Live data from Hacker News

Deliveroo users are getting defrauded

newstatesman.com

331–340 of 354 posts

Re: Deliveroo users are getting defrauded

#331

Earlier quoted context omitted.

I don't see a problem by being blocked from a service I would never use again anyways. Plus the following dialogue: what was your name?...I am reporting you to xyz state attorney general's consumer fraud division is incredibly effective.

I've got to ask, when have you _EVER_ said this and had it actually result in what you wanted? I worked in call centers for years and we laughed at people like you for a whole multitude of reasons. The main reason being once you say this I'm no longer obligated to help you. Since you've decided to make this a legal situation instead of a customer service one you'll now need to talk to our team of lawyers that are on…

I have used it 3 times or so and it was effective. The thing is I am not threatening to sue personally. I am threatening to refer the issue to the government. I personally had no intention or interest in pursuing legal options, but maybe the AG would. In one egregious case where the situation was resolved I still informed that office if the attempted fraud.

Again I'm not threatening to bring legal action. I'm just letting the 800 lb gorilla know about the situation and they perhaps might want to do something.

Re: Deliveroo users are getting defrauded

#332
My husband and I had two state tax liens in New York that were listed as Joint Responsibility. We both did a lot of to get this off our credit but all effort doesn't yield result. so we decided it was best to go online in search of a reliable Credit agency who understands the credit system to come to our rescue and just after a deep search i came across Cyber Hack and emailed him at cyberhack005@gmail .com. I told him about withdrawing our tax liens from my credit report and he explain to me the whole process to help me solve this. After some days we both got an agreement tax liens were completely gone after running his hack and my credit scores being raised to golden scores I. He sent me verification of good work he had done on my credit he sent and I checked my credit report to confirmed and it's exactly what he sent me I found on 3 credit bureaus.. I couldn't have imagined my life so good so fast

Re: Deliveroo users are getting defrauded

#333
post #74
post #66

Earlier quoted context omitted.

Is this actually shady? When doing takeaway you are not really paying for the ambiance of the restaurant anyway and IF the quality is the same I wouldn't necessarily have a problem with it.

> IF the quality is the same That's the thing. It isn't. Every franchise, big or small, has wildly different quality of ingredients and preparation (and even send the correct damn drink and remember the dip) among outlets, and if I order from that one, I want that one to prepare my food.

That’s a pretty big claim. Got a source for it?

Re: Deliveroo users are getting defrauded

#334

Earlier quoted context omitted.

>> According to your own interpretation of the law Look, I am not a laywer, and I am happy for someone to correct me here, but this is the wording of the law: "A personal data breach means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data." Is there anything in that sentence that means a successful credential stuffing atta…

a) the data wasn't breached through the credential stuffing attack, it was breached at an earlier time on another site. b) the credential stuffing attack itself is authorized access (because from the site's perspective, the user provided the correct username and password), not unauthorized access.

>> a) the data wasn't breached through the credential stuffing attack, it was breached at an earlier time on another site.

Remember GDPR is specifically concerned with "A personal data breach" The original breach that led to the password being leaked was likely also a personal data breach (unless the only thing the hackers managed to access was the username/password database - and even then email address can constitute personal data in some cases), but there is definitely a personal data breach as a result of the credential stuffing attack (in the Deliveroo case, more than likely full home address, possibly other addresses too like work, possibly name, some level of credit card data, order history, etc.).

>> b) the credential stuffing attack itself is authorized access (because from the site's perspective, the user provided the correct username and password), not unauthorized access.

It's certainly authenticated access, but I think you'll struggle to convince a lawyer that it was authorised.

Re: Deliveroo users are getting defrauded

#335
post #94
post #87

Earlier quoted context omitted.

This doesn't work in Germany, for example. If you charge back, they'll just put you into a central register (called Schufa) that will basically make it impossible for you to get a credit or even to rent an apartment.

Charge back for a credit card? That's the first time I hear of this. Do you have citations for this?

I've been imprecise, sorry. What I meant: how lead chargebacks to a credit card to a negative Schufa entry? I've never heard of this.

