3 ms·
This is poor form from Deliveroo - their fraud detection seems particularly lacking, and fobbing customers off for months at a time is not good enough. However
by whyleyc 8y ago
This is poor form from Deliveroo - their fraud detection seems particularly lacking, and fobbing customers off for months at a time is not good enough.
However the article is unnecessarily sensationalist in banding around GDPR data breaches. Much of the article intimates there has been a Deliveroo data breach, whereas in fact the most likely explanation is attackers reusing passwords leaked from other breaches. This is acknowledged towards the end of the article but quickly glossed over.
If consumers are reusing exposed passwords this makes life tricky for Deliveroo. Maybe they should be using Troy Hunt's "Pwned passwords" to protect new user signups:
https://www.troyhunt.com/ive-just-launched-pwned-passwords-version-2/ https://www.troyhunt.com/ive-just-launched-pwned-passwords-v...
- edd 8y agoFrom this Deliveroo engineering blog post: https://deliveroo.engineering/2017/09/05/improving-password-security.html https://deliveroo.engineering/2017/09/05/improving-password-... "Therefore, from today, we will be informing our customers when we determine that the password which they use for Deliveroo is publicly known in some way. We will contact the impacted customers to request that they change their password, and advise that they also change that password at other sites where it is also used."
- whyleyc 8y agoThanks for posting this - I hadn't realised they were already doing it. I'm not sure how else they could be combatting password reuse attacks, short of forcing every user to reset their password. It sounds like their engineering time might be better spent on fraud detection algorithms.
- laurent123456 8y agoAlso the hackers managed to change the user's email, which Deliveroo could have easily prevented by sending an email first to the original email address. It's hard to prevent people from using bad passwords, but there are a few easy things they can do to prevent hackers from completely taking over accounts.
- philpem 8y agoI've seen a few services which do this as a matter of course. Sadly few allow the email address change to be rescinded without a customer-service call. By that point, the account may already be in fraudulent use.
- crossman 8y agoThis comment needs to be the top one on this story. It seems the writer is missing this point entirely. It's very poor practice from Deliveroo and their support team. But there is a big difference between breach through negligence of the data controller and accounts being compromised by user negligence.
- lightedman 8y agoHow is the data controller NOT negligent given that this has apparently been going on for years AND IT HAS NOT STOPPED? Do we need DECADES of this before you decide Deliveroo isn't doing enough?
- snowwolf 8y agoI actually think the article is correct about GDPR data breaches. See my other comment about this. https://news.ycombinator.com/item?id=18990122 https://news.ycombinator.com/item?id=18990122