Please or to access all these features

Site stuff

Join our Innovation Panel to try new features early and help make Mumsnet better.

See all MNHQ comments on this thread

Mumsnet Data Breach - Q&A

189 replies

JustineMumsnet · 19/04/2018 21:04

As many of you already know, some screenshots of Mumsnet posts were recently uploaded to Twitter by a former Mumsnet intern – here’s a link to a previous thread discussing this in case you've not seen it.

Three of the screenshots showed an Admin’s view of the site and therefore contained the IP addresses of the posters concerned.

Understandably there have been loads of questions about the implications, about what data we hold and who has access to it so we've collated them here. Please do post any queries here or email [email protected] if you’ve any concerns or further questions.

Thanks and huge apologies if this has caused you any concern.

OP posts:
DarthArts · 20/04/2018 00:16

@noblegiraffe

Every site you sign up to holds data about you.

Every single one.

MNHQ have answered what data they hold on the Q&A.

As a more general point.

I'm sorry but this overly faux outrage is beginning to grate.

DarthArts · 20/04/2018 00:04

I note Bumble has gone.

DarthArts · 20/04/2018 00:02

I think that's the problem tbh.

There's a lot of assumptions.

Honestly I think everyone needs to calm tf down about this.

noblegiraffe · 19/04/2018 23:55

Not official advice, Darth, just posters on threads talking about it. I’m a bit annoyed that MNHQ are holding account data that I can’t see. If I e.g. originally provided my postcode but deleted it, is that actually still on my account too?

People took measures post-Jeffrey that might actually have been pointless.

ChoccyJules · 19/04/2018 23:37

I must have missed that phishing stuff. I am usually all over this kind of thing but for some reason saw PMs differently. I understand they could be pulled up by admin if necessary, I just wonder why they would do this and how many staff had this sort of access.

PencilsInSpace · 19/04/2018 23:36

I always assumed some roles at MNHQ had access to PMs.

I never expected that just about anybody who worked there or did an internship would have access.

DarthArts · 19/04/2018 23:35

What advice?

noblegiraffe · 19/04/2018 23:34

Please can you confirm that you will be deleting records of old email addresses and anything else that users cannot see that is held on them from their ‘my account’ screen?

Advice is being given to users to change their email address to something non-identifiable but this will give a false sense of security if old data is simply being held without their knowledge.

AornisHades · 19/04/2018 23:32

PMs can be read, yes. That was confirmed a while back I thought. There were fishing PMs and it was discussed then

DarthArts · 19/04/2018 23:29

Of course they can access PM's.

Anything you post on any site ultimately can be accessed by sys admins.

KatherinaMinola · 19/04/2018 23:25

I just assumed that they could, Choccy. Not necessarily that they did, but that they could.

I didn't reckon on MN staff stealing the data though.

ChoccyJules · 19/04/2018 23:23

Did we know that MNHQ can read our PMs? I would ask why this is. If the police or interpol demand access that's one thing but on a day to day basis I for one assumed that PMs didn't fall under the same agreement (eg right to publish) as posts on threads. So why do mods/other staff need access to them?
I will add that I am not worried about the content of my PMs but I would still be concerned that I had shared information there which I never expected a third party to have access to.

PencilsInSpace · 19/04/2018 23:16

you cannot let her delete any extra data she has without disclosing it to you. You also cannot just accept her word on this matter

This with giant deafening alarm bells and big flashing lights on.

Encouraging the destruction of evidence is probably a criminal offence in itself. If nothing else it adds to the destruction of trust between MNers and your company.

This is our data @MNHQ, not yours.

We ticked a box to say we agree to you using our data (not taking ownership of it) for various purposes, on the understanding that you were committed to ensuring that our privacy is protected.

If this is no longer a commitment then you need to get us all signed up to a new T&C - 'post at your own risk, we don't care who gets your data or what they do with it. We'll protect ourselves, not you.'

.
KeneftYakimoski · 19/04/2018 23:12

why do they need your old email if you have changed it?

I can see how that one might have arisen, actually, although I think it's a weak argument. These days we take it for granted that anyone can obtain any number of email addresses which are not linkable, but that was kinda-sorta not realised a decade ago. I mean, it was in fact just as true, but my memory of the period is that it was kinda-sort assumed that email addresses were a bit of a fag to change, so people only did it as a last resort. So I can imagine that it was decided to keep old email addresses as part of the "previously banned posters" detection: if someone registered a new account you could check whether it was associated with an old, troublesome email address.

