Live data from Hacker News

Someone at BrowserStack is leaking users' email addresses

shkspr.mobi

71–80 of 123 posts

Re: Someone at BrowserStack is leaking users' email addresses

#71

Earlier quoted context omitted.

There are some big brain companies who will block you if their name appears in the email address. Like Discord. You can create an account, with discrod@example.com. But a seconde later you will get an email that your account got band. They know their way around IT security! /s

What you say is often true, but in the case of Discord, at least in my case, you are wrong. My Discord email address is discord@xxx.com, and I am still receiving emails from them.

It happend to me when i created my account in 2025. Within seconds of verifying the address I got a email that my account was band for TOS violation. I than created a seconds account (within minutes from the same IP) only writing "dc" instead of "discord" and that worked. ¯\_(ツ)_/¯

Re: Someone at BrowserStack is leaking users' email addresses

#72
post #20
post #15

> Like all good nerds, I generate a unique email address for every service I sign up to. This has several advantages - it allows me to see if a message is legitimately from a service, if a service is hacked the hackers can't go credential stuffing, and I instantly know who leaked my address. I think a lot of services will "de-alias" the email addresses from these tricks to prevent alts, account spam, and to still tar…

I just do @ . It is sometimes confusing by when interacting with customer support ;-)

I have an account just like that at Best Buy with my domain. The teenage cashier I gave it to thought it was cool.

Re: Someone at BrowserStack is leaking users' email addresses

#74

Having your own domain and giving a unique email address to everyone... Is it correct to call this canary trapping email addresses? https://en.wikipedia.org/wiki/Canary_trap

Sounds about right. Yes, I've been doing it for decades now and besides telling you who's selling email lists, it makes filtering much easier. Filtering by To: is pretty low effort compared to Bayesian spam filters etc. They get tossed in a Sieve filter as soon as they become a problem, and I'll send a bitch letter to the leaker with another random email address to see how dedicated they are to screwing me.

Re: Someone at BrowserStack is leaking users' email addresses

#75
post #5

BrightData is another company offering hosted browsers who has also recently leaked private data, although they did email customers to warn them. I wonder if both of these companies were compromised by a shared vulnerability in headless Chrome? Or else just a coincidence that 2 headless browser companies got hacked at the same time? I run a headless browser fingerprinting project and have found that URLs that I only…

Brightdata? Isn't that the israeli firm formerly called luminati that sells you shady "high quality residential IPs" that you can rotate to scrape the web?

Now I remember these scumbags. Hijacked HolaVPN I think.

Re: Someone at BrowserStack is leaking users' email addresses

#77
post #13

>After a brief discussion, the emailer told me they got my details from Apollo.io The landing page for Apollo.io says it's a "AI sales platform". In other words, a CRM. My guess is that someone on the sales team uploaded the entire customer list for sales purposes, not realizing the privacy implications.

Working in sales but not being able to handle customer data responsibly (for whatever reason). Not a good look.

Re: Someone at BrowserStack is leaking users' email addresses

#78

Earlier quoted context omitted.

What you say is often true, but in the case of Discord, at least in my case, you are wrong. My Discord email address is discord@xxx.com, and I am still receiving emails from them.

It happend to me when i created my account in 2025. Within seconds of verifying the address I got a email that my account was band for TOS violation. I than created a seconds account (within minutes from the same IP) only writing "dc" instead of "discord" and that worked. ¯\_(ツ)_/¯

Apparently they (unlike other entities I've dealt with) did not go back and review all of the existing, valid email addresses in their user database.

It's always an unpleasant surprise when some company terminates a years-old, active and valid account because of a stupid policy change on their part.

Re: Someone at BrowserStack is leaking users' email addresses

#79
post #13

>After a brief discussion, the emailer told me they got my details from Apollo.io The landing page for Apollo.io says it's a "AI sales platform". In other words, a CRM. My guess is that someone on the sales team uploaded the entire customer list for sales purposes, not realizing the privacy implications.

Working in sales but not being able to handle customer data responsibly (for whatever reason). Not a good look.

You say this like it’s unusual. In my experience, sales is incentivized to only really care about closing deals. Everything else is often just a speed bump to them.

Re: Someone at BrowserStack is leaking users' email addresses

#80
post #47

Earlier quoted context omitted.

I made no such assertion. Only that businesses do things in the business's interest more frequently than databreaches.

> Only that businesses do things in the business's interest That's not mutually exclusive with "someone on the sales team uploaded the entire customer list for sales purposes, not realizing the privacy implications". >more frequently than databreaches. You're fighting against both hanlon's razor and occam's razor here. The OP states the leak came from Apollo, and as other commenters have noted, Apollo specifically ha…

On the other hand it is always convenient to hide behind the "We big, careless, silly org, we no knows how to handle data.". If we apply too many razors, then they are just gonna cut our freedom away. At some size of organizations negligence becomes malicious, since they ought to have people knowing how stuff should be handled and they most likely ignore it.

What is more likely? Everyone at an organization's IT, sales and data protection department is incapable of doing their job, or someone doesn't give a damn, calculating, that preventing such things from happening costs too much?

Post reply on HN