Live data from Hacker News

DoorDash confirms data breach affected 4.9M customers, workers and merchants

techcrunch.com

31–40 of 224 posts

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#31
post #23

The official blog post doesn't give any information about the breach except "We noticed a third-party had unauthorized access to DoorDash data", and the TechCrunch article says that DoorDash responded that they couldn't explain how the breach happened. How are they so sure that they fixed the underlying cause if they don't even know how the third-party got access in the first place?

"couldn't explain" = Were too embarrassed to explain... or could expose themselves to several lawsuits by revealing.

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#32
post #18

Earlier quoted context omitted.

Nope. I was using the built in Android Account linking (like if you link up your Facebook account to an application OAuth style), but the person who set up the account couldn't have been - they would have set it up with a password as they can't access my email account. Of note here, I never verified the account when the user first signed up, so DoorDash has always just been going on the first guy's word that they are…

Lots of services out there let you log in using both password or an external provider (Google, Facebook etc.)

I guess I've never experienced a service where it lets you log in with either option on the same account. At least it should have you verify the email account before assuming that the information is valid.

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#33

Earlier quoted context omitted.

I don't understand, it just never prompted you for a password?

Nope. I was using the built in Android Account linking (like if you link up your Facebook account to an application OAuth style), but the person who set up the account couldn't have been - they would have set it up with a password as they can't access my email account. Of note here, I never verified the account when the user first signed up, so DoorDash has always just been going on the first guy's word that they are…

Yeah this is why you do email verification. But you gotta move fast and break things ¯\_(ツ)_/¯

Or whatever the hip phrase is now that FB is radioactive.

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#34
post #6

I feel bad for the people affected but at least the scummy company got what it deserved for stealing tips (for those unaware, they used to withhold the total tips out of a delivery drivers base compensation so essentially taking the tips for themselves). Now if they could just completely die so a more ethical competitor can take its place it would be even better.

Yeah the Equifax breach was the nail in the coffin for them... Data breaches rarely hurt companies it seems.

Equifax's story is different, people don't have a choice whether to use them (if people did they'd already be out of business) and they have a near-monopoly, not to mention they are profitable so they are here to stay.

Doordash? They're just a shitty startup trying to "disrupt" the market by forgetting laws and morals and are only surviving thanks to VC money. People are not obliged to use them, and since they're essentially providing a commodity people can easily choose to use a competitor, only accelerating Doordash's inevitable demise. People aren't always reasonable, and such incidents can sway them towards other competitors (even though I doubt the competitors are any better in terms of security).

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#35
post #23

The official blog post doesn't give any information about the breach except "We noticed a third-party had unauthorized access to DoorDash data", and the TechCrunch article says that DoorDash responded that they couldn't explain how the breach happened. How are they so sure that they fixed the underlying cause if they don't even know how the third-party got access in the first place?

It seems like the breach was through a third party that only had old data, since nobody that registered after April 5, 2018 is affected.

So it's probably some service that they no longer use and doesn't really need to be fixed or investigated, since all the data they had has already been taken and they (probably) stopped giving them more data a year and a half ago.

They should really say who the third party was though. Hopefully that information comes out.

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#36
post #6

I feel bad for the people affected but at least the scummy company got what it deserved for stealing tips (for those unaware, they used to withhold the total tips out of a delivery drivers base compensation so essentially taking the tips for themselves). Now if they could just completely die so a more ethical competitor can take its place it would be even better.

They did no such thing, and I find it frustrating that people keep repeating this falsehood. Doordash promised to pay drives at least $X (where X was, I believe $1 or something like that) AND that the driver will make at least $Y from the delivery. The driver always gets the tip, plus a variable amount from DD. This is _exactly_ how it works for wait staff in restaurants in most states, except that is by hour instead of delivery. For example, in MA, the restaurant pays out a minimum of $3.75 (wait staff minimum wage in MA) and guarantees that the wait-person makes $11 (actual minimum wage). See https://www.dol.gov/whd/state/tipped.htm

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#37
post #6

I feel bad for the people affected but at least the scummy company got what it deserved for stealing tips (for those unaware, they used to withhold the total tips out of a delivery drivers base compensation so essentially taking the tips for themselves). Now if they could just completely die so a more ethical competitor can take its place it would be even better.

Food delivery customers care about very few things: 1) cost 2) food quality 3) delivery time

If a more ethical competitor can't match or exceed these, they won't be a competitor for long.

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#38

Original blog post: https://blog.doordash.com/important-security-notice-about-yo... From the techcrunch article: "It’s not clear why it took almost five months for DoorDash to publicly reveal the breach. DoorDash spokesperson Mattie Magdovitz say why [sic]." Pretty bad. If personal identity info is exposed, it is irresponsible not to notify users immediately so they can freeze credit and watch for suspicious activity…

They really should have given some actual information, i.e. how the information was stored. I want to know what algorithm was used, not how "it was securely stored so people still can't take your money" or some other corporate-speak intended to mitigate the damage.

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#39
post #13

> The information accessed is not sufficient to make fraudulent charges on your payment card. In other words... "We leaked a bunch of your personal information, but at least it's not enough data to steal your money!" All of these leaks have the cumulative effect of making ineffective very commonly used security verification questions: "Can I verify that last 4 of your social? And the last 4 of your credit card?" How…

But now they have a dump of how many peoples names, address and phone numbers?

Leaking is only part of the problem. The main issue is that this information lets you authenticate with anything at all or as a starting point for social engineering.

For example, you could build your own database of millions of records of name/phone/addr just looking up WHOIS info on every domain name you come across.

And I'm reminded of how you can get into someone's Amazon account by feeding WHOIS information to their customer support, even if the address is bogus but is in the same city that Amazon has on file. https://medium.com/@espringe/amazon-s-customer-service-backd...

HN takes out its pitch forks for every leak, but the outrage is often misdirected.

For example, why do we have this idiotic system where you can make purchases on my credit card with the same credentials I hand out multiple times a day, even for a $5 hotdog, and as a result I need to remain eternally vigilant to find fraud on my monthly statements? Why can you get into my Amazon account if you know a single address that approximates one of the addresses I've ever shipped product to?

Leaking is inevitable. The problem is that our system and thus our expectations are built as if it's not.

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#40

Earlier quoted context omitted.

Yeah the Equifax breach was the nail in the coffin for them... Data breaches rarely hurt companies it seems.

Equifax's story is different, people don't have a choice whether to use them (if people did they'd already be out of business) and they have a near-monopoly, not to mention they are profitable so they are here to stay. Doordash? They're just a shitty startup trying to "disrupt" the market by forgetting laws and morals and are only surviving thanks to VC money. People are not obliged to use them, and since they're ess…

What product or service do you believe that Equifax is near being a monopoly provider for?
Post reply on HN