Earlier quoted context omitted.
My point is I don't think one bit of this is accidental.
And my point is that it's pretty easy for people to accidentally do it, and this is corroborated by the available evidence, so we should apply hanlon's razor rather than assuming someone at browserstack was laughing maniacally while uploading the email list.
Someone at BrowserStack is leaking users' email addresses
41–50 of 123 posts
Re: Someone at BrowserStack is leaking users' email addresses
#42Earlier quoted context omitted.
I just do @ . It is sometimes confusing by when interacting with customer support ;-)
Yes ma'am, my email address really is bofa.com@ .com No I'm not trying to hack you. Which in hindsight is also what a hacker would say. I can't win...
They know their way around IT security! /s
Re: Someone at BrowserStack is leaking users' email addresses
#43Earlier quoted context omitted.
I just do @ . It is sometimes confusing by when interacting with customer support ;-)
Yes ma'am, my email address really is bofa.com@ .com No I'm not trying to hack you. Which in hindsight is also what a hacker would say. I can't win...
Re: Someone at BrowserStack is leaking users' email addresses
#44Everyone in this thread suggesting a “data leak” or “compromise” is totally missing the fact that this is how Apollo works. This is often times overlooked by Apollo customers themselves. You have to opt out of customer data sharing (and in doing so lose out on the value of the product): https://knowledge.apollo.io/hc/en-us/articles/20727684184589... Not commenting on whether this is good or ethical (or even totally l…
1. A user signs up to BrowserStack
2. BrowserStack (automatically) upload the submitted user’s information to Apollo
3. Apollo “enrich” the user’s details using information they already have about the person, e.g: company revenue, LinkedIn profile
4. Sales reps at BrowserStack use the enriched information to identify leads, bucket for marketing etc.
Apollo’s customer data sharing adds any information BrowserStack send to Apollo to the person’s profile with Apollo, accessible to all Apollo customers.
For example, any other Apollo customer can search something like “email addresses for decision makers at Example, Inc.” and get back a list including your email address (if you told BrowserStack you are a decision maker at Example, Inc.)
Every single marketing team is doing all of this, the only reason it was obvious in this case is that the OP used a unique email address for BrowserStack. If you sign up for any business product online, you surely have a profile in Apollo filled with details about you gathered from around the web (and details you submitted).
edit: https://www.apollo.io/privacy-policy/remove opt out link but Apollo are just one of many companies offering this service
Re: Someone at BrowserStack is leaking users' email addresses
#45Is the _very big_ company Amazon, I wonder.
(OP here) Nope! For all their faults, Amazon don't seem to have leaked anything of mine. Yet.
Selling email lists is business. Not selling email lists is, in some cases, much smarter, much more hard-nosed business, and is exactly what you would expect from Amazon.
When your only product is email addresses, you will sell them to anybody trying to sell other shit.
When you sell all the possible kinds of shit in the world, why on earth would you enable your competitors by giving them any form of access to your customer list?
Re: Someone at BrowserStack is leaking users' email addresses
#46> Like all good nerds, I generate a unique email address for every service I sign up to. This has several advantages - it allows me to see if a message is legitimately from a service, if a service is hacked the hackers can't go credential stuffing, and I instantly know who leaked my address. I think a lot of services will "de-alias" the email addresses from these tricks to prevent alts, account spam, and to still tar…
I use Fastmail with my own domain and 1Password. Together they give me a “masked email” button for forms that generates a random enough email address (two common words and four digits) and records the domain it was for. You can also create them ad-hoc from Fastmail’s interface. As well as simply attributing leaks, it’s most valuable as a phishing filter. Why would my bank ever email an address I only used to trial do…
Re: Someone at BrowserStack is leaking users' email addresses
#47Earlier quoted context omitted.
And my point is that it's pretty easy for people to accidentally do it, and this is corroborated by the available evidence, so we should apply hanlon's razor rather than assuming someone at browserstack was laughing maniacally while uploading the email list.
I made no such assertion. Only that businesses do things in the business's interest more frequently than databreaches.
That's not mutually exclusive with "someone on the sales team uploaded the entire customer list for sales purposes, not realizing the privacy implications".
>more frequently than databreaches.
You're fighting against both hanlon's razor and occam's razor here. The OP states the leak came from Apollo, and as other commenters have noted, Apollo specifically has a "Contributor Network" that shares email lists with other companies, and isn't well documented. It's not hard to imagine how this was done unintentionally. On the other hand there's no evidence to suggest this was done intentionally, other generic cynicism of "businesses do things in the business's interest" or whatever.
Re: Someone at BrowserStack is leaking users' email addresses
#48Re: Someone at BrowserStack is leaking users' email addresses
#49Re: Someone at BrowserStack is leaking users' email addresses
#50> Like all good nerds, I generate a unique email address for every service I sign up to. This has several advantages - it allows me to see if a message is legitimately from a service, if a service is hacked the hackers can't go credential stuffing, and I instantly know who leaked my address. I think a lot of services will "de-alias" the email addresses from these tricks to prevent alts, account spam, and to still tar…
I just do @ . It is sometimes confusing by when interacting with customer support ;-)