Live data from Hacker News

Deliveroo users are getting defrauded

newstatesman.com

271–280 of 354 posts

Re: Deliveroo users are getting defrauded

#271

Earlier quoted context omitted.

A demand letter is often enough and is a good step before small claims. “Fix my problem in ten days or get sued in small claims court", sent via certified mail to their designated agent for legal service in your jurisdiction, can often solve your problem.

Good suggestion. There's definitely a series of steps to go through before any time consuming and expensive lawyering up is needed.

Small claims court often does not require a lawyer. But yeah, the general process of "document things and escalate using said documentation to people whose job it is to make sure expensive lawsuits and regulatory actions don't happen" is an excellent choice.

Re: Deliveroo users are getting defrauded

#272
Credential stuffing attacks aren't a valid excuse IMO, and should not make this sort of fraud possible. Amazon for example instituted a very simple and effective policy years ago: if you want to deliver something to a new address using an existing payment method you need to reenter the payment details. This means even if someone guesses your username and password and you have a valid CC on file they still can't send a package to some arbitrary new address.

It's conceivable that the fraud is on the merchant side, with a restaurant faking a large order to an existing address, but in that case Deliveroo still has responsibility for allowing bad merchants into the system.

Re: Deliveroo users are getting defrauded

#273
post #52

Earlier quoted context omitted.

This is basically the sole "feature" of credit cards I value. Any time I'm buying something from somewhere that might act poorly, I use a credit card for the free leverage I have in a disagreement. Had an old phones screen repaired at a store inside a Walmart. They fixed it but half the screen had no touch capability. They were highly resistant to doing anything about it until I said I would just do a charge back. To…

> This is basically the sole "feature" of credit cards I value. Any time I'm buying something from > somewhere that might act poorly, I use a credit card for the free leverage I have in a disagreement. But without a credit card, they wouldn't even have been able to get your money without authorisation. I don't see how something like this would have been possible with a system that requires explicit authorisation per…

> But without a credit card, they wouldn't even have been able to get your money without authorisation. I don't see how something like this would have been possible with a system that requires explicit authorisation per payment.

I don't understands your point. Are you saying the ideal scenario would be to fill the cards information each time? The fact that it's a credit card doesn't change that it was prefilled, a debit card or wire transfer is the same. Credit or not, if it's already there, the one that access your account can use it.

With a credit card though, you can do a chargeback, which not only give you your money back, also add a direct cost (and a steep one from what I understood) to the merchant that made the transaction. As far as I know you couldn't do the same with a debit card.

Re: Deliveroo users are getting defrauded

#274

Credential stuffing attacks aren't a valid excuse IMO, and should not make this sort of fraud possible. Amazon for example instituted a very simple and effective policy years ago: if you want to deliver something to a new address using an existing payment method you need to reenter the payment details. This means even if someone guesses your username and password and you have a valid CC on file they still can't send…

I actually found the other day, if I edit an existing address, it doesn’t make me re-enter payment details. But adding a new one does. Not sure if this was due to a trusted device or if it always does it though.

Re: Deliveroo users are getting defrauded

#275
post #262

Earlier quoted context omitted.

You’re forgetting something. This isn’t my argument. This is what GDPR states. Unauthorised access to personal data constitutes a data breach. Does someone accessing your personal data who is not you using a stolen password count as unauthorised? Yes. It will ultimately come down to a test case, but as I said before, you will be hard pressed to find a lawyer who would tell a company that they definitely won’t be liab…

It depends on how "unauthorized" is defined. Does it actually define "unauthorized" somewhere else in the statute?

I think unauthorised has a fairly clearly defined definition in the English language (without permission or authority). And I’m fairly sure that’s the definition already used in courts of law. So in the absence of any contradicting definition in GDPR (and there isn’t) I would be pretty confident that is the definition that would be used.

But even so I struggle to think of a definition where accessing someone else’s account without their permission or authority wouldn’t be classed as unauthorised.

Re: Deliveroo users are getting defrauded

#276

Earlier quoted context omitted.

You didn’t file for a chargeback with Monzo, because they don’t offer credit cards. There’s less protection generally with debit cards. Generally guidance is that you are entitled to a refund from the bank only if you did not authorise a particular transaction.

Chargeback also apply to debit cards. It's just that credit cards must offer chargebacks by law.

The laws around credit cards are much stricter, in the UK it is much safer to use your credit card online and for day to day purchases (with pay in full every month so no interest charges).

Re: Deliveroo users are getting defrauded

#277
post #270
post #223

Earlier quoted context omitted.

Did saying this make you feel better about yourself or something? Because it's a ridiculously naive statement at best. More likely just some sanctimonious BS you decided to post to signal how much of a good person you are. Like seriously, what world do you live in where you can't picture a person doing something to take advantage of another person? Have you read literally anything in history?

I have a really hard time trying to understand the mindset of somebody who is going to take advantage of a person for profit. I actively remind myself of this because I need to be aware of this fact when dealing with people who could potentially take advantage of me.

Nobody is asking you to understand their mindset. Recognizing that such people exist does not require understanding their mindset..

Re: Deliveroo users are getting defrauded

#278

Earlier quoted context omitted.

> I've started using privacy.com Which is US only. Is there anything like it for the UK?

One could open a MONZO account(Which is completely online and can be opened in a day).( https://monzo.com/ ) You would get your debit card within a week max. You can transfer limited amount from your original bank account to Monzo account and even on top of that you can set some restrictions on how much amount can be withdrawn and there are some special features like POTS which are very useful. I am not saying this i…

The instant transaction alerts let you put a freeze on the account in a matter of seconds, so that's nice. I actually use my monzo account so putting low usage limits isn't practical.

Edit: although I guess they'd just do it in the middle of the night so doesn't really help.

Re: Deliveroo users are getting defrauded

#279
post #262

Earlier quoted context omitted.

It depends on how "unauthorized" is defined. Does it actually define "unauthorized" somewhere else in the statute?

I think unauthorised has a fairly clearly defined definition in the English language (without permission or authority). And I’m fairly sure that’s the definition already used in courts of law. So in the absence of any contradicting definition in GDPR (and there isn’t) I would be pretty confident that is the definition that would be used. But even so I struggle to think of a definition where accessing someone else’s a…

>without permission or authority

Permission or authority from who though?

If someone steals a key and unlocks a lock, is that considered "unauthorized access?" From the perspective of the person whose key was stolen, absolutely. From the perspective of the lock, no, the access was authorized.

We define terms in statutes and contracts for a damn good reason.

Re: Deliveroo users are getting defrauded

#280
Interestingly the same author had a very different opinion when the same was happening to someone else. https://www.newstatesman.com/science-tech/internet/2018/09/g...

> Although what Spotify has done, or failed to do, by handing over data to whoever is logged in on an account, could be considered irresponsible, it is in no way illegal – and, in all likelihood, is generally the norm.

Post reply on HN