Live data from Hacker News

DoorDash confirms data breach affected 4.9M customers, workers and merchants

techcrunch.com

201–210 of 224 posts

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#201
post #13

> The information accessed is not sufficient to make fraudulent charges on your payment card. In other words... "We leaked a bunch of your personal information, but at least it's not enough data to steal your money!" All of these leaks have the cumulative effect of making ineffective very commonly used security verification questions: "Can I verify that last 4 of your social? And the last 4 of your credit card?" How…

Surely the actual problem here is that the responsibility for reliable identification somehow falls on the consumer, not the bank or what have you? I'll give an example: if I get a phishing email claiming to be from my bank, and end up wiring them $1000, I'm out $1000 for not having done the due diligence for verifying that it in fact was my bank; my bank doesn't suddenly owe me $1000. Somehow, though, if some 3rd pa…

> and am again out $1000, but this time as a result of my bank's incompetence

> If the onus for verifying your identity were on institutions

Your two situations are really the same situation.

1. You give your money to another party, and then claim they committed fraud. You can't just instantly seize $1000 from them; you must prove that they committed fraud.

2. You give your money to another party to manage, and then claim they breached contract. You can't just instantly seize $1000 from them; you must prove they violated the contract.

In both cases, the legal onus is on the accuser to demonstrate criminal activity ("innocent until proven guilty"). Otherwise, you could walk around claiming people and banks owe you money and simply be presumed correct.

(Also, in both cases, it would be have been better for you to not to trust those particular parties.)

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#202

Earlier quoted context omitted.

sorry, who are these people you've just graciously named??

The founders (and current CEO and CTO) of DoorDash.

thx, I just wasn't sure exactly who it was

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#203

Earlier quoted context omitted.

> devising wage theft schemes Expand?

There was recently a controversy over how Doordash implemented its tipping policy. Drivers get paid a wage to deliver food to you, and you would expect that if you specify a tip through the application, that tip goes to the driver and their compensation is increased by N, where N is the amount of the tip you specified. It turned out that until recently, that was not the case; drivers would get a wage to deliver food…

Yikes.

That is extremely misleading. Another reason to tip in cash, I suppose :/

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#204
post #199
post #182

Earlier quoted context omitted.

I agree there should be real people (founders, c-levels, engineering managers, etc) taking responsibility for things like this. Another place to look at is the insurance companies who sell cyber liability policies to basically all (even small) tech companies. Those policies provide near full coverage for the most expensive parts of breaches like these (including a set dollar value, often $100-200k in policies I've se…

Really interesting. Do you know who the biggest insurers are?

A couple examples: Beazley, The Hartford. There are lots. Most companies have an insurance broker who goes out to the various insurance companies and brings the quotes/options to the companies to choose from. https://foundershield.com/ is one example of a broker for small/medium size companies.

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#205
post #198

Earlier quoted context omitted.

> devising wage theft schemes Expand?

Basically if you "tip" a driver through DoorDash, the tip doesn't really end up going to them. https://qz.com/1659475/the-merits-of-tipping-your-doordash-d...

DoorDash implemented that scheme to give more consistent payments to workers, as tips are quite variable. Anyway, if it helps, DoorDash is currently moving away from that model. [0]

[0] https://www.theverge.com/2019/8/22/20828742/doordash-tipping...

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#208
post #173

I'd like to point out, it's not "DoorDash" that has done anything wrong, it's these people : - Andy Fang - Evan Moore - Stanley Tang - Tony Xu They decided our security and privacy wasn't worth as much as hur hur hur growth hacking startup hur hur next uber, and couldn't be arsed to even give us a proper apology. Look at their blog post: not one mention of the words "we sorry, we fucked up". It's all about the other…

I would subscribe to a blog you write about the people (with names, photos) behind every single business fuckup, especially if it is a decision made because of greed.

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#209

Earlier quoted context omitted.

The founders are very busy devising wage theft schemes. How can they possibly spend time on security or apologies?

> devising wage theft schemes Expand?

Instacart and DoorDash used to deduct tips from the money paid to drivers so drivers make the same regardless of whether they receive tips or not. Instacart changed their policy in February 2019 while DoorDash changed it in the last month. Other delivery services like UberEats, Postmates, and Grubhub did not engage in this practice.

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#210
post #173

I'd like to point out, it's not "DoorDash" that has done anything wrong, it's these people : - Andy Fang - Evan Moore - Stanley Tang - Tony Xu They decided our security and privacy wasn't worth as much as hur hur hur growth hacking startup hur hur next uber, and couldn't be arsed to even give us a proper apology. Look at their blog post: not one mention of the words "we sorry, we fucked up". It's all about the other…

Is there something about this story that makes you think it's an issue of negligence rather than a capable intruder? We keep getting told that total security is impossible. Isn't this inevitable? Is it just that they waited too long to disclose it?

(clarifying since I've gotten one downvote as of now): Of course we should all be mad about the general state of computer security. I'm just trying to figure out if I really should be avoiding DoorDash in particular or is this just a straw breaking a camel's back?
Post reply on HN