Please or to access all these features

Site stuff

Join our Innovation Panel to try new features early and help make Mumsnet better.

See all MNHQ comments on this thread

Mumsnet Data Breach - Q&A

189 replies

JustineMumsnet · 19/04/2018 21:04

As many of you already know, some screenshots of Mumsnet posts were recently uploaded to Twitter by a former Mumsnet intern – here’s a link to a previous thread discussing this in case you've not seen it.

Three of the screenshots showed an Admin’s view of the site and therefore contained the IP addresses of the posters concerned.

Understandably there have been loads of questions about the implications, about what data we hold and who has access to it so we've collated them here. Please do post any queries here or email [email protected] if you’ve any concerns or further questions.

Thanks and huge apologies if this has caused you any concern.

OP posts:
FloraFox · 19/04/2018 22:43

JustineMumsnet said on the other thread about SPD:

If people volunteer that info to a public forum that’s a different thing.

People are not volunteering the info on a public forum where they are publicly identified - they are sharing the information in an anonymous forum and it is MNHQ's responsibility to maintain that anonymity. As bumble said, primarily by keeping the data sets separate.

PencilsInSpace · 19/04/2018 22:43

Thank you for at last calling this a data breach.

I just read this on the 'sharing' thread: What people volunteer to post is not classed as Sensitive Personal Data ... Any sensitive data that we ask for/collect (eg medical info) then we have a legal obligation to make sure we protect it. If people volunteer that info to a public forum that’s a different thing.

I don't believe this is correct.

All the data you hold on us is volunteered from our sign up data to 'what's for dinner?'. Behind the scenes you can work out exactly what RL identifiable people had for dinner. As well as our medical issues, when our last period was, the ins and outs of our abusive relationships, the difficulties we faced contemplating a termination, how we vote, what we do in bed ... bla bla bla, and of course what we think about the transactivist agenda.

This is what makes all the data you hold on us sensitive and personal. The BIG draw to posting on MN is we can describe what we're going through and say what we think anonymously. You appear to be not bothered about the consequences of compromising this privacy.

Maybe you have shit hot lawyers who are finding all the loopholes to make this just about legally OK. It's not morally OK though and everyone here can see it. We were only here in the first place because we trusted you.

Bumblefuddle · 19/04/2018 22:42

This reply has been deleted

Message withdrawn at poster's request.

Bumblefuddle · 19/04/2018 22:41

This reply has been deleted

Message withdrawn at poster's request.

Lokisglowstickofdestiny · 19/04/2018 22:39

I'm concerned that you appear to be retaining old email addresses. What business need do you have for this - if you don't have a legitimate reason for retaining it you should be deleting it from your records?

DarthArts · 19/04/2018 22:37

@SomeDyke

You might be right on that :-)

After the life extinction event the only think left is left is MNetter with a loo brush, clean carpets, penis beaker in the bedroom, EKL in the garden brandishing Zoflora in a water cannon ;-)

MrsTylerJoseph · 19/04/2018 22:34

I’ve given you my real name and address before, not when I signed up as I signed up with a fake name but because I won something in a competition.

Would those details still be held by MN and would a member of staff be able to easily access that information if they wished?

In view of the reputation MN are getting in the TRA world are you concerned Justine that people may try to infiltrate MN by applying for jobs, pretending to be uninterested in Trans issues and then doing something awful to cause a load of chaos of MN and it’s users? Like aa massive data breach/publication?

ChardonnaysPrettySister · 19/04/2018 22:31

Beyond they said the old identifying emails are still accessible.

DarthArts · 19/04/2018 22:31

MIP

A disaster plan...

In IT terms that's generally related to a major systems outage.

That's not the case here.

In terms of a data leak, yes it's not great but being frank we are not on the scale of Facebook here.

3 users - had IP address linked to them that might - just might - have given a geo location within 5/6 miles. Dynamic IP address which change. 3 users.

Yes 3. On the the basis of screenshots by a politically motivated intern.

Honestly I think a lot of people need to get a grip.

I've seen less posts about FB data breaches of millions of users than this.

MagneticMan · 19/04/2018 22:31

(some) MNers are cockroaches

Hasn't Milton suffered enough online vilification already without being brought into a TRA data theft debate Sad

KeneftYakimoski · 19/04/2018 22:30

Emma told us that she would delete anything she could find that was mumsnet related from her devices

So to be clear, you've reported an information breach to the ICO and the Police, and then agreed a strategy of destroying evidence of that breach with the person who has admitted carrying it out?

KreigersClones · 19/04/2018 22:29

I know some of you think there's some kind of cover up going on here and there's not a lot, it seems, we can do to convince you otherwise
Making her promise to delete anything mn related rather than forcing her to disclose it to you/the police probably isn’t helping tbh...

FloraFox · 19/04/2018 22:27

@JustineMumsnet

I don't think there is a cover up going on but you cannot let her delete any extra data she has without disclosing it to you. You also cannot just accept her word on this matter.

You need to get copies of the other data she has and make the appropriate reports and notifications to anyone whose data has been compromised. You also need to find out whether she has shared that data with anyone else. You should also inform the police that she may have further data that she might destroy as this is evidence of potential criminal action.

