Live data from Hacker News

DocuSign email address database breached and used for phishing campaign

trust.docusign.com

11–20 of 141 posts

Re: DocuSign email address database breached and used for phishing campaign

#11
post #5

Earlier quoted context omitted.

I have also used DocuSign to buy a house and receive stock options. It's used all over the edges of the legal system.

Someone asked me to pay a bill using docusign and entering my credit card information into one of those free text boxes They couldn't understand why I refused to do it.

With credit cards, you personally do not have much to worry about, since your card issuer holds the ultimate liability for any fraud that occurs. Just be careful to use a credit card (attached to a reversible ledger) and not a debit card (attached to a less-reversible cash account).

Re: DocuSign email address database breached and used for phishing campaign

#13

Earlier quoted context omitted.

Someone asked me to pay a bill using docusign and entering my credit card information into one of those free text boxes They couldn't understand why I refused to do it.

With credit cards, you personally do not have much to worry about, since your card issuer holds the ultimate liability for any fraud that occurs. Just be careful to use a credit card (attached to a reversible ledger) and not a debit card (attached to a less-reversible cash account).

Are you sure? I don't know how credit card companies in the US behave, but here in the Netherlands I called up mastercard to ask them whether I am liable for any fraud that occurs if I do something like this (or send credit card info over email, like so many hotels want). The credit card company tells me, yes I am liable for any fraud that occurs, because email and unecrypted text boxes on websites are known to be insecure, and so it can be argued that it's my own fault if credit card fraud occurs.

Re: DocuSign email address database breached and used for phishing campaign

#14
In my opinion they're doing well taking responsibility like this and communicating honestly and openly. You can always disagree on how far the openness should go, but I've seen far less openness and far less communication (as in approaching zero), so they deserve some credit doing it this way.

Re: DocuSign email address database breached and used for phishing campaign

#15
post #7

Emails and email addresses are very different in the context of DocuSign. The former includes the text of contracts. The latter is just a list of people who have ever given or received a job offer.

Sure they're different but make no mistake: emails being breached are a big deal! This is an appropriate response https://twitter.com/troyhunt/status/864315287092342785

I fail to see how slightly wider dissemination of a bit of info I post publicly on my profile at this very web site constitutes a privacy or security risk to me.

Re: DocuSign email address database breached and used for phishing campaign

#20

Emails and email addresses are very different in the context of DocuSign. The former includes the text of contracts. The latter is just a list of people who have ever given or received a job offer.

Job offer? DocuSign is used for all kind of things.
Post reply on HN