Live data from Hacker News

Someone at BrowserStack is leaking users' email addresses

shkspr.mobi

81–90 of 123 posts

Re: Someone at BrowserStack is leaking users' email addresses

#82
post #58
post #44

Earlier quoted context omitted.

For a little more color for people unfamiliar with modern sales/marketing: 1. A user signs up to BrowserStack 2. BrowserStack (automatically) upload the submitted user’s information to Apollo 3. Apollo “enrich” the user’s details using information they already have about the person, e.g: company revenue, LinkedIn profile 4. Sales reps at BrowserStack use the enriched information to identify leads, bucket for marketin…

So I'm not disputing this, but I set up a similar scheme to the author almost 8 years ago and conduct 90+% of my online business through the custom emails. Everything from Amazon to small local business. In that time I have had 'leaks' twice: my State's Fish and Wildlife licensing organ, and GitHub. In both cases I assume it's more that the email ends up being public, not because of something like Apollo. I guess it'…

As far as you know

Re: Someone at BrowserStack is leaking users' email addresses

#83
post #12

Everyone in this thread suggesting a “data leak” or “compromise” is totally missing the fact that this is how Apollo works. This is often times overlooked by Apollo customers themselves. You have to opt out of customer data sharing (and in doing so lose out on the value of the product): https://knowledge.apollo.io/hc/en-us/articles/20727684184589... Not commenting on whether this is good or ethical (or even totally l…

And the sad thing is, I can guarantee this thread alone will be great marketing for Apollo and they will gain a pile of new enquiries Monday morning.

Re: Someone at BrowserStack is leaking users' email addresses

#84
post #15

> Like all good nerds, I generate a unique email address for every service I sign up to. This has several advantages - it allows me to see if a message is legitimately from a service, if a service is hacked the hackers can't go credential stuffing, and I instantly know who leaked my address. I think a lot of services will "de-alias" the email addresses from these tricks to prevent alts, account spam, and to still tar…

iCloud has a great feature that allows you to generate unique aliases on the fly quickly and easily. For example when signing up for new services via the web browser on iOS, you can generate a new address with the click of a button. Many years ago, before I started using iCloud Mail, I was running my own email server and had it set up to forward everything sent to any address on my domain to my inbox. The advantage w…

The downside of such iCloud aliases is that you cannot send emails from there (you can only reply to emails, and ofc receive emails)

Re: Someone at BrowserStack is leaking users' email addresses

#85
post #16
post #10

Earlier quoted context omitted.

The simplest answer is they are voluntarily being scum and selling user data to make a quick buck. It’s almost universally true.

>and selling user data to make a quick buck Are there actually companies that will pay you $$$ for a list of emails?

It's worth nothing. This is an online myth that marks out the user the way the sentence "Expert in JAVA, AWS, GCP, Oracle, and GIT" on a resume marks out the candidate.

Re: Someone at BrowserStack is leaking users' email addresses

#86

Earlier quoted context omitted.

The way that this is done these days (and likely what the author did/does) is that you use a custom domain to receive mail; you provide an email like service@custom.com, and that way when service@ starts receiving spam you know exactly where it comes from

^ I've been doing this with catchalls since before Google Apps for Domain was even a thing. Sometimes customer support staff bring up "oh, do you work at too"? I just tell them that I created an email address just for their company, in case they spam me.

I am more specific: if I start receiving pornographic spam like I did to the address I gave Dell, I will know they have been hacked.

I will also not hold my breath waiting for the legally required breach notification they are supposed to send.

Re: Someone at BrowserStack is leaking users' email addresses

#87

Earlier quoted context omitted.

^ I've been doing this with catchalls since before Google Apps for Domain was even a thing. Sometimes customer support staff bring up "oh, do you work at too"? I just tell them that I created an email address just for their company, in case they spam me.

I've got a few dozen domains, and primarily use two of them for business interactions. One is a catchall, while the other requires me to create explicit email addresses (or aliases). Aside from issues such as the business entity (sometimes silently) prohibiting their name in my email address, I have sometimes encountered cases where part of the email validation process checks to see if the email server is a catchall,…

Wildcard email addresses will subject you to a torrent of spam when spammers try dictionary attacks against your domain. It's better to explicitly create aliases, I built a web UI for Postfix to do this for myself and family (https://GitHub.com/fazalmajid/postmapweb)

Re: Someone at BrowserStack is leaking users' email addresses

#89
post #69
post #16

Earlier quoted context omitted.

>and selling user data to make a quick buck Are there actually companies that will pay you $$$ for a list of emails?

Not exactly, but plenty will just sell everything to data brokers.

>but plenty will just sell everything to data brokers.

Again, "sell" implies that there's some company where they'll accept data from anyone and pay them for it, which so far as I can tell doesn't exist. That's not to say there's no selling going on. The fact that data brokers exist means they do, but that doesn't mean every business is in a position to "sell" data.

Re: Someone at BrowserStack is leaking users' email addresses

#90
post #12

Everyone in this thread suggesting a “data leak” or “compromise” is totally missing the fact that this is how Apollo works. This is often times overlooked by Apollo customers themselves. You have to opt out of customer data sharing (and in doing so lose out on the value of the product): https://knowledge.apollo.io/hc/en-us/articles/20727684184589... Not commenting on whether this is good or ethical (or even totally l…

Another way these companies get data is they have credits. It costs a credit for a salesperson to enrich the data of someone they're trying to contact. There are 2 ways to gain credits: 1 - cash; 2 - the salesperson installs a plugin in their inbox and it scrapes all contact info in the inbox.

ZoomInfo is the most aggressive about this.

re apollo: inbox scraping is what they're describing here [1]

> Apollo does leverage its large network of over 2 million contributors to improve the scope and accuracy of its database of business contact information and run verification checks that result in a better user experience for its entire customer base. Most of the data we collect from our Apollo users simply forms part of our verification system to check and confirm existing information in the Apollo database.

[1] https://knowledge.apollo.io/hc/en-us/articles/20727684184589...

Post reply on HN