Live data from Hacker News

DoorDash confirms data breach affected 4.9M customers, workers and merchants

techcrunch.com

171–180 of 224 posts

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#171
This kind of bugs and problems will open the eyes of companies to get on to blockchain. As a Blockchian enthusiast, i found it is best to store data on it. And in market many companies doing the same too. to fire more questions and query drop a mail on sagar@trsts.co

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#172

This was great to get an email about since doordash does not let users delete accounts. You can only 'deactivate' in a way that is easy to 'reactivate'. If I would have actually been allowed to delete my account many months ago when I asked maybe I wouldn't have had my information leaked.

My doordash got hacked a year ago when they did not have a special call center set up. I had no choice but to file a support ticket into the void (which was even more difficult since I did not have access to my account so I had to use a public contact form). I always suspected a breach since the account had a unique password and was only used on my personal phone which I was still in possession of. I wonder if they are just now getting around to disclosing that breach?

I did not hear back from support for 3 months (no exaggeration). I asked that they delete my account back then so you can imagine my delight to receive more security-related correspondence from this company today.

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#173
I'd like to point out, it's not "DoorDash" that has done anything wrong, it's these people:

- Andy Fang

- Evan Moore

- Stanley Tang

- Tony Xu

They decided our security and privacy wasn't worth as much as hur hur hur growth hacking startup hur hur next uber, and couldn't be arsed to even give us a proper apology.

Look at their blog post: not one mention of the words "we sorry, we fucked up".

It's all about the other guys.

The bad guys.

The guys who stole your data not us, and you should change your password with us to protect your account with us.

No. That's wrong. Look at the 295 million people who weren't affected -- all the people who don't use doordash at all!

That means the best way to protect yourself is to simply not use doordash. Delete it. Delete the email account and the bank/credit card you used with them (ask your bank/credit card company for a new number). Move if you've got to (drivers license details!?!?!?) You have no other protection now- you're fucked. They have your data, and they're only going to risk it again.

And remember how difficult it is to get in control of your data again when the next breach happens, the next time you're thinking about signing up with something, or you're getting ready to vote.

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#174
post #173

I'd like to point out, it's not "DoorDash" that has done anything wrong, it's these people : - Andy Fang - Evan Moore - Stanley Tang - Tony Xu They decided our security and privacy wasn't worth as much as hur hur hur growth hacking startup hur hur next uber, and couldn't be arsed to even give us a proper apology. Look at their blog post: not one mention of the words "we sorry, we fucked up". It's all about the other…

Could not agree more. There's a tendency to not blame founders... but why? They created the product from the ground up. They had a choice on how to build security and chose the easy way out. They should be held to a higher standard given the power dynamics they have over the company and its users.

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#175
post #6

I feel bad for the people affected but at least the scummy company got what it deserved for stealing tips (for those unaware, they used to withhold the total tips out of a delivery drivers base compensation so essentially taking the tips for themselves). Now if they could just completely die so a more ethical competitor can take its place it would be even better.

They did no such thing, and I find it frustrating that people keep repeating this falsehood. Doordash promised to pay drives at least $X (where X was, I believe $1 or something like that) AND that the driver will make at least $Y from the delivery. The driver always gets the tip, plus a variable amount from DD. This is _exactly_ how it works for wait staff in restaurants in most states, except that is by hour instead…

> This is _exactly_ how it works for wait staff in restaurants in most states, except that is by hour instead of delivery. For example, in MA, the restaurant pays out a minimum of $3.75 (wait staff minimum wage in MA) and guarantees that the wait-person makes $11 (actual minimum wage).

This is deceptive.

The big difference is that Doordash's calculation is redone for every order delivered. With wait staff past minimum wage the tip you give them doesn't in any way reduce the amount of money the business pays them. The business pays them the same amount if they make $1/hour above minimum wage or $20/hour above minimum wage.

With Doordash on the other hand, the tip you give _always_ reduces the amount Doordash pays. You are essentially subsidizing Doordash's payment of the driver.

This is deceptive because most people expect that when they leave a tip that the amount of the tip they leave will directly increase the income of the person they're tipping. In reality, a Doordash driver is very unlikely to make additional money because of your tip unless you tip a large amount. To top this off Doordash advertised tips as "100% goes to the driver", which is extremely scummy because it obviously is intended to trick people into this belief.

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#176
post #173

I'd like to point out, it's not "DoorDash" that has done anything wrong, it's these people : - Andy Fang - Evan Moore - Stanley Tang - Tony Xu They decided our security and privacy wasn't worth as much as hur hur hur growth hacking startup hur hur next uber, and couldn't be arsed to even give us a proper apology. Look at their blog post: not one mention of the words "we sorry, we fucked up". It's all about the other…

The founders are very busy devising wage theft schemes. How can they possibly spend time on security or apologies?

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#177
post #13

> The information accessed is not sufficient to make fraudulent charges on your payment card. In other words... "We leaked a bunch of your personal information, but at least it's not enough data to steal your money!" All of these leaks have the cumulative effect of making ineffective very commonly used security verification questions: "Can I verify that last 4 of your social? And the last 4 of your credit card?" How…

Unless you have a domain with GoDaddy, of course...

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#179

Earlier quoted context omitted.

> Somehow, though, if some 3rd party convinces the bank they're me, and withdraws $1000 from my account, I'm at fault as a victim of "identity fraud" (and am again out $1000, but this time as a result of my bank's incompetence). This isn't true, though. The bank is the one on the hook.. eventually. The problem, of course, is that you have to get the bank to agree that it wasn't you who made the withdraw.. While it su…

The type of fraud you described (or at least a very close version of it) is already possible, and happens all the time. The way they manage this is that wire fraud is a federal crime, that will land you with a lot more prison time than you might think.

Wire fraud has no mandatory minimum and depending on the transaction value the sentencing guidelines are very light. The killer is ID theft which carries 24 month mandatory minimum with no ability to run concurrently with any other charge.

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#180
post #173

I'd like to point out, it's not "DoorDash" that has done anything wrong, it's these people : - Andy Fang - Evan Moore - Stanley Tang - Tony Xu They decided our security and privacy wasn't worth as much as hur hur hur growth hacking startup hur hur next uber, and couldn't be arsed to even give us a proper apology. Look at their blog post: not one mention of the words "we sorry, we fucked up". It's all about the other…

[deleted]
Post reply on HN