never had a credit card of mine report a chargeback, and if they ever did I would cancel the card immediately. Mostly chargebacks are for actual fraudulent use of the card, and the process also includes getting a new card number. Lately, most chargebacks I’ve done have actually been issued by the card itself after they detected suspicious activity and sent me a text alert asking about specific charges. In one ca…

Credit cards do not report, merchants banks do directly With credit bureaus. from there they decide if certain card holder triggered too many they put it on.

Oh boy don't you love being downvoted when you give people a genuine good-faith advice. I miss HackerNews from 5 years ago...

Google this: "Account information disputed by consumer, meets FCRA requirements" and you will learn more.

Re: Deliveroo users are getting defrauded

#305

Perhaps worth mentioning, since it's nowhere in the article, that the first thing to do is not to spend hours on the phone with Deliveroo (or whoever else) but to call your bank to report the transactions as fraudulent and to block your card. That will probably get you a refund quicker (the transactions will likely be held until clarified) and will stop any further fraud. As for Deliveroo's support team... Not very g…

This is basically the sole "feature" of credit cards I value. Any time I'm buying something from somewhere that might act poorly, I use a credit card for the free leverage I have in a disagreement. Had an old phones screen repaired at a store inside a Walmart. They fixed it but half the screen had no touch capability. They were highly resistant to doing anything about it until I said I would just do a charge back. To…

This is also the reason why creditcards are so ridiculously expensive.

But then is there literally any alternative payment method in the US that does not involve a creditcard? It seems like the US banking system has just not invented anything in the last 30 years. Its not rocket science: money from my bank account to Deliveroo's bank account in (near) real time.

Re: Deliveroo users are getting defrauded

#306

Earlier quoted context omitted.

I don't see a problem by being blocked from a service I would never use again anyways. Plus the following dialogue: what was your name?...I am reporting you to xyz state attorney general's consumer fraud division is incredibly effective.

I've got to ask, when have you _EVER_ said this and had it actually result in what you wanted? I worked in call centers for years and we laughed at people like you for a whole multitude of reasons. The main reason being once you say this I'm no longer obligated to help you. Since you've decided to make this a legal situation instead of a customer service one you'll now need to talk to our team of lawyers that are on…

Legal threats work for me about half the time, but I threaten small claims court only after getting escalated to a manager while collecting as much info as possible (it also helps if you're in a one party consent state and can play back parts of the phone call to the manager). It works for big companies better than small ones but it does take a little longer for the escalation to go through the legal department and I haven't really bothered trying it for small disputes (anything under a few hundred dollars). The few times I have followed through on the threat resulted in a settlement with one local business and default judgement against two big companies now.

Re: Deliveroo users are getting defrauded

#307
post #241

Earlier quoted context omitted.

So if someone hacks your email because you didn't have sufficient protections in place, does that make the email provider liable? Seems like an argument that falls apart very quickly.

Yes, exactly that if the email provider hasn’t put in place sufficient defences. Why wouldn’t they be liable? They have a duty of care under GDPR to protect your personal data. If they are negligent in that duty then absolutely they should be liable.

I'm not sure why this is being downvoted. All I am doing is pointing out what the current law is under GDPR. You may not agree with the law, but that doesn't change what it says.

Re: Deliveroo users are getting defrauded

#308
post #273
post #52

Earlier quoted context omitted.

> This is basically the sole "feature" of credit cards I value. Any time I'm buying something from > somewhere that might act poorly, I use a credit card for the free leverage I have in a disagreement. But without a credit card, they wouldn't even have been able to get your money without authorisation. I don't see how something like this would have been possible with a system that requires explicit authorisation per…

> But without a credit card, they wouldn't even have been able to get your money without authorisation. I don't see how something like this would have been possible with a system that requires explicit authorisation per payment. I don't understands your point. Are you saying the ideal scenario would be to fill the cards information each time? The fact that it's a credit card doesn't change that it was prefilled, a de…

A few years ago, I made the mistake of buying some furniture using my debit card instead of credit card (about £1k).

Between the payment and the delivery the company went bust.

I though I was out of the money, but after a brief search I found out that, although there is no legal requirement to do so, VISA in the UK offers (or at least used to) the same chargeback facility to debit cards as for CCs. I visited my bank branch which gave me a phone number to contact, sent in a bunch of paperwork and after about 2 weeks I got my money back. I was very pleased as you can expect.

Re: Deliveroo users are getting defrauded

#309
post #295

Earlier quoted context omitted.

That would be an interesting development. It means that either: - is it illegal to not have 2FA; I’m not against that, but it feels… excessive; - every website, including small irrelevant ones, with a password (like HN) needs to crawl the darker internet to check for leaked lists of email/passwords; that would make those unsavoury forums crawl with solution vendors; it would also make it illegal to not find the most…

Remember part 2 of that section: "establish the likelihood and severity of the resulting risk to people’s rights and freedoms. If it’s likely that there will be a risk then you must notify the ICO;" So if it's a small irrelevant website, there isn't likely to be a high or severe risk to that "breach", so they should be ok. In terms of options, I think there are more, mostly around sites getting more sophisticated at…

'So if it's a small irrelevant website, there isn't likely to be a high or severe risk to that "breach", so they should be ok.'

To be clear, no website, depending on passwords alone, can know if an access was authorized by the person who is the subject of the account. Therefore, it would seem that the only sites that can use password-only authentication without risk are those that hold no personal information about their customers. According to your own interpretation of the law, some of your proposed mitigations would not be sufficient to eliminate the risk, if any personal information is held.

Re: Deliveroo users are getting defrauded

#310
post #234

Earlier quoted context omitted.

Er, deliveroo delivers from restaurants. Justeat delivers from fast food. Deliveroo costs more because it's providing a delivery service for restaurants that don't normally deliver. So I'm getting good food. When in a restaurant, things sit in a kitchen for 10 minutes waiting for the rest of your order anyway. 10 minutes in a thermal bag is the same.

Wouldn't that be 10 additional minutes in the thermal bag? If it sits waiting for 10 minutes for the rest of my order wouldn't the time in the thermal bag be in addition to this. Also, in the U.S. delivery in my experience with others doing this is that is takes more than 10 minutes for the driver to pick up the order. Then another 10 - 20 minutes to deliver. To me this ruins the meal. You don't get a nice presentati…

> To me this ruins the meal.

But at that point you're basically just objecting to all delivery food ever. Which is fine but, like, you are aware that it is a huge industry and has been for decades and people do like it? Convenience trumps artistry (and optimum temperature) for many people a lot of the time.

Post reply on HN