TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

DoorDash confirms data breach affected 4.9M customers, workers and merchants

526 pointsby bonytover 5 years ago

38 comments

cjover 5 years ago
&gt; The information accessed is not sufficient to make fraudulent charges on your payment card.<p>In other words... &quot;We leaked a bunch of your personal information, but at least it&#x27;s not enough data to steal your money!&quot;<p>All of these leaks have the cumulative effect of making ineffective very commonly used security verification questions: &quot;Can I verify that last 4 of your social? And the last 4 of your credit card?&quot;<p>How long will it take for us to accept that this kind of data can no longer be assumed private? The sooner, the better, mainly so companies stop using it as a secondary form of identity verification.
评论 #21085841 未加载
评论 #21085642 未加载
评论 #21085621 未加载
评论 #21086959 未加载
评论 #21087631 未加载
评论 #21087695 未加载
评论 #21086811 未加载
评论 #21085634 未加载
评论 #21086353 未加载
评论 #21090596 未加载
geocarover 5 years ago
I&#x27;d like to point out, it&#x27;s not &quot;DoorDash&quot; that has done anything wrong, it&#x27;s these <i>people</i>:<p>- Andy Fang<p>- Evan Moore<p>- Stanley Tang<p>- Tony Xu<p>They decided our security and privacy wasn&#x27;t worth as much as hur hur hur growth hacking startup hur hur next uber, and couldn&#x27;t be arsed to even give us a proper apology.<p>Look at their blog post: not one mention of the words &quot;we sorry, we fucked up&quot;.<p>It&#x27;s all about the other guys.<p>The <i>bad guys</i>.<p>The guys who stole your data <i>not us</i>, and you should change your password with us to protect your account <i>with us</i>.<p>No. That&#x27;s wrong. Look at the 295 million people who weren&#x27;t affected -- all the people who don&#x27;t use doordash at all!<p>That means the best way to protect yourself is to simply not use doordash. Delete it. Delete the email account and the bank&#x2F;credit card you used with them (ask your bank&#x2F;credit card company for a new number). Move if you&#x27;ve got to (drivers license details!?!?!?) You have no other protection now- you&#x27;re fucked. They have your data, and they&#x27;re only going to risk it again.<p>And remember how difficult it is to get in control of your data again when the next breach happens, the next time you&#x27;re thinking about signing up with something, or you&#x27;re getting ready to vote.
评论 #21090584 未加载
评论 #21091034 未加载
评论 #21090338 未加载
评论 #21093157 未加载
评论 #21139926 未加载
评论 #21095026 未加载
评论 #21091869 未加载
评论 #21090973 未加载
评论 #21091988 未加载
standardUserover 5 years ago
At this point HN should just have a permanent module in the top right corner announcing the latest data breach.
评论 #21085617 未加载
评论 #21086036 未加载
评论 #21085772 未加载
dx87over 5 years ago
The official blog post doesn&#x27;t give any information about the breach except &quot;We noticed a third-party had unauthorized access to DoorDash data&quot;, and the TechCrunch article says that DoorDash responded that they couldn&#x27;t explain how the breach happened. How are they so sure that they fixed the underlying cause if they don&#x27;t even know how the third-party got access in the first place?
评论 #21085667 未加载
评论 #21085691 未加载
jacquesmover 5 years ago
There is a silver lining in all these data breaches. At some point in time <i>all</i> our data will have been leaked at least once and probably more than once and subsequent leaks will not do any more damage.<p>The safe assumption would then be to not trust any accounts created online without some good old KYC processes in place requiring live verification of identity.
评论 #21087164 未加载
评论 #21086247 未加载
评论 #21085913 未加载
big_chungusover 5 years ago
Original blog post: <a href="https:&#x2F;&#x2F;blog.doordash.com&#x2F;important-security-notice-about-your-doordash-account-ddd90ddf5996#46h35gr24e" rel="nofollow">https:&#x2F;&#x2F;blog.doordash.com&#x2F;important-security-notice-about-yo...</a><p>From the techcrunch article: &quot;It’s not clear why it took almost five months for DoorDash to publicly reveal the breach. DoorDash spokesperson Mattie Magdovitz say why [sic].&quot;<p>Pretty bad. If personal identity info is exposed, it is irresponsible not to notify users immediately so they can freeze credit and watch for suspicious activity. The blog post did mention a third-party vendor, so it&#x27;s possible there was a delay, but it&#x27;s a whole other problem if it took this long to find a breach.<p>This sounds like it could be &quot;flipboard-itis&quot;. Flipboard stored passwords insecurely in the beginning (SHA-1), but switched to bcrypt as it scaled. The passwords breached were before 2015, so possibly a similar thing here where they started out with bad security and improved with scale (but left the old stuff behind). I&#x27;m guessing Doordash did something similar and improved security as it scaled.
