Live data from Hacker News

DoorDash confirms data breach affected 4.9M customers, workers and merchants

techcrunch.com

11–20 of 224 posts

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#11

I still worry about DoorDashes security - someone has signed up for services with my email account - not an issue, I just will never verify them. But they had signed up for DoorDash, and I didn't realize it, and then I tried to sign up for the first time via the Android App with that same email account. I selected the email account to my surprise it immediately let me into the other persons account! They had ostensib…

I don't understand, it just never prompted you for a password?

Nope. I was using the built in Android Account linking (like if you link up your Facebook account to an application OAuth style), but the person who set up the account couldn't have been - they would have set it up with a password as they can't access my email account.

Of note here, I never verified the account when the user first signed up, so DoorDash has always just been going on the first guy's word that they are who they say they are.

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#12
post #4

Original blog post: https://blog.doordash.com/important-security-notice-about-yo... From the techcrunch article: "It’s not clear why it took almost five months for DoorDash to publicly reveal the breach. DoorDash spokesperson Mattie Magdovitz say why [sic]." Pretty bad. If personal identity info is exposed, it is irresponsible not to notify users immediately so they can freeze credit and watch for suspicious activity…

Huh? The blog post says April 5, 2018.

I'm not sure what you're trying to point out, but it seems like the data was stolen from a third party DoorDash uses, and that they only had data from users that registered on or before April 5, 2018. The breach actually happened on May 4, 2019.

(And the 2015 reference in the comment you're replying to is about a Flipboard breach, not DoorDash)

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#13
> The information accessed is not sufficient to make fraudulent charges on your payment card.

In other words... "We leaked a bunch of your personal information, but at least it's not enough data to steal your money!"

All of these leaks have the cumulative effect of making ineffective very commonly used security verification questions: "Can I verify that last 4 of your social? And the last 4 of your credit card?"

How long will it take for us to accept that this kind of data can no longer be assumed private? The sooner, the better, mainly so companies stop using it as a secondary form of identity verification.

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#14

Earlier quoted context omitted.

I don't understand, it just never prompted you for a password?

Nope. I was using the built in Android Account linking (like if you link up your Facebook account to an application OAuth style), but the person who set up the account couldn't have been - they would have set it up with a password as they can't access my email account. Of note here, I never verified the account when the user first signed up, so DoorDash has always just been going on the first guy's word that they are…

[deleted]

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#15

Earlier quoted context omitted.

I don't understand, it just never prompted you for a password?

Nope. I was using the built in Android Account linking (like if you link up your Facebook account to an application OAuth style), but the person who set up the account couldn't have been - they would have set it up with a password as they can't access my email account. Of note here, I never verified the account when the user first signed up, so DoorDash has always just been going on the first guy's word that they are…

If you control the email address on the account you could get in by resetting the password, so I'm not sure what the difference is there

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#17

Earlier quoted context omitted.

I don't understand, it just never prompted you for a password?

Nope. I was using the built in Android Account linking (like if you link up your Facebook account to an application OAuth style), but the person who set up the account couldn't have been - they would have set it up with a password as they can't access my email account. Of note here, I never verified the account when the user first signed up, so DoorDash has always just been going on the first guy's word that they are…

I don’t see the issue? DoorDash authenticated that you own the email account via a trusted third party. Once authenticated they authorized you to use the account associated with that email address.

It’d be like someone else booking a hotel room as you. When you show up at the front desk they verify it’s you and then let you into that room because it is after all... yours.

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#18

Earlier quoted context omitted.

I don't understand, it just never prompted you for a password?

Nope. I was using the built in Android Account linking (like if you link up your Facebook account to an application OAuth style), but the person who set up the account couldn't have been - they would have set it up with a password as they can't access my email account. Of note here, I never verified the account when the user first signed up, so DoorDash has always just been going on the first guy's word that they are…

Lots of services out there let you log in using both password or an external provider (Google, Facebook etc.)

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#19

Earlier quoted context omitted.

Nope. I was using the built in Android Account linking (like if you link up your Facebook account to an application OAuth style), but the person who set up the account couldn't have been - they would have set it up with a password as they can't access my email account. Of note here, I never verified the account when the user first signed up, so DoorDash has always just been going on the first guy's word that they are…

If you control the email address on the account you could get in by resetting the password, so I'm not sure what the difference is there

[deleted]

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#20

Earlier quoted context omitted.

Nope. I was using the built in Android Account linking (like if you link up your Facebook account to an application OAuth style), but the person who set up the account couldn't have been - they would have set it up with a password as they can't access my email account. Of note here, I never verified the account when the user first signed up, so DoorDash has always just been going on the first guy's word that they are…

If you control the email address on the account you could get in by resetting the password, so I'm not sure what the difference is there

To me the difference is the intent - I didn't intend on entering someone else's account. If I'd tried to log in with a password/email, it would have told me the account already exists, or prompted me to reset the password, and then I'd need to request that and knowingly invade the account. This way I just walked right in without even knowing what I was doing - I didn't realize there was even a problem until I went "hey, that's not my phone number!".
Post reply on HN