Hacker News new | ask | show | jobs
by edd 2698 days ago
From this Deliveroo engineering blog post:

https://deliveroo.engineering/2017/09/05/improving-password-...

"Therefore, from today, we will be informing our customers when we determine that the password which they use for Deliveroo is publicly known in some way. We will contact the impacted customers to request that they change their password, and advise that they also change that password at other sites where it is also used."

1 comments

Thanks for posting this - I hadn't realised they were already doing it. I'm not sure how else they could be combatting password reuse attacks, short of forcing every user to reset their password.

It sounds like their engineering time might be better spent on fraud detection algorithms.