Please or to access all these features

Site stuff

Join our Innovation Panel to try new features early and help make Mumsnet better.

See all MNHQ comments on this thread

Mumsnet Data Breach - Q&A

189 replies

JustineMumsnet · 19/04/2018 21:04

As many of you already know, some screenshots of Mumsnet posts were recently uploaded to Twitter by a former Mumsnet intern – here’s a link to a previous thread discussing this in case you've not seen it.

Three of the screenshots showed an Admin’s view of the site and therefore contained the IP addresses of the posters concerned.

Understandably there have been loads of questions about the implications, about what data we hold and who has access to it so we've collated them here. Please do post any queries here or email [email protected] if you’ve any concerns or further questions.

Thanks and huge apologies if this has caused you any concern.

OP posts:
AngryAttackKittens · 21/04/2018 06:00

This is very scary. Someone mentioned on the other thread that HQ can read all your PMs, and can see all your name changes etc. That's fine, as long as it's restricted access. But if someone who is working as an intern for few months can access them as well , it really scares me. Seems like people started deleting past posts. But I've read on one of the thread(Feenie one) that HQ still can see the deleted posts. That makes me feel even more scared to post anything personal, especially if you can't really trust who are the people have all the access to our info.

This concerns me too. Why would you ever set your systems up in such a way that an intern would have that level of data access? My experience is in e-commerce rather than social media, but anywhere I've ever worked that level of data access would be available to managers only, and even then some data would only be accessible to more specific roles. I've never heard of an intern being given that kind of access. Justine says they've since changed that, which is great, but my concern is, who made the decision to allow that level of access in the first place, and do they still work for Mumsnet?

What I'm getting at is that a competent IT department should never have allowed that, and nor should upper management. When access is requested for a specific role the response should always be "why, and is it really needed in order for them to do their job?"

The responses to recent questions indicate that there's still a lack of understanding of how to manage security. People pointing that out are being handwaved away. That does not fill me with confidence that better security protocols will be put in place.

This isn't about having a go at Mumsnet, or panicking. The stolen data is already out there, too late the fix that now. What the people raising issues are trying to do is make it harder for bad actors to create problems in the future.

thebewilderness · 21/04/2018 03:34

Is it possible that MHQ does not intend to send a membership wide advisory that there has been a breach? It needs to go out ASAP!

Weezol · 21/04/2018 01:34

@MNHQ At time of posting there are a number of threads appearing from first time posters canvassing MN users on being GC and Trans issues generally. I have reported via usual pocedures.
Hopefully, I am being over cautious about this and seeing patterns where there are none, however given your failure to manage the recent issues, please tell me you have increased overnight moderation for the weekend at the very least.

MrsHathaway · 20/04/2018 16:45

Er, in customise somewhere? Sorry, I turned them off literally years ago so I don't remember Blush but it's with the options to show OP highlighted and threads upside down and 100 posts per page etc.

ItsAllGoingToBeFine · 20/04/2018 16:43

I and presumably many others have stickies turned off

Shock I'd love to do this - where is the option?

MrsHathaway · 20/04/2018 16:03

I and presumably many others have stickies turned off. I do think an email is the least we should expect.

FreudianSlurp · 20/04/2018 15:01

This reply has been deleted

Message withdrawn at poster's request.

thurmanmerman · 20/04/2018 14:55

@KeneftYakimoski just a note to say thanks for the link to that Feynman report - it's brilliant.
Not just for engineering either. It applies to any group of people kidding themselves on that things are ok by changing the way they look at it.

Tartanscarf · 20/04/2018 14:45

This reply has been deleted

Message withdrawn at poster's request.

YetAnotherBeckyMumsnet · 20/04/2018 14:28

Hello everyone - just a quick one to say thanks for all your comments, and to let you know we've now stickied the Q&A page.

ItsuAddict · 20/04/2018 14:19

This reply has been deleted

Message withdrawn at poster's request.

TheHodgeoftheHedge · 20/04/2018 14:02

Yes. I think it's pretty poor that all users haven't been emailed. It's the least you can do to actually let people know about the incident.

FreudianSlurp · 20/04/2018 13:29

This reply has been deleted

Message withdrawn at poster's request.

MipMipMip · 20/04/2018 13:15

Have to admit I was very surprised an email hadn't gone out to everyone. It's standard practice.

ItsAllGoingToBeFine · 20/04/2018 13:09

And the Q and A page seems to only be linked to from this thread, not promoted in any way...

ItsAllGoingToBeFine · 20/04/2018 13:08

Would it be possible to put a thread linking to www.mumsnet.com/info/mumsnet-data-qa at the top of every board

Or, you know, email every user as is pretty standard when a data breach becomes apparent...

