Please or to access all these features

Site stuff

Join our Innovation Panel to try new features early and help make Mumsnet better.

See all MNHQ comments on this thread

Mumsnet Data Breach - Q&A

189 replies

JustineMumsnet · 19/04/2018 21:04

As many of you already know, some screenshots of Mumsnet posts were recently uploaded to Twitter by a former Mumsnet intern – here’s a link to a previous thread discussing this in case you've not seen it.

Three of the screenshots showed an Admin’s view of the site and therefore contained the IP addresses of the posters concerned.

Understandably there have been loads of questions about the implications, about what data we hold and who has access to it so we've collated them here. Please do post any queries here or email [email protected] if you’ve any concerns or further questions.

Thanks and huge apologies if this has caused you any concern.

OP posts:
JessicaJonesJacket · 20/04/2018 09:26

Regardless of an article in The Guardian, I would like to think we can assume that the police and the IOC will deal appropriately with EH deleting any further data she may have stolen.

merrymouse · 20/04/2018 09:03

This is simply untrue. There are many mechanisms/processes and tools to prevent sysadmins access actual data.

And they should certainly deter people from sharing information ‘without thinking’.

Beyond11cisRetinol · 20/04/2018 08:50

I have a question not just for mnhq but anyone who knows about the gdpr. Once it comes into force, can you cherry pick information you want deleted, or is it an all or nothing thing?

So if, eg, I want my actual full name and postcode that I signed up with nearly ten years ago deleted (that I thought had already gone...), but not my entire posting history?

C8H10N4O2 · 20/04/2018 08:50

Anything you post on any site ultimately can be accessed by sys admins.

This is simply untrue. There are many mechanisms/processes and tools to prevent sysadmins access actual data.

In terms of mods accessing PMs a very typical model would be segregation and hierarchy of user roles - nothing fancy, basic functionality.

Stop telling us we're hysterical scaremongers who should just go and make a sandwich

^This

noblegiraffe · 20/04/2018 07:50

it is incorrect to assume that you deleting information or changing information would cause the holder of the information to delete the previously recorded information

Why? The data protection act says that data shouldn’t be kept any longer than necessary.

TerfsUp · 20/04/2018 07:47

Hi Justine

No questions. I just wanted to say "thank you" to you and MNHQ. This is obviously a difficult time for you and you are handling it with grace and courage.

Flowers Gin

Tartanscarf · 20/04/2018 07:46

This reply has been deleted

Message withdrawn at poster's request.

Beyond11cisRetinol · 20/04/2018 07:40

Thanks for answering the email question. I guess on that basis then it makes sense to assume that the deleted PMs are still there. Disgruntled staff don't need to worry about screenshotting my IP then, when all that "pretty data" is just sat there Angry

PattiStanger · 20/04/2018 07:40

I'm also now concerned to her that old email addresses are retained.

After reading yesterday's thread I changed my email to an anonymous one which I now find has compromised the anonymous one if it can easily be linked to my everyday one.

Please confirm today that the old email addresses have now been permanently deleted.

Peanutbuttercups21 · 20/04/2018 07:27

I cannot believe MN do not take this whole issue seriously (a bit cross, really?!)

merrymouse · 20/04/2018 07:23

The tweets are still being shared on twitter, most notably by a group calling themselves ‘the Lib Dem party body for gender & sexual minorities’.

Is this an official party group?

If so will you be contacting the libdems? The screenshots are deliberately misleading (one a sarcastic post taken out of context, another a quickly reported and deleted thread).

Obviously the libdems have their own views and policies on trans issues and we can vote accordingly, but they seem to be spreading defamatory information about your moderation policies.

AskBasil · 20/04/2018 06:58

I am so fucking sick of women being told that we are scaremongering, when we point to what could happen as a result of xyz.

The reason the Data Protection Act (and now the GDPR) even exist, is because of what could happen.

Are the people who draw up legislation scaremongers too, or is it only women who have perfectly reasonable concerns about violent men who hate them, having access to their data, who are scaremongers when they express concern?

Transactivists have a record as long as your arm, of abusing, harassing, intimidating and actually using violence against women who disagree with them (and in some cases, even against women who agree with them - check out the handmaiden at the Hyde Park fiasco who was treated very threateningly by Tara Whateverhisnameis, you know, the one who violently assaulted a disobedient woman.)

MRA's sent armed police around to Justine's house FFS.

TRA's are just another form of MRA's.

Women have every right to be at the very least extremely cautious and it is not unreasonable to be alarmed, that these violent men may have been passed personal details which identify them.

Stop telling us we're hysterical scaremongers who should just go and make a sandwich. That's how it's coming across, this minimisation and dismissal of concerns as though they are unreasonable. They are not. They really are not and it is unreasonable to pretend they are.

KeneftYakimoski · 20/04/2018 06:55

How can they link your data if you delete your account and sign up again with a different email?

