Live data from Hacker News

DoorDash confirms data breach affected 4.9M customers, workers and merchants

techcrunch.com

101–110 of 224 posts

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#101
post #85

Earlier quoted context omitted.

You can do something similar with fastmail. Get a domain for your email and make an alias address of the form [anything]@[alias].domain.com . You can then make 'sending identities' for an instance of that catchall domain for the rare time you need to send email as mortgage_company@a.domain.com . You can also create rules to blackhole a specific alias email or whatever you want when you need to invalidate the email.

So how would you handle this breach with your fastmail alias?

If I start noticing annoying spam being sent to doordash@a.domain.com then I make an email rule to delete it and change my doordash account email to doordash_again@a.domain.com along with a password change with my password manager?

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#102
post #12
post #4

Earlier quoted context omitted.

Huh? The blog post says April 5, 2018.

I'm not sure what you're trying to point out, but it seems like the data was stolen from a third party DoorDash uses, and that they only had data from users that registered on or before April 5, 2018. The breach actually happened on May 4, 2019. (And the 2015 reference in the comment you're replying to is about a Flipboard breach, not DoorDash)

Well, back in 2018, TechCrunch reported that they were compromised. I believe this is the same breach as then. They just reported it one year later.

https://techcrunch.com/2018/09/25/doordash-customers-say-the...

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#103

Earlier quoted context omitted.

> Somehow, though, if some 3rd party convinces the bank they're me, and withdraws $1000 from my account, I'm at fault as a victim of "identity fraud" (and am again out $1000, but this time as a result of my bank's incompetence). This isn't true, though. The bank is the one on the hook.. eventually. The problem, of course, is that you have to get the bank to agree that it wasn't you who made the withdraw.. While it su…

All of that argumentation is nice but it doesn’t hold any water. Credit card companies are by law on the hook for any fraud committed with your credit card. Everything you just wrote applies to credit cards, and yet Visa and Mastercard are doing just fine. They aren’t going bankrupt just because you can file a chargeback whenever you want as a consumer. There doesn’t seem to be any doubt Banks can handle this, becaus…

Except they AREN'T on the hook for the fraud... the merchants are. They are doing fine because they pass on the costs to the merchants.

Also, when you dispute a charge, they are able to put the money in 'escrow', basically, while they investigate... since they control both sides of the transaction (both merchant and customer), they 'keep' the money while they resolve it. If they find in the card user's favor, they deduct it from the merchant account and credit it back to the card user. Otherwise, they release the hold and the merchant can withdraw the money.

It doesn't feel like your money is being held as a card holder, because the 'money' in this case is credit, and it doesn't effect your bank account while it is being resolved. However, it DOES count against your credit limit while they resolve the issue, so it shows you that the money is still 'frozen' while they resolve it. They aren't allowed to charge interest during the dispute, but if you lose the dispute you will have to pay the interest.

This is the same thing that happens when your bank account is defrauded.. the money is frozen, and you can't withdraw it until the dispute is resolved.

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#104

Earlier quoted context omitted.

Breaking news: There is someone who has been walkabout living in the woods since 2000, and nobody has his data!

I know you're joking, but I have a relative like this. Owns a huge swath of land someplace remote. Only deals in cash. (His special skills are such that his employer gladly pays him in cash.) Doesn't trust cars with electronics, so he builds his own motorcycles to get around. As far as I know, the only record of him existing is property tax and income tax. I went to visit once, and he doesn't even have a mailbox. I a…

Equifax has his data probably lol

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#106
post #100
post #97

Earlier quoted context omitted.

I've had that thought, but then someone steals your token…

Maybe it could be surgically implanted to deter theft

I'd prefer "Give me your wallet" to "Give me your arm" any day of the week.

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#107

Earlier quoted context omitted.

Breaking news: There is someone who has been walkabout living in the woods since 2000, and nobody has his data!

I know you're joking, but I have a relative like this. Owns a huge swath of land someplace remote. Only deals in cash. (His special skills are such that his employer gladly pays him in cash.) Doesn't trust cars with electronics, so he builds his own motorcycles to get around. As far as I know, the only record of him existing is property tax and income tax. I went to visit once, and he doesn't even have a mailbox. I a…

Imagine being afraid of car electronics and choosing a motorcycle as your safe method of transport.

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#108
I propose a way to improve cybersecurity: FINE companies who loose sensitive customer data to hackers. Fines can be calculated according to the "breach severity grid" which is based on the type of data that is lost. For example:

1. Personal address, DOB - $15. 2. Each social security $20. 3. Driver license number $25. 4. Bank account numbers $30. etc.

So a loss of 4.9 million social security numbers, DOB and addresses would generate a fine of $171,500,000

Problem solved!

Now, the company will think 100x times BEFORE collecting consumer data if they can actually PROTECT IT. Build robust security FIRST!

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#109
post #100
post #97

Earlier quoted context omitted.

I've had that thought, but then someone steals your token…

Maybe it could be surgically implanted to deter theft

And in the minds of many, the fulfillment of ancient prophecy in that "it causes all, both small and great, both rich and poor, both free and slave,e to be marked on the right hand or the forehead, 17so that no one can buy or sell unless he has the mark, that is, the name of the beast or the number of its name" (Revelation 13:16-17, ESV)

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#110

Earlier quoted context omitted.

Surely the actual problem here is that the responsibility for reliable identification somehow falls on the consumer, not the bank or what have you? I'll give an example: if I get a phishing email claiming to be from my bank, and end up wiring them $1000, I'm out $1000 for not having done the due diligence for verifying that it in fact was my bank; my bank doesn't suddenly owe me $1000. Somehow, though, if some 3rd pa…

The problem with what you're proposing is that, as far as I understand, the real "consequences" for things like identity theft end up being intangibles like "time" and "annoyance" or "credit score". I don't think you'll actually be out $1000, the bank will just reverse it or it will be covered under some sort of insurance or something. Many times its just people taking out fraudulent loans under your name (vs. direct…

'Reverse it' often isn't exactly that simple, or even an option, depending on the method of transfer.
Post reply on HN