It's a pretty crap argument, not least because my memory is that donkeys' years ago I signed up for an MN account with a mailinator email address, which is the burner's burner, so there was no serious joined-up attempt to enforce a "banned email" policy with any teeth. But I can imagine it was felt to be useful when tracking people who posted, got banned, and popped up again. I don't think it was useful, but it's enough of a "business purpose" for the era.

Now, of course, it's absurd to keep old email addresses. No upside, lots of downsides. Dumping that archive would be a very good idea.

AornisHades · 19/04/2018 23:12

Has anyone had sight of EH's Twitter posts after she protected it? Do you know what else was posted?
Hopefully she doesn't have identifying details screenshotted of posters she has targetted for GC views tucked away and has sold her career down the Swanee for a few useless IP adresses.
A pp mentioned the purpose of storing old email addresses and this is a valid question you might need to deal with in May when GDPR hits. You may well have a pile of 'right to be forgotten' requests coming!
In some ways EH has done us all a favour by showing her hand on a small subset of her data and leading us to question what is being held, is accessible and whether that is appropriate. And indeed playing her hand with a month to go, highlighting that before the fines :)

Weezol · 19/04/2018 23:12

Excellent post Craic.

TheCraicDealer · 19/04/2018 23:10

I LOVE MN. Honestly. I love it, i was fangirling all over Justine at the weekend and I'm sorry that this shit has been laid at her door.

However, I do not understand the willingness to engage with a disgruntled ex employee who has betrayed you, her colleagues and the users of this website. Betrayed not only the women who feel this is the only space they have to verbalise their concerns about GRA, but everyone else who needs or takes value from this place for innumerous other reasons. She did this knowing that it would damage you and risk this forum's existence. She may be "sorry" and you may truly believe her, but sometimes sorry just doesn't cut it.

I know she is an ex colleague, but she gave zero shits about that when she decided to use her valuable experience at MN to pouff up her own ego and profile. I don't care that she's "deleted" everything because, as has been suggested by MN mods previously, she likely sent the material on or stored it elsewhere during her employ. There is a possibility that this is no longer within her control. Like a cheating spouse on Relationships, she will tell you what she calculates she absolutely has to and no more. Trusting her would be incredibly naive at this point, and I hope there's something going on in the background that isn't being disclosed rather than simply taking her word for it.

[exhale]

Omnomnomnivore · 19/04/2018 23:03

PencilsInSpace and FloraFox have articulated this perfectly. As usernames can be linked with personal data (names and addresses) and sensitive personal data (posts on e.g. pregnancy choices, disability, race) then a raft of information on one person could easily be found, depending on where this data was held and how securely. This goes way beyond one debate and into a wider security issue. MN should be very glad this happened now and not post-GDPR.

I'm not going to demonise EH but after reading the other thread... really Justine? You feel "a bit cross" with the intern? No wonder so many people are asking if you're taking this seriously!

MipMipMip · 19/04/2018 23:03

I am asking them in the context of not knowing the size if the breach, only what has been revealed so far.

DarthArts · 19/04/2018 22:57

There have been some great questions asked but keeping asking them in the context that there has (and it's clear this is not true) been a mass data breech is just feeding the people and ideology who feel the same way as Emma.

FFS get a grip and stop fuelling nonsense.

MipMipMip · 19/04/2018 22:50

And I can't spell breach*Hmm

MipMipMip · 19/04/2018 22:50

I would expect some sort of disaster plan, yes. This would usually be done in stages so if x happens you compliment a, if y happens you implement a+b etc.

Something like this there should be procedures in place - automatic report to the information commissioner, statement sent out acknowledging what has happened within an hour, IT checking for malware and potential breeches, attempts made to find out what information was taken, lawyers involved to make sure no evidence deleted. As this was an internal attach all staff who she was friendly with or worked with should be interviewed separately, not suspecting them but they might have seen something that would help and you don't want memories influenced by each other.

Any organisation that holds data on this scale should have a plan like this. If it was an external breech that would also include shut down from the net to stop further information trickling away or more attacks. And forensic IT searches for anything hidden and to reveal what had been taken.

What is angering me is not that this has happened (although it shouldn't have done) it's that this stuff isn't being done. The investigation appears to be asking EH what she took and if it has been passed on. Mumsnet don't appear to know what category the information they have is. They are keeping old information - why do they need your old email if you have changed it? And they really don't appear to grasp the potential damage if their protege has not told the truth and has more information that she will either publish or quietly pass along to others.

FloraFox · 19/04/2018 22:47

Bumble I totally agree!

whatashower · 19/04/2018 22:46

For Justine and all the team.
Gin
Thank you.

Bumblefuddle · 19/04/2018 22:45

This reply has been deleted

Message withdrawn at poster's request.