Live data from Hacker News

Someone at BrowserStack is leaking users' email addresses

shkspr.mobi

21–30 of 123 posts

Re: Someone at BrowserStack is leaking users' email addresses

#21
post #15

> Like all good nerds, I generate a unique email address for every service I sign up to. This has several advantages - it allows me to see if a message is legitimately from a service, if a service is hacked the hackers can't go credential stuffing, and I instantly know who leaked my address. I think a lot of services will "de-alias" the email addresses from these tricks to prevent alts, account spam, and to still tar…

I personally do x@mydomain.com. It makes it very obvious when you start getting spam (I’m looking at you dji).

Re: Someone at BrowserStack is leaking users' email addresses

#23
post #20
post #15

> Like all good nerds, I generate a unique email address for every service I sign up to. This has several advantages - it allows me to see if a message is legitimately from a service, if a service is hacked the hackers can't go credential stuffing, and I instantly know who leaked my address. I think a lot of services will "de-alias" the email addresses from these tricks to prevent alts, account spam, and to still tar…

I just do @ . It is sometimes confusing by when interacting with customer support ;-)

Yes ma'am, my email address really is bofa.com@.com

No I'm not trying to hack you.

Which in hindsight is also what a hacker would say. I can't win...

Re: Someone at BrowserStack is leaking users' email addresses

#24
post #13

>After a brief discussion, the emailer told me they got my details from Apollo.io The landing page for Apollo.io says it's a "AI sales platform". In other words, a CRM. My guess is that someone on the sales team uploaded the entire customer list for sales purposes, not realizing the privacy implications.

> not realizing the privacy implications.

If only.

Re: Someone at BrowserStack is leaking users' email addresses

#25
post #3

> BrowserStack routinely sell or give away their users' data. > A third-party service used by BrowserStack siphons off information to send to others. > An employee or contractor at BrowserStack is exfiltrating user data and transferring it elsewhere. Or the simpler answer, their db/email list has been compromised.

> > BrowserStack routinely sell or give away their users' data.

> Or the simpler answer, their db/email list has been compromised.

I find the first option far simpler.

Re: Someone at BrowserStack is leaking users' email addresses

#27
post #15

> Like all good nerds, I generate a unique email address for every service I sign up to. This has several advantages - it allows me to see if a message is legitimately from a service, if a service is hacked the hackers can't go credential stuffing, and I instantly know who leaked my address. I think a lot of services will "de-alias" the email addresses from these tricks to prevent alts, account spam, and to still tar…

The way that this is done these days (and likely what the author did/does) is that you use a custom domain to receive mail; you provide an email like service@custom.com, and that way when service@ starts receiving spam you know exactly where it comes from

Re: Someone at BrowserStack is leaking users' email addresses

#29
Thanks to iCloud I haven't used my actual email addresses anywhere in a decade (even without Hide My Email their aliases were very handy)

Caught quite a few leakers that way, by using specific addresses for specific sites or categories of sites

(Last time I tried, Gmail's aliases were useless; they included your real address in the alias!)

Re: Someone at BrowserStack is leaking users' email addresses

#30
post #15

> Like all good nerds, I generate a unique email address for every service I sign up to. This has several advantages - it allows me to see if a message is legitimately from a service, if a service is hacked the hackers can't go credential stuffing, and I instantly know who leaked my address. I think a lot of services will "de-alias" the email addresses from these tricks to prevent alts, account spam, and to still tar…

The way that this is done these days (and likely what the author did/does) is that you use a custom domain to receive mail; you provide an email like service@custom.com, and that way when service@ starts receiving spam you know exactly where it comes from

^ I've been doing this with catchalls since before Google Apps for Domain was even a thing.

Sometimes customer support staff bring up "oh, do you work at too"? I just tell them that I created an email address just for their company, in case they spam me.

Post reply on HN