e dot dot dot
a mostly about the Internet blog by

home << Policy << auto hey doordash why are you hiding your security notice from google just days after you revealed a massive security breach

April 2024
Sun Mon Tue Wed Thu Fri Sat
 
       

Tue, 01 Oct 2019


Hey Doordash: Why Are You Hiding Your 'Security Notice' From Google Just Days After You Revealed A Massive Security Breach?

Furnished content.


As you might have heard, late last week, delivery company DoorDash admitted via a Medium post that there had been a large data breach exposing info on 4.9 million users of the service. The breach had actually happened months earlier, but was only just discovered earlier this month.

We take the security of our community very seriously. Earlier this month, we became aware of unusual activity involving a third-party service provider. We immediately launched an investigation and outside security experts were engaged to assess what occurred. We were subsequently able to determine that an unauthorized third party accessed some DoorDash user data on May 4, 2019. We took immediate steps to block further access by the unauthorized third party and to enhance security across our platform. We are reaching out directly to affected users.
The information accessed included names, emails, delivery addresses, order histories and phone numbers. Salted and hashed passwords were accessible too, but assuming Doordash didn't mess up the salting/hashing, those should still be safe. Some customers also had the last four digits of their credit cards revealed.All in all a somewhat typical breach that happens these days. However, as TechCrunch cybersecurity reporter Zack Whittaker noticed, somewhere right around the time the breach went up, DoorDash told Google to stop indexing its "SecurityNotices" page via robots.text.
He also notes that DoorDash doesn't seem to be going out of its way to alert people to the breach -- pointing out that there's nothing on DoorDash's front page, or on its various social media accounts. Just the blog post on Medium (and, if I'm not mistaken, Medium posts can end up behind a paywall in lots of cases). That's pretty lame. My guess is that since DoorDash says it's "contacting" customers impacted by the breach, it felt it didn't need to do wider outreach. But... that seems like a huge cop out. Notifying people of such a breach is kind of important.And, also, yanking your "securitynotices" directory from Google (even if it currently appears blank) seems super suspicious. Why do that except to hide information from people searching for info about your security issues? A breach of this nature is bad, but it happens to so many companies these days that I don't think this kind of breach leads to much trust lost from customers. However, proactively trying to keep things quiet about this... well... that's the kind of thing that raises eyebrows and destroys trust.Of course, in a bit of perfect timing to distract from all of this, DoorDash happily announced today that it's now delivering for McDonald's, so get your Big Macs quick and ignore any lingering concerns about security...

Permalink | Comments | Email This Story


Read more here

posted at: 12:00am on 01-Oct-2019
path: /Policy | permalink


0 writeback(s)

comment...

 
Name:
URL/Email: (optional)
[http://... or mailto:you@wherever]
Title: (optional)
Comments:
Please enter the anti-spam code shown below: 

home << Policy << auto hey doordash why are you hiding your security notice from google just days after you revealed a massive security breach

April 2024
Sun Mon Tue Wed Thu Fri Sat
 
       


Categories
 - blog home

 - Announcements  (0)
 - Annoyances  (0)
 - Career_Advice  (0)
 - Domains  (0)
 - Downloads  (3)
 - Ecommerce  (0)
 - Fitness  (0)
 - Home_and_Garden  (0)
     - Cooking  (0)
     - Tools  (0)
 - Humor  (0)
 - Notices  (0)
 - Observations  (1)
 - Oddities  (2)
 - Online_Marketing  (0)
     - Affiliates  (1)
     - Merchants  (1)
 - Policy  (3743)
 - Programming  (0)
     - Bookmarklets  (1)
     - Browsers  (1)
     - DHTML  (0)
     - Javascript  (3)
     - PHP  (0)
     - PayPal  (1)
     - Perl  (37)
          - blosxom  (0)
     - Unidata_Universe  (22)
 - Random_Advice  (1)
 - Reading  (0)
     - Books  (0)
     - Ebooks  (0)
     - Magazines  (0)
     - Online_Articles  (5)
 - Resume_or_CV  (1)
 - Reviews  (2)
 - Rhode_Island_USA  (0)
     - Providence  (1)
 - Shop  (0)
 - Sports  (0)
     - Football  (0)
          - Cowboys  (0)
          - Patriots  (0)
     - Futbol  (0)
          - The_Rest  (0)
          - USA  (0)
 - Technology  (1198)
 - Windows  (1)
 - Woodworking  (0)


Archives
 -2024  April  (134)
 -2024  March  (179)
 -2024  February  (168)
 -2024  January  (146)
 -2023  December  (140)
 -2023  November  (174)
 -2023  October  (156)
 -2023  September  (161)
 -2023  August  (49)
 -2023  July  (40)
 -2023  June  (44)
 -2023  May  (45)
 -2023  April  (45)
 -2023  March  (53)


My Sites

 - Millennium3Publishing.com

 - SponsorWorks.net

 - ListBug.com

 - TextEx.net

 - FindAdsHere.com

 - VisitLater.com