At this point HN should just have a permanent module in the top right corner announcing the latest data breach.
DoorDash confirms data breach affected 4.9M customers, workers and merchants
21–30 of 224 posts
Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants
#22> The information accessed is not sufficient to make fraudulent charges on your payment card. In other words... "We leaked a bunch of your personal information, but at least it's not enough data to steal your money!" All of these leaks have the cumulative effect of making ineffective very commonly used security verification questions: "Can I verify that last 4 of your social? And the last 4 of your credit card?" How…
Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants
#23Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants
#24Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants
#25Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants
#26> The information accessed is not sufficient to make fraudulent charges on your payment card. In other words... "We leaked a bunch of your personal information, but at least it's not enough data to steal your money!" All of these leaks have the cumulative effect of making ineffective very commonly used security verification questions: "Can I verify that last 4 of your social? And the last 4 of your credit card?" How…
Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants
#27Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants
#28> The information accessed is not sufficient to make fraudulent charges on your payment card. In other words... "We leaked a bunch of your personal information, but at least it's not enough data to steal your money!" All of these leaks have the cumulative effect of making ineffective very commonly used security verification questions: "Can I verify that last 4 of your social? And the last 4 of your credit card?" How…
We really need to rethink all this. Until then, it feels like mere luck that today wasn’t the day someone decided to social engineer their way into your life.
Everything is so precarious.
Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants
#29Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants
#30Earlier quoted context omitted.
Nope. I was using the built in Android Account linking (like if you link up your Facebook account to an application OAuth style), but the person who set up the account couldn't have been - they would have set it up with a password as they can't access my email account. Of note here, I never verified the account when the user first signed up, so DoorDash has always just been going on the first guy's word that they are…
I don’t see the issue? DoorDash authenticated that you own the email account via a trusted third party. Once authenticated they authorized you to use the account associated with that email address. It’d be like someone else booking a hotel room as you. When you show up at the front desk they verify it’s you and then let you into that room because it is after all... yours.