Live data from Hacker News

DoorDash confirms data breach affected 4.9M customers, workers and merchants

techcrunch.com

21–30 of 224 posts

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#22
post #13

> The information accessed is not sufficient to make fraudulent charges on your payment card. In other words... "We leaked a bunch of your personal information, but at least it's not enough data to steal your money!" All of these leaks have the cumulative effect of making ineffective very commonly used security verification questions: "Can I verify that last 4 of your social? And the last 4 of your credit card?" How…

Yeah. In fact reversing a fraudulent credit card charge is a LOT easier than dealing with identity theft or stalkers.

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#23
The official blog post doesn't give any information about the breach except "We noticed a third-party had unauthorized access to DoorDash data", and the TechCrunch article says that DoorDash responded that they couldn't explain how the breach happened. How are they so sure that they fixed the underlying cause if they don't even know how the third-party got access in the first place?

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#24
post #21

At this point HN should just have a permanent module in the top right corner announcing the latest data breach.

"Days since last publicly disclosed data breach breach: 0"

Honestly? A minutes scale might be more appropriate there. Unless we add the "Major" but then, what is major?

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#25
post #24
post #21

Earlier quoted context omitted.

"Days since last publicly disclosed data breach breach: 0"

Honestly? A minutes scale might be more appropriate there. Unless we add the "Major" but then, what is major?

A rounding error.

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#26
post #13

> The information accessed is not sufficient to make fraudulent charges on your payment card. In other words... "We leaked a bunch of your personal information, but at least it's not enough data to steal your money!" All of these leaks have the cumulative effect of making ineffective very commonly used security verification questions: "Can I verify that last 4 of your social? And the last 4 of your credit card?" How…

But now they have a dump of how many peoples names, address and phone numbers?

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#28
post #13

> The information accessed is not sufficient to make fraudulent charges on your payment card. In other words... "We leaked a bunch of your personal information, but at least it's not enough data to steal your money!" All of these leaks have the cumulative effect of making ineffective very commonly used security verification questions: "Can I verify that last 4 of your social? And the last 4 of your credit card?" How…

Hell, imagine how many scans of people’s passports and driver’s licenses are sitting in databases waiting to be leaked, yet images of those documents let you authenticate with all sorts of financial institutions online from banks to Coinbase to Paypal.

We really need to rethink all this. Until then, it feels like mere luck that today wasn’t the day someone decided to social engineer their way into your life.

Everything is so precarious.

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#29
I don't know a great deal about DoorDash, but my understanding is that they're only in the US. If so, they're not bound by the EU's GDPR data breach disclosure timescales, which are "without undue delay and, where feasible, not later than 72 hours" if they're likely to result in a high risk to the rights and freedoms of data subjects, which this seems to fit. Compare that with the apparent five month delay here, with all its attendant risks to the customers whose data was made available. The EU has its flaws, but when I read stories like this I'm really happy I'm covered by GDPR.

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#30
post #17

Earlier quoted context omitted.

Nope. I was using the built in Android Account linking (like if you link up your Facebook account to an application OAuth style), but the person who set up the account couldn't have been - they would have set it up with a password as they can't access my email account. Of note here, I never verified the account when the user first signed up, so DoorDash has always just been going on the first guy's word that they are…

I don’t see the issue? DoorDash authenticated that you own the email account via a trusted third party. Once authenticated they authorized you to use the account associated with that email address. It’d be like someone else booking a hotel room as you. When you show up at the front desk they verify it’s you and then let you into that room because it is after all... yours.

I suppose so. I guess we assume that email ownership is digital ownership - even though they never verified that the user in fact owned the email? I wonder how that legally works - was I in the wrong for unwittingly accessing someone else's information?
Post reply on HN