The official blog post doesn't give any information about the breach except "We noticed a third-party had unauthorized access to DoorDash data", and the TechCrunch article says that DoorDash responded that they couldn't explain how the breach happened. How are they so sure that they fixed the underlying cause if they don't even know how the third-party got access in the first place?
DoorDash confirms data breach affected 4.9M customers, workers and merchants
31–40 of 224 posts
Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants
#32Earlier quoted context omitted.
Nope. I was using the built in Android Account linking (like if you link up your Facebook account to an application OAuth style), but the person who set up the account couldn't have been - they would have set it up with a password as they can't access my email account. Of note here, I never verified the account when the user first signed up, so DoorDash has always just been going on the first guy's word that they are…
Lots of services out there let you log in using both password or an external provider (Google, Facebook etc.)
Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants
#33Earlier quoted context omitted.
I don't understand, it just never prompted you for a password?
Nope. I was using the built in Android Account linking (like if you link up your Facebook account to an application OAuth style), but the person who set up the account couldn't have been - they would have set it up with a password as they can't access my email account. Of note here, I never verified the account when the user first signed up, so DoorDash has always just been going on the first guy's word that they are…
Or whatever the hip phrase is now that FB is radioactive.
Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants
#34I feel bad for the people affected but at least the scummy company got what it deserved for stealing tips (for those unaware, they used to withhold the total tips out of a delivery drivers base compensation so essentially taking the tips for themselves). Now if they could just completely die so a more ethical competitor can take its place it would be even better.
Yeah the Equifax breach was the nail in the coffin for them... Data breaches rarely hurt companies it seems.
Doordash? They're just a shitty startup trying to "disrupt" the market by forgetting laws and morals and are only surviving thanks to VC money. People are not obliged to use them, and since they're essentially providing a commodity people can easily choose to use a competitor, only accelerating Doordash's inevitable demise. People aren't always reasonable, and such incidents can sway them towards other competitors (even though I doubt the competitors are any better in terms of security).
Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants
#35The official blog post doesn't give any information about the breach except "We noticed a third-party had unauthorized access to DoorDash data", and the TechCrunch article says that DoorDash responded that they couldn't explain how the breach happened. How are they so sure that they fixed the underlying cause if they don't even know how the third-party got access in the first place?
So it's probably some service that they no longer use and doesn't really need to be fixed or investigated, since all the data they had has already been taken and they (probably) stopped giving them more data a year and a half ago.
They should really say who the third party was though. Hopefully that information comes out.
Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants
#36I feel bad for the people affected but at least the scummy company got what it deserved for stealing tips (for those unaware, they used to withhold the total tips out of a delivery drivers base compensation so essentially taking the tips for themselves). Now if they could just completely die so a more ethical competitor can take its place it would be even better.
Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants
#37I feel bad for the people affected but at least the scummy company got what it deserved for stealing tips (for those unaware, they used to withhold the total tips out of a delivery drivers base compensation so essentially taking the tips for themselves). Now if they could just completely die so a more ethical competitor can take its place it would be even better.
If a more ethical competitor can't match or exceed these, they won't be a competitor for long.
Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants
#38Original blog post: https://blog.doordash.com/important-security-notice-about-yo... From the techcrunch article: "It’s not clear why it took almost five months for DoorDash to publicly reveal the breach. DoorDash spokesperson Mattie Magdovitz say why [sic]." Pretty bad. If personal identity info is exposed, it is irresponsible not to notify users immediately so they can freeze credit and watch for suspicious activity…
Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants
#39> The information accessed is not sufficient to make fraudulent charges on your payment card. In other words... "We leaked a bunch of your personal information, but at least it's not enough data to steal your money!" All of these leaks have the cumulative effect of making ineffective very commonly used security verification questions: "Can I verify that last 4 of your social? And the last 4 of your credit card?" How…
But now they have a dump of how many peoples names, address and phone numbers?
For example, you could build your own database of millions of records of name/phone/addr just looking up WHOIS info on every domain name you come across.
And I'm reminded of how you can get into someone's Amazon account by feeding WHOIS information to their customer support, even if the address is bogus but is in the same city that Amazon has on file. https://medium.com/@espringe/amazon-s-customer-service-backd...
HN takes out its pitch forks for every leak, but the outrage is often misdirected.
For example, why do we have this idiotic system where you can make purchases on my credit card with the same credentials I hand out multiple times a day, even for a $5 hotdog, and as a result I need to remain eternally vigilant to find fraud on my monthly statements? Why can you get into my Amazon account if you know a single address that approximates one of the addresses I've ever shipped product to?
Leaking is inevitable. The problem is that our system and thus our expectations are built as if it's not.
Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants
#40Earlier quoted context omitted.
Yeah the Equifax breach was the nail in the coffin for them... Data breaches rarely hurt companies it seems.
Equifax's story is different, people don't have a choice whether to use them (if people did they'd already be out of business) and they have a near-monopoly, not to mention they are profitable so they are here to stay. Doordash? They're just a shitty startup trying to "disrupt" the market by forgetting laws and morals and are only surviving thanks to VC money. People are not obliged to use them, and since they're ess…