Live data from Hacker News

DoorDash confirms data breach affected 4.9M customers, workers and merchants

techcrunch.com

161–170 of 224 posts

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#161
post #126

Earlier quoted context omitted.

It'd be nice if there was a way to way that pile of emails at some authority and say "Here, this is the crap that's come of that data breach." Ditto for any authorized (but shady) third party data sharing. Sadly we currently lack a consumer protection bureau.

This is the part the is really missing. I use user.site@mydomain.com whenever I sign up at random sites. Last night I got a bunch of spams at the just-eat [1] account (food delivery, operating in 13 countries so not a small operation). Now I know they've been breached, but: 1. They haven't reported it anywhere. 2. I don't know of any meaningful action I can take. [1] https://en.wikipedia.org/wiki/Just_Eat

You could submit evidence of the breach to security researcher Troy Hunt at HaveIBeenPwned (https://haveibeenpwned.com/FAQs#SubmitBreach). He maintains a database of data breaches and people can sign up to be notified if their info appears in a new breach.

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#162
post #13

> The information accessed is not sufficient to make fraudulent charges on your payment card. In other words... "We leaked a bunch of your personal information, but at least it's not enough data to steal your money!" All of these leaks have the cumulative effect of making ineffective very commonly used security verification questions: "Can I verify that last 4 of your social? And the last 4 of your credit card?" How…

Surely the actual problem here is that the responsibility for reliable identification somehow falls on the consumer, not the bank or what have you? I'll give an example: if I get a phishing email claiming to be from my bank, and end up wiring them $1000, I'm out $1000 for not having done the due diligence for verifying that it in fact was my bank; my bank doesn't suddenly owe me $1000. Somehow, though, if some 3rd pa…

Not sure about US, but this definitely does not apply in the EU. The banks are responsible. Also, the PSD2, which just came into effect here sets standards on person identification, which every financial institution needs to comply.

Of course, this does not mean that being a victim of identity theft does not suck.

The stolen information has some other severe side effects, which are not directly personal. The stolen credit card information and the drivers licenses are typically used for things like human trafficing. You buy some airline tickets with fake passport and stolen credit card, and travel as someone else.

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#163

Earlier quoted context omitted.

Surely the actual problem here is that the responsibility for reliable identification somehow falls on the consumer, not the bank or what have you? I'll give an example: if I get a phishing email claiming to be from my bank, and end up wiring them $1000, I'm out $1000 for not having done the due diligence for verifying that it in fact was my bank; my bank doesn't suddenly owe me $1000. Somehow, though, if some 3rd pa…

> Somehow, though, if some 3rd party convinces the bank they're me, and withdraws $1000 from my account, I'm at fault as a victim of "identity fraud" (and am again out $1000, but this time as a result of my bank's incompetence). This isn't true, though. The bank is the one on the hook.. eventually. The problem, of course, is that you have to get the bank to agree that it wasn't you who made the withdraw.. While it su…

Bitcoin and other digital cash systems that are bearer instruments would change this: if the 1st outgoing transaction is valid, one can't then defraud the bank of the same money. On the flip side, if a user falls for a phishing campaign and sends digital cash to a fraudulent 3rd party, that can't be reversed, either.

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#164
post #13

> The information accessed is not sufficient to make fraudulent charges on your payment card. In other words... "We leaked a bunch of your personal information, but at least it's not enough data to steal your money!" All of these leaks have the cumulative effect of making ineffective very commonly used security verification questions: "Can I verify that last 4 of your social? And the last 4 of your credit card?" How…

The cynic in me thinks they leaked names, addresses, and credit card numbers but not the CVV number. Without the CVV it's not technically possible to make charges, so it would not be a lie. I think it's been clear since Equifax that private data can't be used to prove identity. I honestly wish the hacker behind that attack just gave away the entire dataset to the public. It would have stung a little at first, but it…

> Without the CVV it's not technically possible to make charges, so it would not be a lie.

