Live data from Hacker News

DoorDash confirms data breach affected 4.9M customers, workers and merchants

techcrunch.com

181–190 of 224 posts

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#181
post #173

I'd like to point out, it's not "DoorDash" that has done anything wrong, it's these people : - Andy Fang - Evan Moore - Stanley Tang - Tony Xu They decided our security and privacy wasn't worth as much as hur hur hur growth hacking startup hur hur next uber, and couldn't be arsed to even give us a proper apology. Look at their blog post: not one mention of the words "we sorry, we fucked up". It's all about the other…

Could not agree more. There's a tendency to not blame founders... but why? They created the product from the ground up. They had a choice on how to build security and chose the easy way out. They should be held to a higher standard given the power dynamics they have over the company and its users.

[deleted]

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#182
post #173

I'd like to point out, it's not "DoorDash" that has done anything wrong, it's these people : - Andy Fang - Evan Moore - Stanley Tang - Tony Xu They decided our security and privacy wasn't worth as much as hur hur hur growth hacking startup hur hur next uber, and couldn't be arsed to even give us a proper apology. Look at their blog post: not one mention of the words "we sorry, we fucked up". It's all about the other…

I agree there should be real people (founders, c-levels, engineering managers, etc) taking responsibility for things like this. Another place to look at is the insurance companies who sell cyber liability policies to basically all (even small) tech companies. Those policies provide near full coverage for the most expensive parts of breaches like these (including a set dollar value, often $100-200k in policies I've seen, to hire a PR firm to recover from the media fallout). These policies are often surprisingly cheap (you can get very good coverage for $10k / year)

Edit: A common complaint with these type of announcements is the lack of owning the mistake. Just wanted to point out that this is almost certainly a result of the company contact their insurance carrier about the incident, and the insurance carrier instructing the company how to respond to the event (in order to remain eligible for benefits under the policy). It’s not a great excuse, but there is a reason that’s slightly outside the control of management.

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#184

Earlier quoted context omitted.

Breaking news: There is someone who has been walkabout living in the woods since 2000, and nobody has his data!

I know you're joking, but I have a relative like this. Owns a huge swath of land someplace remote. Only deals in cash. (His special skills are such that his employer gladly pays him in cash.) Doesn't trust cars with electronics, so he builds his own motorcycles to get around. As far as I know, the only record of him existing is property tax and income tax. I went to visit once, and he doesn't even have a mailbox. I a…

Maybe we’re dealing with the same guy. Lives out in the woods. He only corresponds by fax. Checks are sent to a PO Box. Machinist who creates custom metal work.

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#185

Earlier quoted context omitted.

The type of fraud you described (or at least a very close version of it) is already possible, and happens all the time. The way they manage this is that wire fraud is a federal crime, that will land you with a lot more prison time than you might think.

Wire fraud has no mandatory minimum and depending on the transaction value the sentencing guidelines are very light. The killer is ID theft which carries 24 month mandatory minimum with no ability to run concurrently with any other charge.

My point simply being that most of these types of fraud are rather easy to commit, but actually quite hard to get away with, and the consequences can be very severe. I’ve worked with quite a few US financial institutions, and a lot of their fraud investigations end up with arrest warrants.

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#186
post #173

I'd like to point out, it's not "DoorDash" that has done anything wrong, it's these people : - Andy Fang - Evan Moore - Stanley Tang - Tony Xu They decided our security and privacy wasn't worth as much as hur hur hur growth hacking startup hur hur next uber, and couldn't be arsed to even give us a proper apology. Look at their blog post: not one mention of the words "we sorry, we fucked up". It's all about the other…

Is there something about this story that makes you think it's an issue of negligence rather than a capable intruder? We keep getting told that total security is impossible. Isn't this inevitable? Is it just that they waited too long to disclose it?

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#187
post #46

Earlier quoted context omitted.

Hell, imagine how many scans of people’s passports and driver’s licenses are sitting in databases waiting to be leaked, yet images of those documents let you authenticate with all sorts of financial institutions online from banks to Coinbase to Paypal. We really need to rethink all this. Until then, it feels like mere luck that today wasn’t the day someone decided to social engineer their way into your life. Everythi…

If militaries have any imagination, they already have this data for their adversaries' populations and have cyber weapons ready to do this quickly at massive scale.

Their first targets would be things like power plants, tv stations, and central network nodes. Sowing chaos is useful, sorta, but that means things are still usable -- and the OpFor can potentially hit back. Better off just silencing the wires altogether; hit the power plants, tv and radio stations, major telephone & data centers, undersea cables, etc.

If I had $40B to budget on cyber warfare I'm finding out how to hack nuclear plants or cause hydroelectric dam overloads, not tinker with the Amazon accounts of the flyover states.

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#188

Earlier quoted context omitted.

Anyone that asks a security question, eBay for one.

Only if you provided that information as answer. kwPP2ET6cJMFXVD7BXKJ is an acceptable answer to the maiden name question.

I like swear words. It's fun to tell online personnel your first high school is "Eat A Dick, Son".

High graduation rates at EADS HS, for the record.

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#189

Earlier quoted context omitted.

Equifax's story is different, people don't have a choice whether to use them (if people did they'd already be out of business) and they have a near-monopoly, not to mention they are profitable so they are here to stay. Doordash? They're just a shitty startup trying to "disrupt" the market by forgetting laws and morals and are only surviving thanks to VC money. People are not obliged to use them, and since they're ess…

> Doordash's inevitable demise Perhaps it's different elsewhere, but out of the services I use here in Houston, Doordash is consistently the best experience. Obviously if one of those competitors can best them in categories that matter (cost, speed, and accuracy) I'll switch.

Anecdotally they've been the worst. Since you're adding a delivery middle man to the process instead of having a restaurant deliver straight to you, the food is usually later and colder. I think the only reason to use them is if you're craving something that is farther away or doesn't deliver, like fast food. But then you're paying a premium for colder/crappier food.

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#190
post #173

I'd like to point out, it's not "DoorDash" that has done anything wrong, it's these people : - Andy Fang - Evan Moore - Stanley Tang - Tony Xu They decided our security and privacy wasn't worth as much as hur hur hur growth hacking startup hur hur next uber, and couldn't be arsed to even give us a proper apology. Look at their blog post: not one mention of the words "we sorry, we fucked up". It's all about the other…

sorry, who are these people you've just graciously named??
Post reply on HN