Earlier quoted context omitted.
Hell, imagine how many scans of people’s passports and driver’s licenses are sitting in databases waiting to be leaked, yet images of those documents let you authenticate with all sorts of financial institutions online from banks to Coinbase to Paypal. We really need to rethink all this. Until then, it feels like mere luck that today wasn’t the day someone decided to social engineer their way into your life. Everythi…
If militaries have any imagination, they already have this data for their adversaries' populations and have cyber weapons ready to do this quickly at massive scale.
DoorDash confirms data breach affected 4.9M customers, workers and merchants
121–130 of 224 posts
Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants
#122Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants
#123> The information accessed is not sufficient to make fraudulent charges on your payment card. In other words... "We leaked a bunch of your personal information, but at least it's not enough data to steal your money!" All of these leaks have the cumulative effect of making ineffective very commonly used security verification questions: "Can I verify that last 4 of your social? And the last 4 of your credit card?" How…
Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants
#124There is a silver lining in all these data breaches. At some point in time all our data will have been leaked at least once and probably more than once and subsequent leaks will not do any more damage. The safe assumption would then be to not trust any accounts created online without some good old KYC processes in place requiring live verification of identity.
A government created physical token for every person could be the direction we are headed
Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants
#125Earlier quoted context omitted.
What websites are storing your mother’s maiden name? Besides maybe the bank
Anyone that asks a security question, eBay for one.
Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants
#126Earlier quoted context omitted.
So how would you handle this breach with your fastmail alias?
If I start noticing annoying spam being sent to doordash@a.domain.com then I make an email rule to delete it and change my doordash account email to doordash_again@a.domain.com along with a password change with my password manager?
Sadly we currently lack a consumer protection bureau.
Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants
#127Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants
#128DoorDash probably forgot to tip the “third-party service provider”
Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants
#129Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants
#130I used to work for a third-party service provider that merchants send this sort of data to for lots of users. Considering there weren't lots of customers using this provider making similar posts, and Doordash didn't call out the provider, it wouldn't surprise me if a Doordash employee account with that provider got compromised. The blog post was carefully worded to not throw the provider under the bus, but also avoid taking blame, themselves.
The telling bit is that the last four digits of credit card numbers were sent. There are only a few types of vendors you'd send that data to.