With ease, if they actually wanted to. It would be treading a very dangerous data protection and computer misuse line, but a website which wanted to track users across registrations would have many ways to do it. All can be defeated, but would work for I suspect 90% of people likely to be signing up for a forum.

Firstly, they can use cookies. When you log on to a website like mumsnet, authorisation is done using a cookie. A cookie is a small piece of data which is supplied to the website which gave it you every time you visit a page on that website.

So to login you supply your username and password to one page, and the site gives you back a cookie. It probably looks like dDaQU/lerSASBo/+TwYfuA==. Sometimes it encodes some information (ie, you can look "inside" it and it means something), more often it's just an encoded random number (as that is).

A database is then used to say "anyone who presents the cookie dDaQU/lerSASBo/+TwYfuA== when accessing this site, for the next 72 hours (or whatever) can be assumed to have logged in as user so-and-so".

So if you delete your account and then create a new one, the cookie from your last login session may well still be passed across. If the site is more nefarious, it could actually drop a long-lived cookie for the express purpose of doing this, but it's more likely to happen "by accident".

OK, you say: I'm across that. I'll delete my account, delete all the cookies from my browser (it isn't enough, for various reasons too tedious to go into, to just delete the cookies dropped by MN), and then create a new account. Result!

Now we're off into the world of "MN don't do this, I assume, but they could tinfoil hattery". Browser Fingerprinting is the technique of looking at the precise configuration of your browser: not only the version, and the version of the operating system you are using, but the fonts you have installed, the extensions you have installed, any number of other subtle "my browser is not quite like your browser" issues. Combined with, say, the IP number - it won't usually uniquely identify a user, but it's likely to remain constant over a "delete my account, create a new one" session, and even if it doesn't, the particular ISP you are using is likely to remain the same - and you have a good chance of identifying delete and re-sign pairs. Not always, but often. Or at least sometimes.

I would, for the record, be amazed were MN doing this deliberately. But I wouldn't be completely surprised if they were collecting in their logs and trace information sufficient that a bad actor with access to data collected for good purposes would be able to re-analyse that data to spot such pairs. A capable threat actor with administrative access to a system is not to be trifled with. Which is why controlling, and indeed filtering, logging is a serious issue in overall security.

AuntieStella · 20/04/2018 06:50

I think a number of people have noticed how strange some moderation decisions have been for a while recently.

I wonder if having temp interns, rather than longer-term staffers, has contributed to that?

AuntieStella · 20/04/2018 06:48

Now, of course, it's absurd to keep old email addresses. No upside, lots of downsides. Dumping that archive would be a very good idea.

Agree. Unless there is a strong business reason to keep old email addresses, they should all be removed forthwith. I can't think of a single good reason to retain them.

Xeneth88 · 20/04/2018 06:46

DarthArts completely agree.

Saucery · 20/04/2018 06:44

Is there any internal moderation or overview of deleted posts in sensitive areas that might show bias on the part of individuals in the community Mod team?
Not just in the GC/TRA area but other topics such as antenatal choices.
One or two well, I didn’t consider my post to be contravening TG as others saying the same thing were left to stand may show considerable bias if a pattern was established that showed a Mod persistently came down on one side or the other.
I don’t expect the Mod Team to be perfect, none of us are and we all have our own personal bias in particular topics in the wider world, whatever our job. However, in my job that bias would be noticed due to a culture of monitoring (without spying on colleagues) and training that emphasises our personal bias is not acceptable in the workplace or on social media.

SonicVersusGynaephobia · 20/04/2018 06:32

United we stand, divided we fall...

phonemania · 20/04/2018 05:40

"It is incorrect to assume that you deleting information or changing information would cause the holder of the information to delete the previously recorded information. On or off the internet."

How can they link your data if you delete your account and sign up again with a different email?

thebewilderness · 20/04/2018 03:24

It is incorrect to assume that you deleting information or changing information would cause the holder of the information to delete the previously recorded information. On or off the internet.

SecretsRSecrets · 20/04/2018 02:05

apologies in to not into

SecretsRSecrets · 20/04/2018 02:04

@JustineMumsnet FlowersGin

AFAIK Justine is the only big business person who has stood up for our right to talk about WAG rights.

Hell, even very rich/protected celebs like JK have caved into TRA pressure.

Justine backed us, I'll back her.

DarthArts · 20/04/2018 00:37

If you interpreted it as patronising @noblegiraffe then that's your call.

Upshot is that aside some pertinent and relevant questions on this issue there's a hell of a lot of scaremongering going on.

Which is exactly what EH an her ilk wanted.

AdoraBell · 20/04/2018 00:30

Agree that deletion of evidence of data theft is wrong.

noblegiraffe · 20/04/2018 00:27

Darth I think it is reasonable to assume that if I delete something from my account then that data is deleted from my account. Deleting it is an indication that I no longer want them to hold that data. If you change your username, you can see that they still hold a record of your previous usernames.

overly faux outrage

How patronising.