Live data from Hacker News

DoorDash confirms data breach affected 4.9M customers, workers and merchants

techcrunch.com

131–140 of 224 posts

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#131
post #84
post #17

Earlier quoted context omitted.

I don’t see the issue? DoorDash authenticated that you own the email account via a trusted third party. Once authenticated they authorized you to use the account associated with that email address. It’d be like someone else booking a hotel room as you. When you show up at the front desk they verify it’s you and then let you into that room because it is after all... yours.

Actually, it's more like someone else booked a hotel room as OP. Since they were there in person, the hotel gave them the room key, and they are in that room taking a shower (updated the phone number in this case). The OP goes in and asks for a room, presents his/her email, and since it matched receives the key to the _same room_. OP then walks into the other guy's room while they are in it. At least that's my unders…

maybe if you said you lost your key, but if you come in and ask to check-in, the clerk isn't just going to hand you a new key. they're going to say, but mr. soandso, you're already checked-in.

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#132
post #124

Earlier quoted context omitted.

A government created physical token for every person could be the direction we are headed

Alternatively, we might be headed for sane data breach and privacy laws. Something like... if you want to store personal data then pay for an external audit or have your domain confiscated - done.

Exactly this. If companies actually had to face serious penalties for every breach, the frequency of them happening would plummet.

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#133

There is a silver lining in all these data breaches. At some point in time all our data will have been leaked at least once and probably more than once and subsequent leaks will not do any more damage. The safe assumption would then be to not trust any accounts created online without some good old KYC processes in place requiring live verification of identity.

But we generate new data that's worth stealing every day

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#134
post #72
post #69

Wonder if I'll get another $25-50 from a class action lawsuit over this.

Nah, you'll be offered 25-50$ but then they'll swap it out for 25-50$ in credit monitoring and/or applebee's coupons at the last minute.

I can't wait for the FTC to issue a statement, it will be something like:

"Applebee's Coupons are clearly the best value for consumers, from savory appetizers to desserts with a kick, you're going to want to take that delicious settlement!"

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#135
post #13

> The information accessed is not sufficient to make fraudulent charges on your payment card. In other words... "We leaked a bunch of your personal information, but at least it's not enough data to steal your money!" All of these leaks have the cumulative effect of making ineffective very commonly used security verification questions: "Can I verify that last 4 of your social? And the last 4 of your credit card?" How…

Surely the actual problem here is that the responsibility for reliable identification somehow falls on the consumer, not the bank or what have you? I'll give an example: if I get a phishing email claiming to be from my bank, and end up wiring them $1000, I'm out $1000 for not having done the due diligence for verifying that it in fact was my bank; my bank doesn't suddenly owe me $1000. Somehow, though, if some 3rd pa…

>reliable identification somehow falls on the consumer, not the bank or what have you?

No, it falls on the bank or what have you. If the bank or what have you gets defrauded they lose the money.

As an unfortunate side effect the fraud might affect a consumers credit, but not due to any kind of responsibility for the fraud.

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#136
DoorDash is the worst. They inexplicably banned me from their platform after giving me a credit for a bad order. I filed several support tickets over several months and kept getting canned responses about how they were "looking into the issue." Eventually I just switched to Uber Eats.

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#137
post #126
post #101

Earlier quoted context omitted.

If I start noticing annoying spam being sent to doordash@a.domain.com then I make an email rule to delete it and change my doordash account email to doordash_again@a.domain.com along with a password change with my password manager?

It'd be nice if there was a way to way that pile of emails at some authority and say "Here, this is the crap that's come of that data breach." Ditto for any authorized (but shady) third party data sharing. Sadly we currently lack a consumer protection bureau.

This is the part the is really missing.

I use user.site@mydomain.com whenever I sign up at random sites. Last night I got a bunch of spams at the just-eat [1] account (food delivery, operating in 13 countries so not a small operation).

Now I know they've been breached, but:

1. They haven't reported it anywhere.

2. I don't know of any meaningful action I can take.

[1] https://en.wikipedia.org/wiki/Just_Eat

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#138

Earlier quoted context omitted.

The problem with what you're proposing is that, as far as I understand, the real "consequences" for things like identity theft end up being intangibles like "time" and "annoyance" or "credit score". I don't think you'll actually be out $1000, the bank will just reverse it or it will be covered under some sort of insurance or something. Many times its just people taking out fraudulent loans under your name (vs. direct…

Except that it can take months or years for the affected individual to clear up their credit record. And they may still end up on the hook for some of that debt. There is a direct and immediate impact on the individual in terms of debt against them and whatever credit reporting occurs on that debt. There is more distant impact on the lenders to eventually eat the losses - which in aggregate are in fact quite large -…

>Except that it can take months or years for the affected individual to clear up their credit record

In what scenario could this take years? Honestly anything beyond a month sounds pretty unlikely unless your identity was abused for an extended period (as in by a family member or such), and even then I don't see how.

As far as I understand the process for getting fraudulent accounts removed from credit reports typically takes less than a week.

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#139
post #124

Earlier quoted context omitted.

A government created physical token for every person could be the direction we are headed

Alternatively, we might be headed for sane data breach and privacy laws. Something like... if you want to store personal data then pay for an external audit or have your domain confiscated - done.

Ever since the enacting of the GDPR I've seen a substantial uptick in the number of companies that take their data liabilities serious.
Post reply on HN