@JustineMumsnet
We emailed the affected users overnight offering to delete their posts, a retrospective name change or to change their email address. There are around 20 users affected
Can you please clarify how you have validated that list? Are you relying on logs or using logs of all replies to reports? (I'm assuming you have a timestamped audit trail).
It applied only to the emails/usernames of users who had posts reported (not to those doing the reporting). (Their details were included at the bottom of replies to the person who reported the post)
Why have email addresses started appearing at all? Replies in this type of system should keep all contact details blind both to reporter and moderator. That is a design choice which needed implementing and should have been picked up during data/security design. Is this another issues which is on the list to fix as a "glitch" of the upgrade?
We know how the error occurred - we obviously have checks and balances in place to stop this kind of thing happening and in two very clear ways the proper procedures weren't followed in this instance
If human beings can override procedures in two places without a check step them something is fundamentally wrong with the SDLC model. Config changes, particular those which could expose data should be both tested and automated and subject to review before deployment.
What has been put in place to stop procedures being overidden in future? We all remember the joy of the intern.
I'm really sorry this has happened and apologise wholeheartedly to all those who've suffered undue concern as a result
With the greatest respect, this statement is completely at odds with publicly posting the contents of the reports about one of your victims.