It'd be nice if there was a way to way that pile of emails at some authority and say "Here, this is the crap that's come of that data breach." Ditto for any authorized (but shady) third party data sharing. Sadly we currently lack a consumer protection bureau.
This is the part the is really missing. I use user.site@mydomain.com whenever I sign up at random sites. Last night I got a bunch of spams at the just-eat [1] account (food delivery, operating in 13 countries so not a small operation). Now I know they've been breached, but: 1. They haven't reported it anywhere. 2. I don't know of any meaningful action I can take. [1] https://en.wikipedia.org/wiki/Just_Eat
That would be an interesting project, create the breach-via-spam sensor network via accounts.
It also might not be a breach, but could of been sold via some sort marketing 'partnership'.
(Throwaway account) I used to work for a third-party service provider that merchants send this sort of data to for lots of users. Considering there weren't lots of customers using this provider making similar posts, and Doordash didn't call out the provider, it wouldn't surprise me if a Doordash employee account with that provider got compromised. The blog post was carefully worded to not throw the provider under the…
I cant figure out what "third party provider" you send passwords to though?
This was great to get an email about since doordash does not let users delete accounts. You can only 'deactivate' in a way that is easy to 'reactivate'. If I would have actually been allowed to delete my account many months ago when I asked maybe I wouldn't have had my information leaked.
I received the email. I'd asked them to delete my account 6 months ago, and they confirmed at the time they'd "deactivated" it. I guess that wasn't enough to protect me. As an American developer, GDPR seemed like a pain at first, but more and more I wish we had something similar.
If militaries have any imagination, they already have this data for their adversaries' populations and have cyber weapons ready to do this quickly at massive scale.
I'd assumed that was the motivation for the OPM hack. Helps root out agents and handlers since they have SF-86 forms and biometrics, but also a massive database for identity fraud. Also helps with money laundering, which even richer states can benefit from.
Editor's clarification: United States Office of Personnel Management(OPM)
Alternatively, we might be headed for sane data breach and privacy laws. Something like... if you want to store personal data then pay for an external audit or have your domain confiscated - done.
Ever since the enacting of the GDPR I've seen a substantial uptick in the number of companies that take their data liabilities serious.
Not doordash, apparently. Their CS agents and supervisors were completely unaware of GDPR and unable (or unwilling) to delete accounts.
Except they AREN'T on the hook for the fraud... the merchants are. They are doing fine because they pass on the costs to the merchants. Also, when you dispute a charge, they are able to put the money in 'escrow', basically, while they investigate... since they control both sides of the transaction (both merchant and customer), they 'keep' the money while they resolve it. If they find in the card user's favor, they de…
> Also, when you dispute a charge, they are able to put the money in 'escrow', basically, while they investigate... since they control both sides of the transaction (both merchant and customer), they 'keep' the money while they resolve it. If they find in the card user's favor, they deduct it from the merchant account and credit it back to the card user. Otherwise, they release the hold and the merchant can withdraw…
I mean, they can't really 'invest it' since it was their money in the first place. They are loaning it to the credit card holder, who is giving it to the merchant. In this case they just don't loan it out until the case is resolved.
Except they AREN'T on the hook for the fraud... the merchants are. They are doing fine because they pass on the costs to the merchants. Also, when you dispute a charge, they are able to put the money in 'escrow', basically, while they investigate... since they control both sides of the transaction (both merchant and customer), they 'keep' the money while they resolve it. If they find in the card user's favor, they de…
> Also, when you dispute a charge, they are able to put the money in 'escrow', basically, while they investigate... since they control both sides of the transaction (both merchant and customer), they 'keep' the money while they resolve it. If they find in the card user's favor, they deduct it from the merchant account and credit it back to the card user. Otherwise, they release the hold and the merchant can withdraw…
Visa and Mastercard are card schemes. They are just moving the money between financial institutions. The issuer (which is the financial institution from where the credit card was applied from) is providing the credit line=they own the money. The scheme ensures that the other parties always gets their money, which is why their business is really dependent on good fraud detection algorithms. The payment schema will just freeze the settlements during the dispute, but if evidence is found that it was fraud, they will lose the money. This of course happens all the time, but it is just a pricing issue. Visa charges license fees from issuer and acquirer, and every transaction costs for the merchant around 0.5-5% depending on the card.