It really does seem like MNHQ trying as hard as possible to make sure no-one finds about this. This thread isn't even stickied FFS.

Would be really pissed if I only found out about the breach in the press!

FreudianSlurp · 20/04/2018 12:59

This reply has been deleted

Message withdrawn at poster's request.

AskBasil · 20/04/2018 11:40

Most of them are violent Spiderweb.

They are bog standard abusers and if they didn't call themselves women, they would be generally recognised as such.

merrymouse · 20/04/2018 11:32

I am willing to believe that the extent of the damage in this particular case was limited because the person involved only had a vague idea of how the internet works.

However, in general, I don't think employing people who are only vaguely aware of how the internet works is an effective way of maintaining security at a company like MN. I want to know how this situation will be improved.

KeneftYakimoski · 20/04/2018 11:14

What happened in this case was relatively minor in itself but it should be taking as a warning sign

As anyone working in health and safety or quality or any other statistical process will tell you: it's the near misses that count. The untreated risk of a catastrophe is quite small, so a year in which a catastrophe doesn't happen doesn't tell you that your controls are working, it just tells you that a rare event didn't happen. It's the near misses, and the little incidents, that should have been stopped by your controls but weren't, but which didn't turn into catastrophes because luck, which tell you whether your controls are effective. You need to listen to the near misses.

Everyone working in engineering of any sort should read Feynman's appendix to the Challenger report every year.

science.ksc.nasa.gov/shuttle/missions/51-l/docs/rogers-commission/Appendix-F.txt

It covers the way in which people use failures which don't develop to disasters to lull themselves into a false sense of security better than anything ever written.

hackmum · 20/04/2018 11:03

What comes out of this is that firewalls and so on are all very well but employees are always an organisations' biggest risk. Very many data breaches are the result of either deliberate action by disgruntled employees or accidents by employees (e.g. leaving a password on a sticky post-it, failing to log off the system when away from a desk, leaving your laptop in the pub etc).

For a site like Mumsnet, which has thousands of posts every day, many of them relating to sensitive issues such as domestic violence, sexual assault or abortion, the safety of posters' data is absolutely paramount. Mumsnet's employee vetting procedures must be rigorous, their training must be thorough and their access to sensitive data strongly controlled.

What happened in this case was relatively minor in itself but it should be taking as a warning sign of what can happen when an employee goes rogue. I'd like some reassurance that Mumsnet is putting in place the appropriate procedures I've suggested above.

CarpeVitam · 20/04/2018 10:42

Along with some pp I too am concerned that my original (identifying) email address is still on 'file'.

I think a change should be initiated whereby the only email address stored is my current one.

SpiderwebHammock · 20/04/2018 10:10

AskBasil, I agree absolutely with your post. This whole fiasco, but more importantly the way The way it's been minimised, has left me gobsmacked. I think this whole mess is going to escalate to serious violence at some point.

BUT:

Transactivists have a record as long as your arm, of abusing, harassing, intimidating and actually using violence against women who disagree with them (and in some cases, even against women who agree with them - check out the handmaiden at the Hyde Park fiasco who was treated very threateningly by Tara Whateverhisnameis, you know, the one who violently assaulted a disobedient woman.)

I'm pretty sure the TRA who menaced that woman was not Tara Wolf, but a different person. They were dressed very differently iirc. Which actually makes it fucking worse, that there were two violent TRAs present at Hyde Park and not just the one.

MrsHathaway · 20/04/2018 09:40

But I've read on one of the thread(Feenie one) that HQ still can see the deleted posts.

I think that depends on why it was deleted- or certainly will under GDPR.

If it's deleted by them for breaching TGs then that's not the same as being withdrawn by you for privacy reasons - the former is effectively "hide" rather than "delete". Under GDPR as I understand it, if you request a delete of all your data including posts then they also have to delete the information from the back end including backups (so it can't accidentally be restored in the event of reverting to a backed up instance). I don't know what that will look like on MN because at present a deleted post isn't deleted, but just emptied: the poster/time/date line is still there. I suspect all that will happen is that the time/date trace will still be there but the username will be redacted (see e.g. Reddit for examples).

That would show a difference between e.g.

GoadyFucker 13/04/18 12:52
Deleted for breaching Talk Guidelines

13/04/18 12:59
Message withdrawn at poster's request

user789653241 · 20/04/2018 09:29

This is very scary. Someone mentioned on the other thread that HQ can read all your PMs, and can see all your name changes etc. That's fine, as long as it's restricted access. But if someone who is working as an intern for few months can access them as well , it really scares me. Seems like people started deleting past posts. But I've read on one of the thread(Feenie one) that HQ still can see the deleted posts. That makes me feel even more scared to post anything personal, especially if you can't really trust who are the people have all the access to our info.