Meet the Other Phone. Protection built in.

Meet the Other Phone.
Protection built in.

Buy now

Please or to access all these features

Chat

Join the discussion and chat with other Mumsnetters about everyday life, relationships and parenting.

Another Mumsnet data breach

90 replies

kittensinthekitchen · 06/06/2022 23:46

www.mumsnet.com/talk/site_stuff/4564026-change-in-format-of-response-to-report-emails

A user posted in Site Stuff earlier today to say that they'd received a response to a report they'd made, then noticed it included the other user's name and email address.

Justine has said the following

We had a temporary glitch with 'Report this post' for a short time today which meant the email of the person reported was included in the report and in a few cases in responses to those reports. This applies to a very small number of users and we'll be contacting them shortly to let them know. Our DPO has been informed and on his advice we'll report it the ICO if appropriate. Please be assured the issue is now fixed. We will of course be examining how it happened to ensure it never happens again. We're really sorry for any concern caused.
**

Has anyone been contacted? If you've noticed you've had a comment deleted today, beware, the person who reported it might have access to your personal information.

OP posts:
Simbaya · 07/06/2022 11:53

I'm not convinced this wasn't malicious.

Moosake · 07/06/2022 12:02

DeaconBoo · 07/06/2022 09:40

Thank you to the person who noticed this on their reporting email and posted about it. Many people wouldn't have given the "report confirmation" email a second glance!

Yes! Could have gone on ages!

pixie5121 · 07/06/2022 12:08

IncessantNameChanger · 07/06/2022 09:05

As a web developer you have to choose to display this and theres no chance it's a slip up. You have to call to the database to retrieve the user details of the poster and then choose to print it to the page.

So your standard display message + whatever strings you called from the DB

Even if you stored the deletion reason on the db next to the reported message it would be as a code and the user details wouldnt be in that section of the db. Everything has / should be separate unless its stored in the deletion message string which is very unbelievable.

Plus who tested it? UAT? I struggle to see how it happened tbh

Yes, all of this.

The developers working on this site are not just bad, they're horrendous, and would have been fired from any other company weeks ago. I'm not sure MN quite grasp just how bad it is. Like, you actually need to actively try to be this bad.

I am one of the '20' users affected - just my luck, when I barely ever get comments deleted. I use a throwaway email just for this site and don't post anything overly personal, but what if I had? People post all sorts of stuff about their home lives, domestic violence, etc. I've seen people in abusive relationships posting about having affairs. Can you imagine a malicious person getting their email and using it to contact their abusive partner?

I will definitely be taking this further. Luckily for me, I work in tech and deal with this stuff all the time. It won't be Mumsnet's choice whether or not they get reported to the authorities.

IncompleteSenten · 07/06/2022 12:12

I've just checked my email and yes, I have the email address of that stupid "faggot faggot faggot" poster from yesterday

Simbaya · 07/06/2022 12:18

I think it's important for us to know how many posters now have our details. I've also asked for the content of the reports to get an idea of why I was reported and thus figure out how potentially malicious those who have my email address may be.

WaitroseWoman · 07/06/2022 12:57

Very concerning.

WaitroseWoman · 07/06/2022 13:03

There were big problems on the site late last night - DDoS? No word from MNHQ on that.
www.mumsnet.com/talk/site_stuff/4562956-pages-taking-an-age-to-load-anyone-else

Simbaya · 07/06/2022 13:07

I responded to MNHQ email at 11.33am.
I haven't had a response.
So much for sorting it 'immediately'.

Care to respond @MNHQ?

grapewines · 07/06/2022 13:12

WaitroseWoman · 07/06/2022 13:03

There were big problems on the site late last night - DDoS? No word from MNHQ on that.
www.mumsnet.com/talk/site_stuff/4562956-pages-taking-an-age-to-load-anyone-else

I wondered about that.

User487216 · 07/06/2022 13:13

I have a separate email address for MN, I also reregistered a few months ago to clear out anything that may have been there, old usernames and stuff like that, if it gets hacked there isn't much there then.

BenCooperisaGod · 07/06/2022 13:58

For those of you not aware, the feminism section of mn host discussions on gender critical feminism that are not popular with trans rights activists.

