Earlier quoted context omitted.
It'd be nice if there was a way to way that pile of emails at some authority and say "Here, this is the crap that's come of that data breach." Ditto for any authorized (but shady) third party data sharing. Sadly we currently lack a consumer protection bureau.
This is the part the is really missing. I use user.site@mydomain.com whenever I sign up at random sites. Last night I got a bunch of spams at the just-eat [1] account (food delivery, operating in 13 countries so not a small operation). Now I know they've been breached, but: 1. They haven't reported it anywhere. 2. I don't know of any meaningful action I can take. [1] https://en.wikipedia.org/wiki/Just_Eat
DoorDash confirms data breach affected 4.9M customers, workers and merchants
161–170 of 224 posts
Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants
#162> The information accessed is not sufficient to make fraudulent charges on your payment card. In other words... "We leaked a bunch of your personal information, but at least it's not enough data to steal your money!" All of these leaks have the cumulative effect of making ineffective very commonly used security verification questions: "Can I verify that last 4 of your social? And the last 4 of your credit card?" How…
Surely the actual problem here is that the responsibility for reliable identification somehow falls on the consumer, not the bank or what have you? I'll give an example: if I get a phishing email claiming to be from my bank, and end up wiring them $1000, I'm out $1000 for not having done the due diligence for verifying that it in fact was my bank; my bank doesn't suddenly owe me $1000. Somehow, though, if some 3rd pa…
Of course, this does not mean that being a victim of identity theft does not suck.
The stolen information has some other severe side effects, which are not directly personal. The stolen credit card information and the drivers licenses are typically used for things like human trafficing. You buy some airline tickets with fake passport and stolen credit card, and travel as someone else.
Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants
#163Earlier quoted context omitted.
Surely the actual problem here is that the responsibility for reliable identification somehow falls on the consumer, not the bank or what have you? I'll give an example: if I get a phishing email claiming to be from my bank, and end up wiring them $1000, I'm out $1000 for not having done the due diligence for verifying that it in fact was my bank; my bank doesn't suddenly owe me $1000. Somehow, though, if some 3rd pa…
> Somehow, though, if some 3rd party convinces the bank they're me, and withdraws $1000 from my account, I'm at fault as a victim of "identity fraud" (and am again out $1000, but this time as a result of my bank's incompetence). This isn't true, though. The bank is the one on the hook.. eventually. The problem, of course, is that you have to get the bank to agree that it wasn't you who made the withdraw.. While it su…
Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants
#164> The information accessed is not sufficient to make fraudulent charges on your payment card. In other words... "We leaked a bunch of your personal information, but at least it's not enough data to steal your money!" All of these leaks have the cumulative effect of making ineffective very commonly used security verification questions: "Can I verify that last 4 of your social? And the last 4 of your credit card?" How…
The cynic in me thinks they leaked names, addresses, and credit card numbers but not the CVV number. Without the CVV it's not technically possible to make charges, so it would not be a lie. I think it's been clear since Equifax that private data can't be used to prove identity. I honestly wish the hacker behind that attack just gave away the entire dataset to the public. It would have stung a little at first, but it…
You can process charges without the cvv, but it costs your more to process them and is supposed to lower the risk.
Some big players like Amazon still process payments without the need of providing a cvv.
Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants
#165Earlier quoted context omitted.
Ever since the enacting of the GDPR I've seen a substantial uptick in the number of companies that take their data liabilities serious.
Not doordash, apparently. Their CS agents and supervisors were completely unaware of GDPR and unable (or unwilling) to delete accounts.
Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants
#166Earlier quoted context omitted.
Surely the actual problem here is that the responsibility for reliable identification somehow falls on the consumer, not the bank or what have you? I'll give an example: if I get a phishing email claiming to be from my bank, and end up wiring them $1000, I'm out $1000 for not having done the due diligence for verifying that it in fact was my bank; my bank doesn't suddenly owe me $1000. Somehow, though, if some 3rd pa…
I think that this is extension of semantic play that such leaks lead to "identity theft". Even if you took due diligence to protect your credit card and SSN or other personal info after the fact you are being played as "victim of identity theft". No it is not identity theft that someone used yours info to take fast loan or buy bitcoin with your credict card that incompetent business lost and now you are SOL with ruin…
Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants
#167(Throwaway account) I used to work for a third-party service provider that merchants send this sort of data to for lots of users. Considering there weren't lots of customers using this provider making similar posts, and Doordash didn't call out the provider, it wouldn't surprise me if a Doordash employee account with that provider got compromised. The blog post was carefully worded to not throw the provider under the…
I cant figure out what "third party provider" you send passwords to though?
Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants
#168Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants
#169Earlier quoted context omitted.
It'd be nice if there was a way to way that pile of emails at some authority and say "Here, this is the crap that's come of that data breach." Ditto for any authorized (but shady) third party data sharing. Sadly we currently lack a consumer protection bureau.
This is the part the is really missing. I use user.site@mydomain.com whenever I sign up at random sites. Last night I got a bunch of spams at the just-eat [1] account (food delivery, operating in 13 countries so not a small operation). Now I know they've been breached, but: 1. They haven't reported it anywhere. 2. I don't know of any meaningful action I can take. [1] https://en.wikipedia.org/wiki/Just_Eat
> If ... you’re concerned about how an organisation has handled your information – if the information is wrong, they have lost it or disclosed it to someone else – tell us.
Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants
#170Earlier quoted context omitted.
> Also, when you dispute a charge, they are able to put the money in 'escrow', basically, while they investigate... since they control both sides of the transaction (both merchant and customer), they 'keep' the money while they resolve it. If they find in the card user's favor, they deduct it from the merchant account and credit it back to the card user. Otherwise, they release the hold and the merchant can withdraw…
Visa and Mastercard are card schemes. They are just moving the money between financial institutions. The issuer (which is the financial institution from where the credit card was applied from) is providing the credit line=they own the money. The scheme ensures that the other parties always gets their money, which is why their business is really dependent on good fraud detection algorithms. The payment schema will jus…