Live data from Hacker News

DoorDash confirms data breach affected 4.9M customers, workers and merchants

techcrunch.com

61–70 of 224 posts

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#61
post #13

> The information accessed is not sufficient to make fraudulent charges on your payment card. In other words... "We leaked a bunch of your personal information, but at least it's not enough data to steal your money!" All of these leaks have the cumulative effect of making ineffective very commonly used security verification questions: "Can I verify that last 4 of your social? And the last 4 of your credit card?" How…

Surely the actual problem here is that the responsibility for reliable identification somehow falls on the consumer, not the bank or what have you? I'll give an example: if I get a phishing email claiming to be from my bank, and end up wiring them $1000, I'm out $1000 for not having done the due diligence for verifying that it in fact was my bank; my bank doesn't suddenly owe me $1000. Somehow, though, if some 3rd pa…

The problem with what you're proposing is that, as far as I understand, the real "consequences" for things like identity theft end up being intangibles like "time" and "annoyance" or "credit score". I don't think you'll actually be out $1000, the bank will just reverse it or it will be covered under some sort of insurance or something. Many times its just people taking out fraudulent loans under your name (vs. directly stealing money from you), so it gets handled entirely "digitally" and you experience no long term financial harm. Because of that, no one ends up "angry" at the bank, since what they lost was a week in "hassle".

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#62
post #53

Is there a list of all disclosed security breaches somewhere?

https://haveibeenpwned.com/PwnedWebsites

There is even an RSS feed. It doesn't cover every breach but certainly significant verified ones - details in the site FAQ. There is even such a thing as faked breaches!

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#63
post #53

Is there a list of all disclosed security breaches somewhere?

The best site I've used is haveibeenpwned.com, seems to be the go-to for most security breaches and has a tool that can notify you when some of your information has been compromised tied to an email address.

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#64

There is a silver lining in all these data breaches. At some point in time all our data will have been leaked at least once and probably more than once and subsequent leaks will not do any more damage. The safe assumption would then be to not trust any accounts created online without some good old KYC processes in place requiring live verification of identity.

Totally agree! As a bit of self-promotion, my company (Berbix) is trying to solve this by automating ID checks and being the best possible stewards of this sensitive data: http://berbix.com

We've gone to great lengths to secure ID and DL information and have even built a watermarking service to track all access to these images: https://docs.berbix.com/docs/transactions#section-watermarki...

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#66
post #48

At this point HN should just have a permanent module in the top right corner announcing the latest data breach.

It's far too common now and there doesn't seem to be any meaningful consequences for the websites/companies involved.

IMO think this is the core of the issue.

As long as there are no serious consequences for leaking user's data these things are going to continue to happen.

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#67

Earlier quoted context omitted.

They did no such thing, and I find it frustrating that people keep repeating this falsehood. Doordash promised to pay drives at least $X (where X was, I believe $1 or something like that) AND that the driver will make at least $Y from the delivery. The driver always gets the tip, plus a variable amount from DD. This is _exactly_ how it works for wait staff in restaurants in most states, except that is by hour instead…

Did they make that clear to the end customer that this is what's happening with the tips? I don't care what their contract with the delivery driver states, if they allow me to add a tip I expect that tip to go in the driver's pocket in addition to whatever they'd get paid without the tip, just like if I was giving them cash directly. If that's not what's happening they have essentially defrauded me and I wouldn't be…

When was the last time a restaurant disclosed this arrangement to you?

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#68
post #44

>The breach happened on May 4 I don't believe for one second that they didn't know about it for five months! Can someone in the EU please report this so that it's investigated for a GDPR violation? Edit: from the official post on blog.doordash.com: >Earlier this month, we became aware of unusual activity involving a third-party service provider. Of course. This is quite a bit more than the 72 hour window GDPR allows.

I think DoorDash is in just US and Canada at this time.

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#70

At this point HN should just have a permanent module in the top right corner announcing the latest data breach.

Breaking news: There is someone who has been walkabout living in the woods since 2000, and nobody has his data!
Post reply on HN