Live data from Hacker News

DoorDash confirms data breach affected 4.9M customers, workers and merchants

techcrunch.com

91–100 of 224 posts

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#91

At this point HN should just have a permanent module in the top right corner announcing the latest data breach.

Breaking news: There is someone who has been walkabout living in the woods since 2000, and nobody has his data!

I know you're joking, but I have a relative like this.

Owns a huge swath of land someplace remote. Only deals in cash. (His special skills are such that his employer gladly pays him in cash.) Doesn't trust cars with electronics, so he builds his own motorcycles to get around. As far as I know, the only record of him existing is property tax and income tax.

I went to visit once, and he doesn't even have a mailbox. I assume he has a PO Box somewhere. He built his own house. It's not a very good house, but it's good enough for him and his wife. The only electronics he has is a TV that runs off of some kind of tiny water mill in the creek. It only gets over-the-air channels.

I guess he's happy, but it's not the kind of happiness I could bear. He also seems to have lost all interest in shaving.

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#92
post #86
post #13

> The information accessed is not sufficient to make fraudulent charges on your payment card. In other words... "We leaked a bunch of your personal information, but at least it's not enough data to steal your money!" All of these leaks have the cumulative effect of making ineffective very commonly used security verification questions: "Can I verify that last 4 of your social? And the last 4 of your credit card?" How…

What websites are storing your mother’s maiden name? Besides maybe the bank

Anyone that asks a security question, eBay for one.

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#93
post #48

Earlier quoted context omitted.

It's far too common now and there doesn't seem to be any meaningful consequences for the websites/companies involved.

IMO think this is the core of the issue. As long as there are no serious consequences for leaking user's data these things are going to continue to happen.

But if you suggest large fines for data breaches, suddenly HN resounds with a chorus of "regulatory capture!"

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#94

Earlier quoted context omitted.

The problem with what you're proposing is that, as far as I understand, the real "consequences" for things like identity theft end up being intangibles like "time" and "annoyance" or "credit score". I don't think you'll actually be out $1000, the bank will just reverse it or it will be covered under some sort of insurance or something. Many times its just people taking out fraudulent loans under your name (vs. direct…

Except that it can take months or years for the affected individual to clear up their credit record. And they may still end up on the hook for some of that debt. There is a direct and immediate impact on the individual in terms of debt against them and whatever credit reporting occurs on that debt. There is more distant impact on the lenders to eventually eat the losses - which in aggregate are in fact quite large -…

It's worth distinguishing between the lenders and the credit bureaus. The latter cause much of the pain around identity theft afaik.

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#95

Earlier quoted context omitted.

Surely the actual problem here is that the responsibility for reliable identification somehow falls on the consumer, not the bank or what have you? I'll give an example: if I get a phishing email claiming to be from my bank, and end up wiring them $1000, I'm out $1000 for not having done the due diligence for verifying that it in fact was my bank; my bank doesn't suddenly owe me $1000. Somehow, though, if some 3rd pa…

> Somehow, though, if some 3rd party convinces the bank they're me, and withdraws $1000 from my account, I'm at fault as a victim of "identity fraud" (and am again out $1000, but this time as a result of my bank's incompetence). This isn't true, though. The bank is the one on the hook.. eventually. The problem, of course, is that you have to get the bank to agree that it wasn't you who made the withdraw.. While it su…

All of that argumentation is nice but it doesn’t hold any water.

Credit card companies are by law on the hook for any fraud committed with your credit card. Everything you just wrote applies to credit cards, and yet Visa and Mastercard are doing just fine. They aren’t going bankrupt just because you can file a chargeback whenever you want as a consumer.

There doesn’t seem to be any doubt Banks can handle this, because they already do.

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#96

There is a silver lining in all these data breaches. At some point in time all our data will have been leaked at least once and probably more than once and subsequent leaks will not do any more damage. The safe assumption would then be to not trust any accounts created online without some good old KYC processes in place requiring live verification of identity.

A government created physical token for every person could be the direction we are headed

https://en.wikipedia.org/wiki/Estonian_identity_card

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#97

There is a silver lining in all these data breaches. At some point in time all our data will have been leaked at least once and probably more than once and subsequent leaks will not do any more damage. The safe assumption would then be to not trust any accounts created online without some good old KYC processes in place requiring live verification of identity.

A government created physical token for every person could be the direction we are headed

I've had that thought, but then someone steals your token…

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#98
post #77

The classic trite "We take the security of our community very seriously." Nearly every corporate communication about a breach says it and often it comes out to have been demonstrably untrue.

It's like the data breach version of "It's been an incredible journey!" after getting acquired.

Someone should make a Tumblr for data breach marketing copy.

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#99

Earlier quoted context omitted.

IMO think this is the core of the issue. As long as there are no serious consequences for leaking user's data these things are going to continue to happen.

But if you suggest large fines for data breaches, suddenly HN resounds with a chorus of "regulatory capture!"

Large fines can—and probably should—be relative.

Edit: I’m not sure I’ve ever heard anyone suggest “regulatory capture” as a reason to not levy fines against companies who held breached data. HN discussions on this topic seem to trade in the same repeated points—“identity theft” is bank failure/fraud masquerading as the customer’s problem; there should be consequences and/or fines for the party who held the data; the frequency of breaches should make us rethink how private PII really is; etc.

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#100
post #97

Earlier quoted context omitted.

A government created physical token for every person could be the direction we are headed

I've had that thought, but then someone steals your token…

Maybe it could be surgically implanted to deter theft
Post reply on HN