Live data from Hacker News

Someone at BrowserStack is leaking users' email addresses

shkspr.mobi

91–100 of 123 posts

Re: Someone at BrowserStack is leaking users' email addresses

#91
post #44
post #12

Everyone in this thread suggesting a “data leak” or “compromise” is totally missing the fact that this is how Apollo works. This is often times overlooked by Apollo customers themselves. You have to opt out of customer data sharing (and in doing so lose out on the value of the product): https://knowledge.apollo.io/hc/en-us/articles/20727684184589... Not commenting on whether this is good or ethical (or even totally l…

For a little more color for people unfamiliar with modern sales/marketing: 1. A user signs up to BrowserStack 2. BrowserStack (automatically) upload the submitted user’s information to Apollo 3. Apollo “enrich” the user’s details using information they already have about the person, e.g: company revenue, LinkedIn profile 4. Sales reps at BrowserStack use the enriched information to identify leads, bucket for marketin…

I had never heard of Apollo, but I was interested so I followed your link to opt out.

I have had the same work email address for 13 years. I have done lots of hardware and software purchasing in that time, and I am never shy of using my work email to sign up for things and give to account managers etc. It is used on my microsoft SSO, my Dell business account, my slack account etc etc.

After I jumped through all their hoops to opt out, I got this email from them:

"We searched our records with your email: xxx@xxxxxx but could not find any information associated to it in our databases. We will keep your email: xxx@xxxxxx in our suppression list in order not to create any data associated with your email. "

So I guess they might not be as ubiquitous in their data capture as you may have thought? Or they are straight up lying.

Re: Someone at BrowserStack is leaking users' email addresses

#92
post #47

Earlier quoted context omitted.

I made no such assertion. Only that businesses do things in the business's interest more frequently than databreaches.

> Only that businesses do things in the business's interest That's not mutually exclusive with "someone on the sales team uploaded the entire customer list for sales purposes, not realizing the privacy implications". >more frequently than databreaches. You're fighting against both hanlon's razor and occam's razor here. The OP states the leak came from Apollo, and as other commenters have noted, Apollo specifically ha…

[deleted]

Re: Someone at BrowserStack is leaking users' email addresses

#93
post #10

Earlier quoted context omitted.

The simplest answer is they are voluntarily being scum and selling user data to make a quick buck. It’s almost universally true.

> It’s almost universally true. It’s not. I give a unique email address to every service I register with, which means I can see who is leaking my email address. Very few of them leak my email address at all, and those that do tend to do so involuntarily through data breaches. The other main factors in spam are the sleazeballs at Apollo, ZoomInfo, et al., services that use my email address internally for more than I c…

If you dont mind, What kind of unique email address do you use and how do you manage all the aliases?

Re: Someone at BrowserStack is leaking users' email addresses

#94
post #16

Earlier quoted context omitted.

>and selling user data to make a quick buck Are there actually companies that will pay you $$$ for a list of emails?

It's worth nothing. This is an online myth that marks out the user the way the sentence "Expert in JAVA, AWS, GCP, Oracle, and GIT" on a resume marks out the candidate.

My boss has paid many people for lists of email addresses in the past.

Im pretty sure he is not a mythical being!

Re: Someone at BrowserStack is leaking users' email addresses

#95

Having your own domain and giving a unique email address to everyone... Is it correct to call this canary trapping email addresses? https://en.wikipedia.org/wiki/Canary_trap

How is this possible for any normal person with a work provided 365 account?

Re: Someone at BrowserStack is leaking users' email addresses

#96
post #37
post #18

Email needs a consent revocation system effectively like how Blackberry had PINs for BBM

Hey.com works that way. You have to approve new senders before they can reach your inbox. And you can always revoke their permission to message you. I'd like to see that concept replicated to other email services. I don't particularly like all the other opinionated choices of Hey.com (especially the fact that you can't use IMAP).

This sounds to me like a normal black/white list, but everything is on the blacklist by default.

I imagine this can be achieved with most mailboxes with a simple deny all rule and then cherry picking email addresses to whitelist.

Re: Someone at BrowserStack is leaking users' email addresses

#97

Earlier quoted context omitted.

iCloud has a great feature that allows you to generate unique aliases on the fly quickly and easily. For example when signing up for new services via the web browser on iOS, you can generate a new address with the click of a button. Many years ago, before I started using iCloud Mail, I was running my own email server and had it set up to forward everything sent to any address on my domain to my inbox. The advantage w…

The downside of such iCloud aliases is that you cannot send emails from there (you can only reply to emails, and ofc receive emails)

True, and there has been a time or two where that has been inconvenient for me as well.

Initial account creation confirmation email, and maybe even some newsletters, were sent from noreply@ some domain. Responding to such an email address directly will likely either bounce or be silently dropped on their side, as indicated by them using noreply as the sender address.

The website might say to email support@ their domain. But because like you point out iCloud alias addresses cannot be used as sender when composing a new message, and I don’t have any past received emails from that address, I can’t email them using the same alias email address that I used to create an account.

And of course if the account belongs to jumping.carrot-1j@icloud.com and I instead send an email to them from a different sender address, then they will be sceptical about whether it really is the account owner trying to get in touch or some impostor. Assuming they don’t completely ignore the email on that grounds, you might eventually get support if you are able to either answer questions from them about past invoice amounts and dates or similar, or if they are willing to email the original account owner address from their support address. But it’s extra hassle, if they even bother to respond at all.

Fortunately most websites have a contact form or similar to get in touch with their support, but there are a few sites that have an email address as the only way to contact their support.

Re: Someone at BrowserStack is leaking users' email addresses

#99
post #95

Having your own domain and giving a unique email address to everyone... Is it correct to call this canary trapping email addresses? https://en.wikipedia.org/wiki/Canary_trap

How is this possible for any normal person with a work provided 365 account?

You can use the +label method on M365 work accounts, like first.last+label@workdomain.com

Outlook rules match on them too, for rules.

Re: Someone at BrowserStack is leaking users' email addresses

#100
post #58
post #44

Earlier quoted context omitted.

For a little more color for people unfamiliar with modern sales/marketing: 1. A user signs up to BrowserStack 2. BrowserStack (automatically) upload the submitted user’s information to Apollo 3. Apollo “enrich” the user’s details using information they already have about the person, e.g: company revenue, LinkedIn profile 4. Sales reps at BrowserStack use the enriched information to identify leads, bucket for marketin…

So I'm not disputing this, but I set up a similar scheme to the author almost 8 years ago and conduct 90+% of my online business through the custom emails. Everything from Amazon to small local business. In that time I have had 'leaks' twice: my State's Fish and Wildlife licensing organ, and GitHub. In both cases I assume it's more that the email ends up being public, not because of something like Apollo. I guess it'…

I used to do the same until I got tired of it. The only two leaks I found were United Airlines and Gary Johnson, the Libertarian presidential candidate, who sold my email to the Scott Walker campaign (strongly confirming my suspicions that Republicans use libertarianism as a gateway drug).
Post reply on HN