Live data from Hacker News

DoorDash confirms data breach affected 4.9M customers, workers and merchants

techcrunch.com

141–150 of 224 posts

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#141
post #44

>The breach happened on May 4 I don't believe for one second that they didn't know about it for five months! Can someone in the EU please report this so that it's investigated for a GDPR violation? Edit: from the official post on blog.doordash.com: >Earlier this month, we became aware of unusual activity involving a third-party service provider. Of course. This is quite a bit more than the 72 hour window GDPR allows.

DoorDash doesn't operate in the EU, so I don't think they need to care about GDPR.

[deleted]

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#142

Earlier quoted context omitted.

I know you're joking, but I have a relative like this. Owns a huge swath of land someplace remote. Only deals in cash. (His special skills are such that his employer gladly pays him in cash.) Doesn't trust cars with electronics, so he builds his own motorcycles to get around. As far as I know, the only record of him existing is property tax and income tax. I went to visit once, and he doesn't even have a mailbox. I a…

Imagine being afraid of car electronics and choosing a motorcycle as your safe method of transport.

Ya, some pre-2010 car should be perfect.

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#143
post #13

> The information accessed is not sufficient to make fraudulent charges on your payment card. In other words... "We leaked a bunch of your personal information, but at least it's not enough data to steal your money!" All of these leaks have the cumulative effect of making ineffective very commonly used security verification questions: "Can I verify that last 4 of your social? And the last 4 of your credit card?" How…

The cynic in me thinks they leaked names, addresses, and credit card numbers but not the CVV number. Without the CVV it's not technically possible to make charges, so it would not be a lie.

I think it's been clear since Equifax that private data can't be used to prove identity. I honestly wish the hacker behind that attack just gave away the entire dataset to the public. It would have stung a little at first, but it would have saved society a ton of time and money on the long run.

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#144

Earlier quoted context omitted.

Surely the actual problem here is that the responsibility for reliable identification somehow falls on the consumer, not the bank or what have you? I'll give an example: if I get a phishing email claiming to be from my bank, and end up wiring them $1000, I'm out $1000 for not having done the due diligence for verifying that it in fact was my bank; my bank doesn't suddenly owe me $1000. Somehow, though, if some 3rd pa…

The problem with what you're proposing is that, as far as I understand, the real "consequences" for things like identity theft end up being intangibles like "time" and "annoyance" or "credit score". I don't think you'll actually be out $1000, the bank will just reverse it or it will be covered under some sort of insurance or something. Many times its just people taking out fraudulent loans under your name (vs. direct…

Bullshit.

I had a fraudulent charge on my bank account via a “demand draft” (essentially a check without my signature). Yes, I had to spend significant time resolving the issue: going to the bank, having them insist they needed to close my account and reopen a new one, plus changing all my ACH drafts. But, I was very angry with the bank, because their proposed solution caused me hassle and doesn’t protect me from whatever attack vector compromised my account. They would not let me have them refuse to honor such instruments without prior authorization, either.

And, this was over a $40 charge. Had it been $4000, I wouldn’t have been any less angry with them for failing to protect me.

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#145
post #13

> The information accessed is not sufficient to make fraudulent charges on your payment card. In other words... "We leaked a bunch of your personal information, but at least it's not enough data to steal your money!" All of these leaks have the cumulative effect of making ineffective very commonly used security verification questions: "Can I verify that last 4 of your social? And the last 4 of your credit card?" How…

At least with a drivers license it should be pretty easy to commit identity theft and sign up for credit cards/open bank accounts with that person’s identity.

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#146
post #35
post #23

The official blog post doesn't give any information about the breach except "We noticed a third-party had unauthorized access to DoorDash data", and the TechCrunch article says that DoorDash responded that they couldn't explain how the breach happened. How are they so sure that they fixed the underlying cause if they don't even know how the third-party got access in the first place?

It seems like the breach was through a third party that only had old data, since nobody that registered after April 5, 2018 is affected. So it's probably some service that they no longer use and doesn't really need to be fixed or investigated, since all the data they had has already been taken and they (probably) stopped giving them more data a year and a half ago. They should really say who the third party was thoug…

A year ago customers were complaning that their accounts were accounted despite using an unique password to DoorDash. DoorDash at that time denied any hacking incidents.

A more sinister explanation is that DoorDash knew back then who is leaking their data and removed their access. But chose to disclose only just now.

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#147
post #77

The classic trite "We take the security of our community very seriously." Nearly every corporate communication about a breach says it and often it comes out to have been demonstrably untrue.

A sibling site of Our Incredible Journey could be SRS BSNS, with statements by companies to that effect.

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#148
post #63
post #53

Is there a list of all disclosed security breaches somewhere?

The best site I've used is haveibeenpwned.com, seems to be the go-to for most security breaches and has a tool that can notify you when some of your information has been compromised tied to an email address.

I don't like that because if you put in an email address it doesn't reveal whether you've already addressed the issue or not. It just shows if it was included in a breach, great for newbs to go "ooOOOooooOOoo" but useless for anything else.

I also alias email addresses for every service that allows a + sign in the email field, so now I have no way to notice quickly if the email was included in a leak. But I do have a way to know which service got breached or sold info if I start getting additional emails to any particular alias.

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#149
post #77

The classic trite "We take the security of our community very seriously." Nearly every corporate communication about a breach says it and often it comes out to have been demonstrably untrue.

Here's a four-year-old collection:

https://www.troyhunt.com/we-take-security-seriously-otherwis...

> “We take security seriously”, otherwise known as “We didn’t take it seriously enough”

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#150

Earlier quoted context omitted.

All of that argumentation is nice but it doesn’t hold any water. Credit card companies are by law on the hook for any fraud committed with your credit card. Everything you just wrote applies to credit cards, and yet Visa and Mastercard are doing just fine. They aren’t going bankrupt just because you can file a chargeback whenever you want as a consumer. There doesn’t seem to be any doubt Banks can handle this, becaus…

Except they AREN'T on the hook for the fraud... the merchants are. They are doing fine because they pass on the costs to the merchants. Also, when you dispute a charge, they are able to put the money in 'escrow', basically, while they investigate... since they control both sides of the transaction (both merchant and customer), they 'keep' the money while they resolve it. If they find in the card user's favor, they de…

> Also, when you dispute a charge, they are able to put the money in 'escrow', basically, while they investigate... since they control both sides of the transaction (both merchant and customer), they 'keep' the money while they resolve it. If they find in the card user's favor, they deduct it from the merchant account and credit it back to the card user. Otherwise, they release the hold and the merchant can withdraw the money.

> It doesn't feel like your money is being held as a card holder, because the 'money' in this case is credit, and it doesn't effect your bank account while it is being resolved. However, it DOES count against your credit limit while they resolve the issue, so it shows you that the money is still 'frozen' while they resolve it. They aren't allowed to charge interest during the dispute, but if you lose the dispute you will have to pay the interest.

I knew roughly how this worked before, but it didn't occur to me until I read your explanation that this allows the credit card company or bank to invest the money while it's in escrow. So it actually benefits them when fraud happens on your account.

...of course that's a thing. The bankers always win.

Post reply on HN