You can process charges without the cvv, but it costs your more to process them and is supposed to lower the risk.

Some big players like Amazon still process payments without the need of providing a cvv.

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#165

Earlier quoted context omitted.

Ever since the enacting of the GDPR I've seen a substantial uptick in the number of companies that take their data liabilities serious.

Not doordash, apparently. Their CS agents and supervisors were completely unaware of GDPR and unable (or unwilling) to delete accounts.

Doordash is headquartered in San Francisco, that might have something to do with it. Do they even operate in Europe?

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#166
post #81

Earlier quoted context omitted.

Surely the actual problem here is that the responsibility for reliable identification somehow falls on the consumer, not the bank or what have you? I'll give an example: if I get a phishing email claiming to be from my bank, and end up wiring them $1000, I'm out $1000 for not having done the due diligence for verifying that it in fact was my bank; my bank doesn't suddenly owe me $1000. Somehow, though, if some 3rd pa…

I think that this is extension of semantic play that such leaks lead to "identity theft". Even if you took due diligence to protect your credit card and SSN or other personal info after the fact you are being played as "victim of identity theft". No it is not identity theft that someone used yours info to take fast loan or buy bitcoin with your credict card that incompetent business lost and now you are SOL with ruin…

Regarding your first point, there's a very relevant 2-minute sketch from the radio show 'That Mitchell & Webb Sound' that makes a similar argument: https://www.youtube.com/watch?v=CS9ptA3Ya9E

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#167

(Throwaway account) I used to work for a third-party service provider that merchants send this sort of data to for lots of users. Considering there weren't lots of customers using this provider making similar posts, and Doordash didn't call out the provider, it wouldn't surprise me if a Doordash employee account with that provider got compromised. The blog post was carefully worded to not throw the provider under the…

I cant figure out what "third party provider" you send passwords to though?

Yeah. My guess is 3rd Party provider is AWS S3 and a DB backup was accessed.

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#169
post #126

Earlier quoted context omitted.

It'd be nice if there was a way to way that pile of emails at some authority and say "Here, this is the crap that's come of that data breach." Ditto for any authorized (but shady) third party data sharing. Sadly we currently lack a consumer protection bureau.

This is the part the is really missing. I use user.site@mydomain.com whenever I sign up at random sites. Last night I got a bunch of spams at the just-eat [1] account (food delivery, operating in 13 countries so not a small operation). Now I know they've been breached, but: 1. They haven't reported it anywhere. 2. I don't know of any meaningful action I can take. [1] https://en.wikipedia.org/wiki/Just_Eat

They're headquartered in the UK, so I'd start with making a complaint via the Information Comissioner's Office: https://ico.org.uk/make-a-complaint/. The best option is probably "Your personal information concerns":

> If ... you’re concerned about how an organisation has handled your information – if the information is wrong, they have lost it or disclosed it to someone else – tell us.

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#170
post #160

Earlier quoted context omitted.

> Also, when you dispute a charge, they are able to put the money in 'escrow', basically, while they investigate... since they control both sides of the transaction (both merchant and customer), they 'keep' the money while they resolve it. If they find in the card user's favor, they deduct it from the merchant account and credit it back to the card user. Otherwise, they release the hold and the merchant can withdraw…

Visa and Mastercard are card schemes. They are just moving the money between financial institutions. The issuer (which is the financial institution from where the credit card was applied from) is providing the credit line=they own the money. The scheme ensures that the other parties always gets their money, which is why their business is really dependent on good fraud detection algorithms. The payment schema will jus…

Had to check again, visa and Mastercard actually don't carry the risk in this scenario. It's either the acquirer or issuer. Scheme acts as a judge and decides who's fault it is. However, now that 3d secure is in place, if both issuer and acquirer support it, there are really few frauds. If they don't, the risk is on the one who did not enforce 3d secure.
Post reply on HN