Live data from Hacker News

Someone at BrowserStack is leaking users' email addresses

shkspr.mobi

51–60 of 123 posts

Re: Someone at BrowserStack is leaking users' email addresses

#51
post #10
post #3

> BrowserStack routinely sell or give away their users' data. > A third-party service used by BrowserStack siphons off information to send to others. > An employee or contractor at BrowserStack is exfiltrating user data and transferring it elsewhere. Or the simpler answer, their db/email list has been compromised.

The simplest answer is they are voluntarily being scum and selling user data to make a quick buck. It’s almost universally true.

> It’s almost universally true.

It’s not. I give a unique email address to every service I register with, which means I can see who is leaking my email address. Very few of them leak my email address at all, and those that do tend to do so involuntarily through data breaches.

The other main factors in spam are the sleazeballs at Apollo, ZoomInfo, et al., services that use my email address internally for more than I consented (if I use my email address to register for a service, this does not permit that service to add me to their product mailing list), and the spammers who guess email addresses based on LinkedIn info (e.g. name + company domain).

The number of services who appear to take an email address I have given them and sell it appear to be extremely rare.

Re: Someone at BrowserStack is leaking users' email addresses

#53
Selected quotes from Apollo's GDPR page:

> Consent must be "freely given, specific, informed, and unambiguous."

and

> Apollo notifies them when their data is added to Apollo's database of business contact information and provides them with instructions on how to opt out.

https://knowledge.apollo.io/hc/en-us/articles/4409141087757-...

Now, their claim appears to be that they're processing business contact data under the legal basis of "Legitimate Interests". But as much as I am a big fan of not doing things that require a legal basis of "Consent", I'm unconvinced that they ensure their customers are sticking as tightly to their basis as they ought to be if they wish to claim it.

In other words: yes, if you have a CRM in then you might derive legitimate interests in sharing with Apollo. But you need to make sure you actually have the right legal basis for putting customer details into your CRM, and your support database almost certainly does not hold appropriate data!

So ultimately I think this is on both Browserstack (for connecting and sharing data other than in accordance with a legal basis) and Apollo (for making it too easy for their customers to send them data without a sound legal basis and then for sharing that data without suitably validating they had the legal basis to).

Apollo's privacy centre makes all the right claims about how they comply with GDPR, but the OP's story demonstrates that they're not as scrupulous in their verification as they claim to be. And strictly, both should be reporting the breach and taking steps to ensure it doesn't recur.

Re: Someone at BrowserStack is leaking users' email addresses

#54
post #20
post #15

> Like all good nerds, I generate a unique email address for every service I sign up to. This has several advantages - it allows me to see if a message is legitimately from a service, if a service is hacked the hackers can't go credential stuffing, and I instantly know who leaked my address. I think a lot of services will "de-alias" the email addresses from these tricks to prevent alts, account spam, and to still tar…

I just do @ . It is sometimes confusing by when interacting with customer support ;-)

I had one website forward my mail to their legal department who asked me why I’m impersonating them :D Only required a short explanation though.

Re: Someone at BrowserStack is leaking users' email addresses

#55
post #44
post #12

Everyone in this thread suggesting a “data leak” or “compromise” is totally missing the fact that this is how Apollo works. This is often times overlooked by Apollo customers themselves. You have to opt out of customer data sharing (and in doing so lose out on the value of the product): https://knowledge.apollo.io/hc/en-us/articles/20727684184589... Not commenting on whether this is good or ethical (or even totally l…

For a little more color for people unfamiliar with modern sales/marketing: 1. A user signs up to BrowserStack 2. BrowserStack (automatically) upload the submitted user’s information to Apollo 3. Apollo “enrich” the user’s details using information they already have about the person, e.g: company revenue, LinkedIn profile 4. Sales reps at BrowserStack use the enriched information to identify leads, bucket for marketin…

Hopefully in the soon future:

5. BrowserStack gets hit by a massive GDPR fine.

Re: Someone at BrowserStack is leaking users' email addresses

#57
post #20

Earlier quoted context omitted.

