Live data from Hacker News

Someone at BrowserStack is leaking users' email addresses

shkspr.mobi

31–40 of 123 posts

Re: Someone at BrowserStack is leaking users' email addresses

#31
post #13

>After a brief discussion, the emailer told me they got my details from Apollo.io The landing page for Apollo.io says it's a "AI sales platform". In other words, a CRM. My guess is that someone on the sales team uploaded the entire customer list for sales purposes, not realizing the privacy implications.

> not realizing the privacy implications. If only.

Linkedin got users to unwittingly to share their entire contact list by signing into gmail. What makes you think something similar wouldn't happen to some non-technical person on the sales team?

Re: Someone at BrowserStack is leaking users' email addresses

#32
post #15

> Like all good nerds, I generate a unique email address for every service I sign up to. This has several advantages - it allows me to see if a message is legitimately from a service, if a service is hacked the hackers can't go credential stuffing, and I instantly know who leaked my address. I think a lot of services will "de-alias" the email addresses from these tricks to prevent alts, account spam, and to still tar…

The way that this is done these days (and likely what the author did/does) is that you use a custom domain to receive mail; you provide an email like service@custom.com, and that way when service@ starts receiving spam you know exactly where it comes from

Take it a step further and do uuid@

Re: Someone at BrowserStack is leaking users' email addresses

#33
post #15

> Like all good nerds, I generate a unique email address for every service I sign up to. This has several advantages - it allows me to see if a message is legitimately from a service, if a service is hacked the hackers can't go credential stuffing, and I instantly know who leaked my address. I think a lot of services will "de-alias" the email addresses from these tricks to prevent alts, account spam, and to still tar…

iCloud has a great feature that allows you to generate unique aliases on the fly quickly and easily. For example when signing up for new services via the web browser on iOS, you can generate a new address with the click of a button.

Many years ago, before I started using iCloud Mail, I was running my own email server and had it set up to forward everything sent to any address on my domain to my inbox. The advantage was that I could invent random aliases any time I wanted and didn’t even need to do anything on the server for those emails to get delivered to my main inbox. The very big drawback as I soon experienced was that spammers would email a lot of different email addresses on my domain that never existed but because I was going catch-all, would also get delivered to my main inbox. They’d be all kinds of email addresses like joe@ or sales@ or what have you. So apparently they were guessing common addresses and because I was accepting everything I’d also get tons of spam.

Re: Someone at BrowserStack is leaking users' email addresses

#34
post #15

> Like all good nerds, I generate a unique email address for every service I sign up to. This has several advantages - it allows me to see if a message is legitimately from a service, if a service is hacked the hackers can't go credential stuffing, and I instantly know who leaked my address. I think a lot of services will "de-alias" the email addresses from these tricks to prevent alts, account spam, and to still tar…

I use Fastmail with my own domain and 1Password. Together they give me a “masked email” button for forms that generates a random enough email address (two common words and four digits) and records the domain it was for. You can also create them ad-hoc from Fastmail’s interface.

As well as simply attributing leaks, it’s most valuable as a phishing filter. Why would my bank ever email an address I only used to trial dog food delivery?

Re: Someone at BrowserStack is leaking users' email addresses

#35
post #15

> Like all good nerds, I generate a unique email address for every service I sign up to. This has several advantages - it allows me to see if a message is legitimately from a service, if a service is hacked the hackers can't go credential stuffing, and I instantly know who leaked my address. I think a lot of services will "de-alias" the email addresses from these tricks to prevent alts, account spam, and to still tar…

The way that this is done these days (and likely what the author did/does) is that you use a custom domain to receive mail; you provide an email like service@custom.com, and that way when service@ starts receiving spam you know exactly where it comes from

yes, but service is too guessable, so append a randomly generated nonce as well, eg service_rjfh34@example.com. It doesn't need to be cryptographically random, just non trivially guessable to prove the service is leaking email addresses.

Re: Someone at BrowserStack is leaking users' email addresses

#36
post #31

Earlier quoted context omitted.

> not realizing the privacy implications. If only.

Linkedin got users to unwittingly to share their entire contact list by signing into gmail. What makes you think something similar wouldn't happen to some non-technical person on the sales team?

My point is I don't think one bit of this is accidental.

Re: Someone at BrowserStack is leaking users' email addresses

#37
post #18

Email needs a consent revocation system effectively like how Blackberry had PINs for BBM

Hey.com works that way. You have to approve new senders before they can reach your inbox. And you can always revoke their permission to message you.

I'd like to see that concept replicated to other email services. I don't particularly like all the other opinionated choices of Hey.com (especially the fact that you can't use IMAP).

Re: Someone at BrowserStack is leaking users' email addresses

#38
post #15

> Like all good nerds, I generate a unique email address for every service I sign up to. This has several advantages - it allows me to see if a message is legitimately from a service, if a service is hacked the hackers can't go credential stuffing, and I instantly know who leaked my address. I think a lot of services will "de-alias" the email addresses from these tricks to prevent alts, account spam, and to still tar…

[deleted]

Re: Someone at BrowserStack is leaking users' email addresses

#39
post #15

> Like all good nerds, I generate a unique email address for every service I sign up to. This has several advantages - it allows me to see if a message is legitimately from a service, if a service is hacked the hackers can't go credential stuffing, and I instantly know who leaked my address. I think a lot of services will "de-alias" the email addresses from these tricks to prevent alts, account spam, and to still tar…

I use DuckDuckGo Email and it generates unique addresses that I can both receive emails (obviously) and reply to from that email. There's also an option to shutdown that address and never receive spam again.

Re: Someone at BrowserStack is leaking users' email addresses

#40
post #31

Earlier quoted context omitted.

Linkedin got users to unwittingly to share their entire contact list by signing into gmail. What makes you think something similar wouldn't happen to some non-technical person on the sales team?

My point is I don't think one bit of this is accidental.

And my point is that it's pretty easy for people to accidentally do it, and this is corroborated by the available evidence, so we should apply hanlon's razor rather than assuming someone at browserstack was laughing maniacally while uploading the email list.
Post reply on HN