Live data from Hacker News

DoorDash confirms data breach affected 4.9M customers, workers and merchants

techcrunch.com

51–60 of 224 posts

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#51

Earlier quoted context omitted.

They did no such thing, and I find it frustrating that people keep repeating this falsehood. Doordash promised to pay drives at least $X (where X was, I believe $1 or something like that) AND that the driver will make at least $Y from the delivery. The driver always gets the tip, plus a variable amount from DD. This is _exactly_ how it works for wait staff in restaurants in most states, except that is by hour instead…

Did they make that clear to the end customer that this is what's happening with the tips? I don't care what their contract with the delivery driver states, if they allow me to add a tip I expect that tip to go in the driver's pocket in addition to whatever they'd get paid without the tip, just like if I was giving them cash directly. If that's not what's happening they have essentially defrauded me and I wouldn't be…

The fact that it works just like waitstaff in restaurants (which is the first tipped job that comes to mind for the vast majority of people) makes it seem reasonable to me. Either way, though, they didn't do as the OP said they did

> they used to withhold the total tips out of a delivery drivers base compensation so essentially taking the tips for themselves

The driver's base pay was something like $1 or $2. They did not take tips out of that.

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#52
post #24
post #21

Earlier quoted context omitted.

"Days since last publicly disclosed data breach breach: 0"

Honestly? A minutes scale might be more appropriate there. Unless we add the "Major" but then, what is major?

Nah, a minutes scale would require data entry frequently, and HN's volunteer moderators probably don't want to have to click "Reset breach counter" all the time, plus you'd need to write code for both that button and the minute counter.

Let's keep HN Javascript-light: "Days Since" is much easier to implement. Just one line of static HTML will do:

    Days Since Last Breach: 0

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#55

Earlier quoted context omitted.

> Doordash's inevitable demise Perhaps it's different elsewhere, but out of the services I use here in Houston, Doordash is consistently the best experience. Obviously if one of those competitors can best them in categories that matter (cost, speed, and accuracy) I'll switch.

> Obviously if one of those competitors can best them in categories that matter (cost, speed, and accuracy) I'll switch. It's just a matter of time anyway, the VC money will dry up, they will either go down the drain right away or raise prices, which if nothing else will open the doors for another VC-fuelled competitor to overtake the market by subsidising deliveries for the next few years.

True of most startups that aren't turning a profit.

However, it doesn't seem that Doordash is struggling that much, and is outpacing it's competitors in growth rate

https://www.restaurantbusinessonline.com/financing/delivery-...

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#57
post #13

> The information accessed is not sufficient to make fraudulent charges on your payment card. In other words... "We leaked a bunch of your personal information, but at least it's not enough data to steal your money!" All of these leaks have the cumulative effect of making ineffective very commonly used security verification questions: "Can I verify that last 4 of your social? And the last 4 of your credit card?" How…

Surely the actual problem here is that the responsibility for reliable identification somehow falls on the consumer, not the bank or what have you?

I'll give an example: if I get a phishing email claiming to be from my bank, and end up wiring them $1000, I'm out $1000 for not having done the due diligence for verifying that it in fact was my bank; my bank doesn't suddenly owe me $1000. Somehow, though, if some 3rd party convinces the bank they're me, and withdraws $1000 from my account, I'm at fault as a victim of "identity fraud" (and am again out $1000, but this time as a result of my bank's incompetence).

If the onus for verifying your identity were on institutions (and, consequently, the losses in cases of failure to do so) I'm confident that we would have much more reliable means of personal identification magically pop into existence.

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#58
post #13

> The information accessed is not sufficient to make fraudulent charges on your payment card. In other words... "We leaked a bunch of your personal information, but at least it's not enough data to steal your money!" All of these leaks have the cumulative effect of making ineffective very commonly used security verification questions: "Can I verify that last 4 of your social? And the last 4 of your credit card?" How…

Hell, imagine how many scans of people’s passports and driver’s licenses are sitting in databases waiting to be leaked, yet images of those documents let you authenticate with all sorts of financial institutions online from banks to Coinbase to Paypal. We really need to rethink all this. Until then, it feels like mere luck that today wasn’t the day someone decided to social engineer their way into your life. Everythi…

People don't really use them to hack existing accounts so much.

They use them to create new accounts to move money that way.

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#59
post #6

I feel bad for the people affected but at least the scummy company got what it deserved for stealing tips (for those unaware, they used to withhold the total tips out of a delivery drivers base compensation so essentially taking the tips for themselves). Now if they could just completely die so a more ethical competitor can take its place it would be even better.

The part where they didn’t tell the customers they were doing this is definitely scummy. The pure economics of it is more complicated—DoorDash was redistributing the “tips” to effectively guarantee higher minimum payment per order (a lot of customers don’t tip at all as the social expectations with the delivery apps are not as well established), and after they’ve changed the policy a number of dashers see their overall pay has decreased through no fault of their own (there can be many factors that are correlated with giving more 0 tips in a given area/route that have nothing to do with the driver).

The honest thing to do would have been to raise the delivery fees across the board, but that doesn’t attract customers. The seemingly optional “tip” preys on the customer’s mistaken assumptions and was used as a sneaky way to achieve the same thing.

Re: DoorDash confirms data breach affected 4.9M customers, workers and merchants

#60
post #13

> The information accessed is not sufficient to make fraudulent charges on your payment card. In other words... "We leaked a bunch of your personal information, but at least it's not enough data to steal your money!" All of these leaks have the cumulative effect of making ineffective very commonly used security verification questions: "Can I verify that last 4 of your social? And the last 4 of your credit card?" How…

Hell, imagine how many scans of people’s passports and driver’s licenses are sitting in databases waiting to be leaked, yet images of those documents let you authenticate with all sorts of financial institutions online from banks to Coinbase to Paypal. We really need to rethink all this. Until then, it feels like mere luck that today wasn’t the day someone decided to social engineer their way into your life. Everythi…

I've worked for companies who were more careless with even more private data required by law to be encrypted but wasn't .

Always comes down to "we don't have enough time". Then when it leaks we have all the time in the world.

Post reply on HN