Re: Deliveroo users are getting defrauded

#336

Perhaps worth mentioning, since it's nowhere in the article, that the first thing to do is not to spend hours on the phone with Deliveroo (or whoever else) but to call your bank to report the transactions as fraudulent and to block your card. That will probably get you a refund quicker (the transactions will likely be held until clarified) and will stop any further fraud. As for Deliveroo's support team... Not very g…

That was my first thought too. Yes, I'd contact Deliveroo, but also my bank. If I didn't get a refund (some people waited months ?), I'd sue them in a small claims court if the amount is low enough for small claims and if its not, I'd at least talk to a legal adviser. Waiting on Deliveroo for months after being defrauded thousands of pounds is crazy.

Small claims hearings are held in county courts.

Re: Deliveroo users are getting defrauded

#337

Earlier quoted context omitted.

Accessory to a large number of immigration crimes and in the Uk that's a strict liability offence. A former PM (Gordon Brown) was fined when it was found that his cleaner had used good forged papers. Various modern slavery and gangmaster laws also come to mind.

The question was what makes it immoral, not what makes it illegal.

Taking advantage and ripping off unfortunates is not immoral? As Seward said "there is a higher law".

Re: Deliveroo users are getting defrauded

#338
post #319

Earlier quoted context omitted.

This is also the reason why creditcards are so ridiculously expensive. But then is there literally any alternative payment method in the US that does not involve a creditcard? It seems like the US banking system has just not invented anything in the last 30 years. Its not rocket science: money from my bank account to Deliveroo's bank account in (near) real time.

This is a peculiarly US phenomenon. Much of the UK, EU, Aus etc are much more willing to adopt new payment technology. (Can't speak for the non English speaking world but obviously China is way ahead) Surprisingly the US is much harder to convince. Ask people under 30yo in Aus or the UK when they last wrote a cheque, and the answer "what's a cheque?" is likely the response. Signing for a payment, magstripe, even usin…

> Ask people under 30yo in Aus or the UK when they last wrote a cheque, and the answer "what's a cheque?"

It's what train companies in the UK send you 3 weeks after you fill a compensation for delay claim...

Re: Deliveroo users are getting defrauded

#339
post #273
post #52

Earlier quoted context omitted.

> This is basically the sole "feature" of credit cards I value. Any time I'm buying something from > somewhere that might act poorly, I use a credit card for the free leverage I have in a disagreement. But without a credit card, they wouldn't even have been able to get your money without authorisation. I don't see how something like this would have been possible with a system that requires explicit authorisation per…

> But without a credit card, they wouldn't even have been able to get your money without authorisation. I don't see how something like this would have been possible with a system that requires explicit authorisation per payment. I don't understands your point. Are you saying the ideal scenario would be to fill the cards information each time? The fact that it's a credit card doesn't change that it was prefilled, a de…

What I mean is: with a credit card, you submit the information necessary to make the payment, to the merchant you're buying from. They could store that information and use it to make payments I never authorised, which is bad. On the Web, some sites have fortunately delegated that responsibility to a payment provider, but the payment provider is still not my own bank.

When I pay with my bank card with an internet payment through my bank, the authorisation is handled by me and my own bank, and nobody else. Nobody else can ever make that kind of payment without access to my password and my 2FA system. That's how it should work.

Re: Deliveroo users are getting defrauded

#340
post #52

Earlier quoted context omitted.

> This is basically the sole "feature" of credit cards I value. Any time I'm buying something from > somewhere that might act poorly, I use a credit card for the free leverage I have in a disagreement. But without a credit card, they wouldn't even have been able to get your money without authorisation. I don't see how something like this would have been possible with a system that requires explicit authorisation per…

Little confused as to why you chose their comment as the place to mention this downside. Their story is about a situation where they gave explicit authorisation. They intentionally paid.

That's true. Being able to undo an authorised payment if the other party doesn't fulfil their end of the bargain is absolutely an advantage over other forms of payment.

In the Deliveroo case, however, it's the inherent insecurity of credit cards that made that problem possible in the first place. In light of that, the ubiquity of credit cards for online payments where data is so easily copied and leaked, never ceases to puzzle me.

Post reply on HN