Live data from Hacker News

DoorDash confirms data breach affected 4.9M customers, workers and merchants

techcrunch.com

81–90 of 224 posts

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#81
post #13

> The information accessed is not sufficient to make fraudulent charges on your payment card. In other words... "We leaked a bunch of your personal information, but at least it's not enough data to steal your money!" All of these leaks have the cumulative effect of making ineffective very commonly used security verification questions: "Can I verify that last 4 of your social? And the last 4 of your credit card?" How…

Surely the actual problem here is that the responsibility for reliable identification somehow falls on the consumer, not the bank or what have you? I'll give an example: if I get a phishing email claiming to be from my bank, and end up wiring them $1000, I'm out $1000 for not having done the due diligence for verifying that it in fact was my bank; my bank doesn't suddenly owe me $1000. Somehow, though, if some 3rd pa…

I think that this is extension of semantic play that such leaks lead to "identity theft". Even if you took due diligence to protect your credit card and SSN or other personal info after the fact you are being played as "victim of identity theft". No it is not identity theft that someone used yours info to take fast loan or buy bitcoin with your credict card that incompetent business lost and now you are SOL with ruined life/credit score - it is bank fraud and banks should stop making it look like it is not their problem/fault.

It even is stamped on CC that it is property of the issuing bank. So you made it such way that skimmer can copy your card at gas station and empty someones account in few minutes but you are not part of the problem at all? Then what is the point of of plastic other that milking fees?

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#82
I've been vending myself unique email addresses for every online account I use for about 3 years. They are nice because I can reply to them like a regular mail and my actual email account gets stripped out automagically.

I've been considering making it a product and I wonder in this case what people would want to do when the account data gets leaked?

1. blackhole all email to the address. 2. forward all email to some email service that is never/rarely used. 3. flag messages that are not sent from the matching domain (doordash.com in this case). 4. blackhole and generate a new address so the user can go back to door dash and provide a fresh email address.

I also wonder if there is any use for meta data on who's trying to email a blackholed email addrress e.g spam blacklisting.

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#84
post #17

Earlier quoted context omitted.

Nope. I was using the built in Android Account linking (like if you link up your Facebook account to an application OAuth style), but the person who set up the account couldn't have been - they would have set it up with a password as they can't access my email account. Of note here, I never verified the account when the user first signed up, so DoorDash has always just been going on the first guy's word that they are…

I don’t see the issue? DoorDash authenticated that you own the email account via a trusted third party. Once authenticated they authorized you to use the account associated with that email address. It’d be like someone else booking a hotel room as you. When you show up at the front desk they verify it’s you and then let you into that room because it is after all... yours.

Actually, it's more like someone else booked a hotel room as OP. Since they were there in person, the hotel gave them the room key, and they are in that room taking a shower (updated the phone number in this case). The OP goes in and asks for a room, presents his/her email, and since it matched receives the key to the _same room_. OP then walks into the other guy's room while they are in it. At least that's my understanding of it.

edit: grammar

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#85

I've been vending myself unique email addresses for every online account I use for about 3 years. They are nice because I can reply to them like a regular mail and my actual email account gets stripped out automagically. I've been considering making it a product and I wonder in this case what people would want to do when the account data gets leaked? 1. blackhole all email to the address. 2. forward all email to some…

You can do something similar with fastmail. Get a domain for your email and make an alias address of the form [anything]@[alias].domain.com . You can then make 'sending identities' for an instance of that catchall domain for the rare time you need to send email as mortgage_company@a.domain.com . You can also create rules to blackhole a specific alias email or whatever you want when you need to invalidate the email.

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#86
post #13

> The information accessed is not sufficient to make fraudulent charges on your payment card. In other words... "We leaked a bunch of your personal information, but at least it's not enough data to steal your money!" All of these leaks have the cumulative effect of making ineffective very commonly used security verification questions: "Can I verify that last 4 of your social? And the last 4 of your credit card?" How…

What websites are storing your mother’s maiden name?

Besides maybe the bank

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#87
post #85

I've been vending myself unique email addresses for every online account I use for about 3 years. They are nice because I can reply to them like a regular mail and my actual email account gets stripped out automagically. I've been considering making it a product and I wonder in this case what people would want to do when the account data gets leaked? 1. blackhole all email to the address. 2. forward all email to some…

You can do something similar with fastmail. Get a domain for your email and make an alias address of the form [anything]@[alias].domain.com . You can then make 'sending identities' for an instance of that catchall domain for the rare time you need to send email as mortgage_company@a.domain.com . You can also create rules to blackhole a specific alias email or whatever you want when you need to invalidate the email.

So how would you handle this breach with your fastmail alias?

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#88
post #6

I feel bad for the people affected but at least the scummy company got what it deserved for stealing tips (for those unaware, they used to withhold the total tips out of a delivery drivers base compensation so essentially taking the tips for themselves). Now if they could just completely die so a more ethical competitor can take its place it would be even better.

What would be best is for everyone to not ask or expect tips, instead of utilizing this social pressure system to display deflated prices.

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#89
post #86
post #13

> The information accessed is not sufficient to make fraudulent charges on your payment card. In other words... "We leaked a bunch of your personal information, but at least it's not enough data to steal your money!" All of these leaks have the cumulative effect of making ineffective very commonly used security verification questions: "Can I verify that last 4 of your social? And the last 4 of your credit card?" How…

What websites are storing your mother’s maiden name? Besides maybe the bank

[deleted]

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#90
post #13

> The information accessed is not sufficient to make fraudulent charges on your payment card. In other words... "We leaked a bunch of your personal information, but at least it's not enough data to steal your money!" All of these leaks have the cumulative effect of making ineffective very commonly used security verification questions: "Can I verify that last 4 of your social? And the last 4 of your credit card?" How…

Surely the actual problem here is that the responsibility for reliable identification somehow falls on the consumer, not the bank or what have you? I'll give an example: if I get a phishing email claiming to be from my bank, and end up wiring them $1000, I'm out $1000 for not having done the due diligence for verifying that it in fact was my bank; my bank doesn't suddenly owe me $1000. Somehow, though, if some 3rd pa…

> Somehow, though, if some 3rd party convinces the bank they're me, and withdraws $1000 from my account, I'm at fault as a victim of "identity fraud" (and am again out $1000, but this time as a result of my bank's incompetence).

This isn't true, though. The bank is the one on the hook.. eventually. The problem, of course, is that you have to get the bank to agree that it wasn't you who made the withdraw..

While it sucks, I am struggling to figure out alternative solutions.

Let's suppose we did the opposite; if you tell the bank that it wasn't you, then they have to prove it was, and in the meantime they give you the money. Sounds great, but this makes fraud about as easy as you can get - open an account, deposit $50,000, then transfer it somewhere else and withdraw it to cash. Then, tell the first bank that it wasn't you that did it. Sure, they will be able to prove it was you eventually.... but according to our new rules, they have to return the money while they figure it out... you withdraw it all and flee.

There would be literally NOTHING the bank could do to prevent this sort of fraud. They could put a million checks in place, but since they would still need to 'prove' it was you when you claim it was fraudulent, and make you whole in the meantime, you could still steal the money during that time. You claim fraud, they put the money back into your account.. and then they show someone (who? an arbiter? the gov?) that they have video evidence of you making the withdraw. While the ruling is happening, you skip town with the money.

It really sucks, and I really can't think of a solution.

Post reply on HN