Live data from Hacker News

Someone at BrowserStack is leaking users' email addresses

shkspr.mobi

111–120 of 123 posts

Re: Someone at BrowserStack is leaking users' email addresses

#111
post #94

Earlier quoted context omitted.

It's worth nothing. This is an online myth that marks out the user the way the sentence "Expert in JAVA, AWS, GCP, Oracle, and GIT" on a resume marks out the candidate.

My boss has paid many people for lists of email addresses in the past. Im pretty sure he is not a mythical being!

You can buy it. But companies don’t sell it. Email lists are worth nothing to enterprise.

Re: Someone at BrowserStack is leaking users' email addresses

#112
post #93

Earlier quoted context omitted.

> It’s almost universally true. It’s not. I give a unique email address to every service I register with, which means I can see who is leaking my email address. Very few of them leak my email address at all, and those that do tend to do so involuntarily through data breaches. The other main factors in spam are the sleazeballs at Apollo, ZoomInfo, et al., services that use my email address internally for more than I c…

If you dont mind, What kind of unique email address do you use and how do you manage all the aliases?

There’s no real management involved. I set up a wildcard MX record for *.example.com and hand out jim@.example.com whenever anything needs my email address. I don’t need to specifically set up an alias. If spam comes in, I look at the To address to determine where they obtained my email address. Fastmail can be configured this way, for instance.

Most mail providers also support plus addresses or wildcard local parts, so you can do jim+@example.com or just @example.com. Gmail supports plus addresses, for instance. The downside is that some services reject pluses and some spammers strip out the IDs.

Re: Someone at BrowserStack is leaking users' email addresses

#113
post #37
post #18

Email needs a consent revocation system effectively like how Blackberry had PINs for BBM

Hey.com works that way. You have to approve new senders before they can reach your inbox. And you can always revoke their permission to message you. I'd like to see that concept replicated to other email services. I don't particularly like all the other opinionated choices of Hey.com (especially the fact that you can't use IMAP).

I sketched out a protocol for this a while back. The root cause of email abuse is that the only thing you need to send email to somebody is knowledge of their email address. We need to change that so that you also need their consent.

The initial email verification sent to you (“click here to confirm your email address”) includes an attachment requesting an auth token. Emails with this attachment get presented to the user in something akin to a friend request for email, with a consent screen describing how they intend to use your email and for how long. Approving the request hands them a Biscuit token.

The sender attenuates this token when sending email to you or when sharing with a third party provider like Mailchimp. Any emails authorised by a token automatically skip all spam filters. This is the carrot for senders to adopt – they can stop worrying about all the deliverability and IP reputation nonsense and can just send direct from their own servers, reversing the centralisation of email and making it more reliable by skipping spam filter heuristics.

All of these emails have reliable provenance and traceability. If a leak / abuse happens, you can revoke the token and any emails sent with it. Senders can also proactively revoke any tokens provided to third-parties in case they were breached, without affecting the sender’s ability to send themselves or through other providers.

Once a critical mass hits, you can auto-deny anything without a token. At this point, all the email you receive is from somebody who has obtained your explicit consent to do so.

Re: Someone at BrowserStack is leaking users' email addresses

#114
post #20

Earlier quoted context omitted.

I just do @ . It is sometimes confusing by when interacting with customer support ;-)

I had one website forward my mail to their legal department who asked me why I’m impersonating them :D Only required a short explanation though.

I've had this a couple times too

Re: Someone at BrowserStack is leaking users' email addresses

#119
Few things to note here are that what actually reached the OP was a cold sales email, not someone who had their password or payment info. The data that moved was business contact info going through a sales pipeline. Annoying? Absolutely. But the comments in here talking about GDPR fines and comparing this to actual data breaches feel like a massive escalation from what actually happened. I've seen real breaches in this industry. This isn't one. This is probably some SDR from sales team or the prospecting tool which is Apollo being sloppy in this case with their processes and not thinking through what happens to the data they're working with.

Re: Someone at BrowserStack is leaking users' email addresses

#120
The canary email trick is clever and the OP's frustration is valid. But the most likely explanation is their data passed through a CRM into an enrichment platform like Apollo, which then made it available to other customers. That's not a breach, i think it's just how these tools are designed to work. Which might be worse because it's happening at scale across thousands of companies. The response could've been better though. When a customer raises something like this you trace the data flow and explain what happened. But the real conversation should be about the enrichment industry itself. Opt-out instead of opt-in became the default and nobody questioned it. That's where regulation needs to catch up, hence singling out individual companies won't fix anything structural
Post reply on HN