I just do @ . It is sometimes confusing by when interacting with customer support ;-)

Yes ma'am, my email address really is bofa.com@ .com No I'm not trying to hack you. Which in hindsight is also what a hacker would say. I can't win...

On top of it my email address is .me so is very common to when I finish spelling my e-mail, people waiting for .com

Re: Someone at BrowserStack is leaking users' email addresses

#58
post #44
post #12

Everyone in this thread suggesting a “data leak” or “compromise” is totally missing the fact that this is how Apollo works. This is often times overlooked by Apollo customers themselves. You have to opt out of customer data sharing (and in doing so lose out on the value of the product): https://knowledge.apollo.io/hc/en-us/articles/20727684184589... Not commenting on whether this is good or ethical (or even totally l…

For a little more color for people unfamiliar with modern sales/marketing: 1. A user signs up to BrowserStack 2. BrowserStack (automatically) upload the submitted user’s information to Apollo 3. Apollo “enrich” the user’s details using information they already have about the person, e.g: company revenue, LinkedIn profile 4. Sales reps at BrowserStack use the enriched information to identify leads, bucket for marketin…

So I'm not disputing this, but I set up a similar scheme to the author almost 8 years ago and conduct 90+% of my online business through the custom emails. Everything from Amazon to small local business.

In that time I have had 'leaks' twice: my State's Fish and Wildlife licensing organ, and GitHub. In both cases I assume it's more that the email ends up being public, not because of something like Apollo.

I guess it's possible that spam is getting filtered before it ever hits my inbox.

Edit: I was responding to the idea of it leading to spam, not that Apollo wasn't collecting information on me.

For those curious: I signed up with Apollo and looked at what they had on me (via the link in the flagged/dead post by fontain). The email address they have is technically correct, but it's a non-current work email. It's still active and I do get a lot of senseless/bizarre business sales inquiries on that address. The phone number they have is wrong and I don't recognize it. They have my LinkedIn byline; it's likely how I was 'found' so quickly, as my username is the same there. I'm listed as cold.

Re: Someone at BrowserStack is leaking users' email addresses

#59
post #44

Earlier quoted context omitted.

For a little more color for people unfamiliar with modern sales/marketing: 1. A user signs up to BrowserStack 2. BrowserStack (automatically) upload the submitted user’s information to Apollo 3. Apollo “enrich” the user’s details using information they already have about the person, e.g: company revenue, LinkedIn profile 4. Sales reps at BrowserStack use the enriched information to identify leads, bucket for marketin…

Hopefully in the soon future: 5. BrowserStack gets hit by a massive GDPR fine.

6. BrowserStack contests the fine for a couple of years, not paying a euro cent

7. People just remember 'BrowserStack got hit by a massive fine'

8. Everyone carries on with business as usual

Re: Someone at BrowserStack is leaking users' email addresses

#60

Earlier quoted context omitted.

The way that this is done these days (and likely what the author did/does) is that you use a custom domain to receive mail; you provide an email like service@custom.com, and that way when service@ starts receiving spam you know exactly where it comes from

^ I've been doing this with catchalls since before Google Apps for Domain was even a thing. Sometimes customer support staff bring up "oh, do you work at too"? I just tell them that I created an email address just for their company, in case they spam me.

I've got a few dozen domains, and primarily use two of them for business interactions. One is a catchall, while the other requires me to create explicit email addresses (or aliases).

Aside from issues such as the business entity (sometimes silently) prohibiting their name in my email address, I have sometimes encountered cases where part of the email validation process checks to see if the email server is a catchall, and rejects the email address if it is. It takes a little extra effort on my part to make a new alias, but sometimes it's required.

Lots of organizations (such as PoS system providers) will associate an email I provided with credit card number, and when I use the card at a completely different place, they'll automatically populate my email with the (totally unrelated) one that they have. Same goes for telephone numbers.

I've had many incidents similar to the author. More often than not, it's a rouge employee or a compromised computer, but sometimes it is as nefarious as the author's story.

Post reply on HN