Live data from Hacker News

Someone at BrowserStack is leaking users' email addresses

shkspr.mobi

101–110 of 123 posts

Re: Someone at BrowserStack is leaking users' email addresses

#101
post #15

> Like all good nerds, I generate a unique email address for every service I sign up to. This has several advantages - it allows me to see if a message is legitimately from a service, if a service is hacked the hackers can't go credential stuffing, and I instantly know who leaked my address. I think a lot of services will "de-alias" the email addresses from these tricks to prevent alts, account spam, and to still tar…

Of course. I use Firefox Relay to generate a unique email address for every site where I have to use an email. That method hasn't failed me so far.

Re: Someone at BrowserStack is leaking users' email addresses

#102
post #44
post #12

Everyone in this thread suggesting a “data leak” or “compromise” is totally missing the fact that this is how Apollo works. This is often times overlooked by Apollo customers themselves. You have to opt out of customer data sharing (and in doing so lose out on the value of the product): https://knowledge.apollo.io/hc/en-us/articles/20727684184589... Not commenting on whether this is good or ethical (or even totally l…

For a little more color for people unfamiliar with modern sales/marketing: 1. A user signs up to BrowserStack 2. BrowserStack (automatically) upload the submitted user’s information to Apollo 3. Apollo “enrich” the user’s details using information they already have about the person, e.g: company revenue, LinkedIn profile 4. Sales reps at BrowserStack use the enriched information to identify leads, bucket for marketin…

Maybe you'd have insight into something that happened to me recently:

I did a search (DDG, Chromium) for an Anker product line that I've been following. Clicked the link to Anker, skimmed, nothing new.

Then shortly I get an email from "Checkmate" with a promo offer.

I don't have an Anker account or whatever, don't recall signing in. I figure it's fingerprinting or cookies, but so far it's never been so overt.

I feel like this is an indicator of something, some sea change. Of needing to squeeze more water from the stone. My phone's been blowing up with spam calls since. I've been mysteriously added to email lists. I'm getting short-code text spam in addition to the regular spam, which when I report to 7726, AT&T basically tells me it's fine, it's paid for.

This may be a ploy to get me to turn the AI features back on in Gmail, but it feels like somewhere, lines have been crossed.

Re: Someone at BrowserStack is leaking users' email addresses

#103

Earlier quoted context omitted.

The way that this is done these days (and likely what the author did/does) is that you use a custom domain to receive mail; you provide an email like service@custom.com, and that way when service@ starts receiving spam you know exactly where it comes from

^ I've been doing this with catchalls since before Google Apps for Domain was even a thing. Sometimes customer support staff bring up "oh, do you work at too"? I just tell them that I created an email address just for their company, in case they spam me.

> up "oh, do you work at too"?

Oh boy, I had many of these conversations and especially non technical people never grasp the concept, I had some cases where they demanded to change it and use a “real email like gmail!!”, one time I bought shoes and the store guy asked me the email to signup for whatever, so I read the shoe’s name and added the custom domain, gave me the the look as if I am bullshitting him. Another at a government connected agency and she thought “I work there because I have the agency email” despite it is the alias not the domain.

But similar to OP, few times I found the service is leaking my email, or they got compromised who knew.

Re: Someone at BrowserStack is leaking users' email addresses

#104
post #14

Earlier quoted context omitted.

Brightdata? Isn't that the israeli firm formerly called luminati that sells you shady "high quality residential IPs" that you can rotate to scrape the web?

Yes, that's the one. Their residential IPs service is one of the best ones, but their "ethically sourced proxies" claim seems dubious at best.

There was a research paper several years ago showing that the "residential IP" stuff is powered by botnets and compromised devices. Luminati is specifically called out.

Paper: https://xianghang.me/files/resi_paper.pdf Medium Article: https://medium.com/@xianghangmi/resident-evil-understanding-...

Re: Someone at BrowserStack is leaking users' email addresses

#107
post #40

Earlier quoted context omitted.

My point is I don't think one bit of this is accidental.

And my point is that it's pretty easy for people to accidentally do it, and this is corroborated by the available evidence, so we should apply hanlon's razor rather than assuming someone at browserstack was laughing maniacally while uploading the email list.

Hanlon's razor suggests that browserstack has made the conscious decision to use a vendor and share data with them. Companies of that size don't YOLO those things, that relationship and the data-sharing has passed through legal, they have a contract in place.

Don't assume businesses operate the same way some job-hunting person on monday morning is.

Re: Someone at BrowserStack is leaking users' email addresses

#108
post #44

Earlier quoted context omitted.

For a little more color for people unfamiliar with modern sales/marketing: 1. A user signs up to BrowserStack 2. BrowserStack (automatically) upload the submitted user’s information to Apollo 3. Apollo “enrich” the user’s details using information they already have about the person, e.g: company revenue, LinkedIn profile 4. Sales reps at BrowserStack use the enriched information to identify leads, bucket for marketin…

Maybe you'd have insight into something that happened to me recently: I did a search (DDG, Chromium) for an Anker product line that I've been following. Clicked the link to Anker, skimmed, nothing new. Then shortly I get an email from "Checkmate" with a promo offer. I don't have an Anker account or whatever, don't recall signing in. I figure it's fingerprinting or cookies, but so far it's never been so overt. I feel…

> This may be a ploy to get me to turn the AI features back on in Gmail, but it feels like somewhere, lines have been crossed

Lines have absolutely been crossed and there is no going back without a lot of political will

There are no rules anymore. The internet started it, and AI companies proved it. We're much worse of for it. The social contract is extremely flimsy nowadays

Re: Someone at BrowserStack is leaking users' email addresses

#109

Earlier quoted context omitted.

^ I've been doing this with catchalls since before Google Apps for Domain was even a thing. Sometimes customer support staff bring up "oh, do you work at too"? I just tell them that I created an email address just for their company, in case they spam me.

I've got a few dozen domains, and primarily use two of them for business interactions. One is a catchall, while the other requires me to create explicit email addresses (or aliases). Aside from issues such as the business entity (sometimes silently) prohibiting their name in my email address, I have sometimes encountered cases where part of the email validation process checks to see if the email server is a catchall,…

> checks to see if the email server is a catchall

How is this possible? Do they test sending to a few random addresses?

Re: Someone at BrowserStack is leaking users' email addresses

#110
Many years ago a substantially sized OSS groups' forum software (maybe KDE or Qt? it was a long time ago) was accidentally including user email addresses in the non-user-visible html tags of forum pages.

Web scanners though aren't people, and easily noticed them, thus building up a database of email addresses to spam people.

It was discovered when a friend mentioned that one of their uniquely generated email addresses was being used by spammers. Similar to this post.

So, we got in contact with the forum people to let them know, and they tracked down + fixed the problem.

Perhaps a similar thing is happening to the article author, rather than purposely malicious behaviour?

Post reply on HN