评论 #21085703 未加载
评论 #21085400 未加载
riettaover 5 years ago
The classic trite &quot;We take the security of our community very seriously.&quot; Nearly every corporate communication about a breach says it and often it comes out to have been demonstrably untrue.
评论 #21087811 未加载
评论 #21086511 未加载
评论 #21087778 未加载
throwaway867295over 5 years ago
(Throwaway account)<p>I used to work for a third-party service provider that merchants send this sort of data to for lots of users. Considering there weren&#x27;t lots of customers using this provider making similar posts, and Doordash didn&#x27;t call out the provider, it wouldn&#x27;t surprise me if a Doordash employee account with that provider got compromised. The blog post was carefully worded to not throw the provider under the bus, but also avoid taking blame, themselves.<p>The telling bit is that the last four digits of credit card numbers were sent. There are only a few types of vendors you&#x27;d send that data to.
评论 #21088049 未加载
luhnover 5 years ago
The official blog post: <a href="https:&#x2F;&#x2F;blog.doordash.com&#x2F;important-security-notice-about-your-doordash-account-ddd90ddf5996#46h35gr24e" rel="nofollow">https:&#x2F;&#x2F;blog.doordash.com&#x2F;important-security-notice-about-yo...</a>
Nextgridover 5 years ago
I feel bad for the people affected but at least the scummy company got what it deserved for stealing tips (for those unaware, they used to withhold the total tips out of a delivery drivers base compensation so essentially taking the tips for themselves).<p>Now if they could just completely die so a more ethical competitor can take its place it would be even better.
评论 #21085852 未加载
评论 #21086394 未加载
评论 #21085702 未加载
评论 #21085499 未加载
评论 #21085695 未加载
评论 #21085455 未加载
评论 #21086836 未加载
jenrzzzover 5 years ago
DoorDash is the worst. They inexplicably banned me from their platform after giving me a credit for a bad order. I filed several support tickets over several months and kept getting canned responses about how they were &quot;looking into the issue.&quot; Eventually I just switched to Uber Eats.
greenailover 5 years ago
I&#x27;ve been vending myself unique email addresses for every online account I use for about 3 years. They are nice because I can reply to them like a regular mail and my actual email account gets stripped out automagically.<p>I&#x27;ve been considering making it a product and I wonder in this case what people would want to do when the account data gets leaked?<p>1. blackhole all email to the address. 2. forward all email to some email service that is never&#x2F;rarely used. 3. flag messages that are not sent from the matching domain (doordash.com in this case). 4. blackhole and generate a new address so the user can go back to door dash and provide a fresh email address.<p>I also wonder if there is any use for meta data on who&#x27;s trying to email a blackholed email addrress e.g spam blacklisting.
评论 #21086326 未加载
评论 #21086734 未加载
SketchySeaBeastover 5 years ago
I still worry about DoorDashes security - someone has signed up for services with my email account - not an issue, I just will never verify them. But they had signed up for DoorDash, and I didn&#x27;t realize it, and then I tried to sign up for the first time via the Android App with that same email account. I selected the email account to my surprise it immediately let me into the other persons account! They had ostensibly set up a password, but I didn&#x27;t need it and could see their phone number and bits of their payment information. I sent in a support email for that one, and got the account closed, but still, not a great sign.
评论 #21085517 未加载
readhnover 5 years ago
I propose a way to improve cybersecurity: FINE companies who loose sensitive customer data to hackers. Fines can be calculated according to the &quot;breach severity grid&quot; which is based on the type of data that is lost. For example:<p>1. Personal address, DOB - $15. 2. Each social security $20. 3. Driver license number $25. 4. Bank account numbers $30. etc.<p>So a loss of 4.9 million social security numbers, DOB and addresses would generate a fine of $171,500,000<p>Problem solved!<p>Now, the company will think 100x times BEFORE collecting consumer data if they can actually PROTECT IT. Build robust security FIRST!
评论 #21086777 未加载
hnrussover 5 years ago
Wonder if I&#x27;ll get another $25-50 from a class action lawsuit over this.