Beyond11cisRetinol · 19/04/2018 22:25

Hi Justine, just carrying my questions over from the other thread...

A former MN employee stated upthread (on the other thread) that sign up info is available to any mn admin. I don't have a problem with that necessarily, but just wanted to check - if I have changed from the info I signed up with to something less outing (say "Jane smith" and "[email protected]" to "Jane" and "[email protected]"), are both visible to you, or can you only see the updated one?

And with PMs, a few people have sent real names or addresses to one another. After Jeffery we were advised to delete anything like that in case of a breach, but can MNHQ see deleted PMs?

Then last one... I'm a product tester with the insight team. Assuming (hopefully!) the answer to the above two posts is that admin can't see my old/deleted data, are they able to access the insight team data?

I'm actually "out" in my real name so the TRA comeback isn't a massive concern in my case, but there is a lot of sensitive info on my mn posts over the past nine years that I'd rather not have linked to my real (quite uncommon) name.

MipMipMip · 19/04/2018 22:24

I suppose the real question is are you are of what a massive deal this is? It could be nothing, she have really only took those screenshots and will do nothing more. Or it could be huge with her handing data straight over to TRAs. But it is coming across very naively.

SomeDyke · 19/04/2018 22:23

"I'd put less faith in anything "Ariel" had to say than a MNetter arguing a loo brush is sanitary."

Except there might be one thing that the washing-powder person may be right about.............(some) MNers are cockroaches, which means we can survive a nuclear blast, unharmed...........I'm brandishing my loo brush with my antennae. Plus more Gin for MNHQ (these multiple legs come in handy!)

MagneticMan · 19/04/2018 22:21

Irrespective of your reports to ICO and the Police, will you be conducting your own internal investigations into this breach of data, i.e. by employing Forensic IT experts to analyse the extent of what information EH accessed during her internship?

I think that would go a LONG way to restoring faith in MN. I'm sure the organisation can afford it and it would be an appropriate response under the circumstances.

It would help if they analyse the data re: access of other MN employees over the period when EH was employed. It seems there's a lot of doubt as to whether Emma's claims about 'friends on the inside' is true or not. MN feel that it's not true whereas the users whose personal data has been compromised are not so convinced.

I think MN has an awful lot of bridges to build due to data-fat trolls lurking beneath them in plain sight.

MipMipMip · 19/04/2018 22:20

You should still habe had a disaster plan. Why didn't you?

Why are you apparently so unaware of what falls under what data category? Are you getting good advice and did you previously?

JustineMumsnet · 19/04/2018 22:19

@ChampiontheWonderHamster

You said in your statement Emma had no more data. In the Guardian article it said she had promised to delete further data. Which is correct?

I’d also like an answer to this when you come back tomorrow. Thanks.

Both - Emma told us that she would delete anything she could find that was mumsnet related from her devices. This is not in contradiction to the Guardian article.

I know some of you think there's some kind of cover up going on here and there's not a lot, it seems, we can do to convince you otherwise. We've endeavoured to be as straightforward and honest about what's happened and how and why. We definitely can do some things better procedurally and technically for sure but we're not lying to you. Anyhow on that note I really am off. Night all.

OP posts:
truthybeach · 19/04/2018 22:15

Slightly off topic but in light of the GDPR regulations are you changing any of your processes regarding personal data?

AskBasil · 19/04/2018 22:14

one or two of our team have said they're worried we're not being thorough enough in deleting things that are mean.

What is the criteria you use to decide that something is mean, please?

Is the "meanness" criteria applied across all mumsnet threads and topics, or just trans issue posts?

Why can't women be mean about men? Why are you complying with that taboo? We have the right to laugh at men, to ridicule them and to point out when they look or act in a ludicrous fashion. Women laughing at men is a massive political issue - they murder us for it. Our deepest fear about men is that they will murder us, their deepest fear about us, is that we will laugh at them. Otherwise known as being "mean" to them. It is an act of defiance and dissidence to do it. It's the act of a quisling to put a stop to it because male feelz matter.

Don't be a quisling Mumsnet. It will damage your brand.

MrsHathaway · 19/04/2018 22:13

*full user delete

MrsHathaway · 19/04/2018 22:13

Will it be possible to do a GDPRstyle fill user delete before GDPR, or will those currently deleting their accounts be leaving traces in your database and backups?

tribpot · 19/04/2018 22:12

There is no evidence of anyone on our staff mis-using mod powers.

As RoseAndRose says, with no audit facilities, you have no evidence either way. I had hoped MN might have upped its game on IT security after Jeffreygate. I strongly recommend you overhaul your tech function - it seems very disconnected from the main business of MN. I assume you can see that with such a demonstrably poor grasp of IT, there is no reason to trust statements from MN on this subject?

You have been asked repeatedly what measures you are taking to establish what else might have been stolen. The truth seems to be you have no absolutely no way of doing so, so you're choosing to believe an intern with every reason to lie when she says she's disclosed everything she has.

I don't believe we have any one who poses a risk to user data on the current team.
You have no way to know this.

AuntieStella · 19/04/2018 22:09

'Yes, the old email is still visible'

Why?