I have had a joke theory that the site redevelopment was being done by a transrights activist, as something this shit couldn't have been done by accident.

Suddenly this theory doesn't seem so far fetched. Having e mail addresses revealed to activists would be very damaging for many women who use this site.

FourOclock · 07/06/2022 14:34

This is pretty awful isn't it? Very surprised there's been no response from MNHQ on this thread

Simbaya · 07/06/2022 16:00

@MNHQ Please respond.

Labpictures · 07/06/2022 20:02

TreadingWaters · 06/06/2022 23:53

This is really bloody serious.

MNHQ might let the ICO know? Might?

Might… if appropriate

might!
what

Labpictures · 07/06/2022 20:03

BenCooperisaGod · 07/06/2022 13:58

For those of you not aware, the feminism section of mn host discussions on gender critical feminism that are not popular with trans rights activists.

I have had a joke theory that the site redevelopment was being done by a transrights activist, as something this shit couldn't have been done by accident.

Suddenly this theory doesn't seem so far fetched. Having e mail addresses revealed to activists would be very damaging for many women who use this site.

It puts them at risk in multiple different ways

Simbaya · 07/06/2022 20:11

MNHQ have done nothing to reassure me or safeguard me as a result of them passing my private details to three malicious people.

CARE TO RESPOND????????????

EmpressaurusWitchDoesntBurn · 07/06/2022 21:08

BenCooperisaGod · 07/06/2022 13:58

For those of you not aware, the feminism section of mn host discussions on gender critical feminism that are not popular with trans rights activists.

I have had a joke theory that the site redevelopment was being done by a transrights activist, as something this shit couldn't have been done by accident.

Suddenly this theory doesn't seem so far fetched. Having e mail addresses revealed to activists would be very damaging for many women who use this site.

Yes. Given the number of psychos on Twitter who would love to be able to dox women on the FWR board this is really worrying.

I nearly reported a couple of posts earlier today, I’m glad now that I didn’t get round to it.

Moosake · 07/06/2022 21:21

EmpressaurusWitchDoesntBurn · 07/06/2022 21:08

Yes. Given the number of psychos on Twitter who would love to be able to dox women on the FWR board this is really worrying.

I nearly reported a couple of posts earlier today, I’m glad now that I didn’t get round to it.

I'm never reporting a post again

Johnnysgirl · 07/06/2022 21:24

Moosake · 07/06/2022 21:21

I'm never reporting a post again

They really do seem to have shot themselves in the foot with this latest fiasco.

IncessantNameChanger · 07/06/2022 21:25

Maybe MN might be wise to consult an experienced architect who could advise on encrypting email address? Maybe that's needed?

If you store the email address just once. Only in one place on your database and use its key only in the other parts of the db ( single point of truth is an absolute basic in IT) there would be zero reason to ever have emails accessible from anywhere in the first place. But say the table is username, password, email in your user table then why the need to call anything back except the username unless your logging on? Why would you even need to know the email except for logon or in user settings? My mind boggles.

Or put some proper access rights on that table in the db? Only the database administrators have access to that table on the DB. You could also set up a new table on the db that shows you who looked at the user emails and when.

But only using the username or its key would be the norm. Who repeatedly parses a email address? No wonder it's a bit slow to load.

No where at all does this site display email except in user settings.

It's very odd

MarieBaroneIsMyMom · 07/06/2022 21:37

I’m shocked at how badly MN is handling this.

Justine’s response on this thread is unreal.

www.mumsnet.com/talk/site_stuff/4564499-my-data-has-been-breached?reply=117744975

Harridan1981 · 07/06/2022 22:03

Surely someone could have gone around reporting anyone they wanted the details of once they realised? How can mn keep tabs?

Diverseopinions · 07/06/2022 22:28

What are TRAs and MRAs?

Thanks

Sortilege · 07/06/2022 22:56

This is why I re-regged under a burner email and fake name and won’t upgrade to premium. How anyone can trust them with real details to access premium defeats me.

Sortilege · 07/06/2022 22:56

Diverseopinions · 07/06/2022 22:28

What are TRAs and MRAs?

Thanks

Trans rights activists and men’s rights activists. Place is swarming with them.

Swipe left for the next trending thread