评论 #21086043 未加载
tolstoshevover 5 years ago
DoorDash probably forgot to tip the “third-party service provider”
评论 #21087098 未加载
newherehiover 5 years ago
Stealing tips and now a breach with a terrible response. These people should be in jail and their company should be shut down.
abuehrleover 5 years ago
I received the email. I&#x27;d asked them to delete my account 6 months ago, and they confirmed at the time they&#x27;d &quot;deactivated&quot; it. I guess that wasn&#x27;t enough to protect me. As an American developer, GDPR seemed like a pain at first, but more and more I wish we had something similar.
cavisneover 5 years ago
Disclosure on this was pretty bad. I got an email saying your password has been reset, if you didnt do this contact support.<p>Removed payment methods from my account and reset the password, but now I assume this was done to all users?
frereubuover 5 years ago
I don&#x27;t know a great deal about DoorDash, but my understanding is that they&#x27;re only in the US. If so, they&#x27;re not bound by the EU&#x27;s GDPR data breach disclosure timescales, which are &quot;without undue delay and, where feasible, not later than 72 hours&quot; if they&#x27;re likely to result in a high risk to the rights and freedoms of data subjects, which this seems to fit. Compare that with the apparent <i>five month</i> delay here, with all its attendant risks to the customers whose data was made available. The EU has its flaws, but when I read stories like this I&#x27;m really happy I&#x27;m covered by GDPR.
innagadadavidaover 5 years ago
After using food delivery and takeout services, I felt the plastic waste it generates is incredible. All the folks that care even a little bit about the environment, please just get out of your homes and just dine-in. Silicon Valley startups just don’t care about the environment, you can change that one person at a time.
mattbreedenover 5 years ago
This was great to get an email about since doordash does not let users delete accounts. You can only &#x27;deactivate&#x27; in a way that is easy to &#x27;reactivate&#x27;. If I would have actually been allowed to delete my account many months ago when I asked maybe I wouldn&#x27;t have had my information leaked.
评论 #21090068 未加载
louwrentiusover 5 years ago
A 490 million dollar fine sounds reasonable. To be paid by giving each customer back $100.
zer0faithover 5 years ago
When the F are we going to hold people accountable for piss poor security posture.
Thripticover 5 years ago
Is their password change function working? I can&#x27;t seem to change my pw. It gets to SMS 2FA then appears to fail when I try to verify the token I&#x27;m sent and boots me back to the PW change page.
seomintover 5 years ago
I don&#x27;t know what&#x27;s more frustrating to read -- news of these seemingly constant data breaches or news that the latest Windows 10 Update just broke something else.
treggleover 5 years ago
Is there a list of all disclosed security breaches somewhere?
评论 #21085888 未加载
评论 #21085892 未加载
评论 #21085812 未加载
basicplus2over 5 years ago
A government created physical token for every person could be the direction we are headed
noodlesUKover 5 years ago
Once again, the US is sorely lacking regulation w.r.t data breaches. In Europe the breach might have still happened but at least customers would have been told months earlier and there would be some predictable penalties for the companies. I also think that DoorDash would have been more transparent about the steps that lead up to this.<p>We need a US GDPR. Even if there’s nothing like the right to be forgotten, we need data breach regs.
thoughtpaletteover 5 years ago
Anyone know how this affects users that login via Facebook Auth with Doordash?
oldspleenover 5 years ago
There goes my private data; thanks doordash for the leak
luckydataover 5 years ago
when will it become not ok to suck at this?
评论 #21086052 未加载
adtacover 5 years ago
&gt;The breach happened on May 4<p>I don&#x27;t believe for one second that they didn&#x27;t know about it for five months! Can someone in the EU please report this so that it&#x27;s investigated for a GDPR violation?<p>Edit: from the official post on blog.doordash.com:<p>&gt;Earlier this month, we became aware of unusual activity involving a third-party service provider.<p>Of course. This is quite a bit more than the 72 hour window GDPR allows.
评论 #21085978 未加载
评论 #21086075 未加载
rkhoover 5 years ago
I attempted to purge my data from Doordash&#x27;s servers. They refused, citing GDPR for some reason and saying the best they could do was to &quot;deactivate&quot; my account (while retaining my personal information).
oldspleenover 5 years ago
There goes my private data. Thank you DoorDash for the leak.
DConway39over 5 years ago
Wow thats crazy
PeterCorlessover 5 years ago
Okay, this has been up for two whole hours, and no one has yet said &quot;OMG, I think I&#x27;m going to lose my lunch over this!&quot;<p>Get with it people! The jokes are right there.
sir_sagarover 5 years ago
This kind of bugs and problems will open the eyes of companies to get on to blockchain. As a Blockchian enthusiast, i found it is best to store data on it. And in market many companies doing the same too. to fire more questions and query drop a mail on sagar@trsts.co