Help end medical misogyny. Sign our petition.

Help end medical misogyny.
Sign our petition.

Sign the petition

Please or to access all these features

Site stuff

Join our Innovation Panel to try new features early and help make Mumsnet better.

See all MNHQ comments on this thread

My data has been breached

261 replies

Simbaya · 07/06/2022 16:05

Respond please.

OP posts:
C8H10N4O2 · 11/06/2022 08:46

Bosky · 11/06/2022 02:54

C8H10N4O2 - Apologies if I have become confused by the issues mentioned in this thread.

Has Mumsnet said that "reporter" email addresses have been exposed to the person reported, ie. as well as the "reporter" being sent the email address of the person they have reported in "about 20 cases"?

Sorry I should have made that clearer.

Contact systems are normally configured so that neither the customer manager nor the customer has direct sight of email addresses or any direct contact info.

So if unneeded contact information appears in the body of a mail this is nearly always badly configured software or someone not following data privacy policies. I'm assuming this is what happened in the case of the exposed OP and moderator addresses, that has been accepted as wrong. However I also saw my address as a reporter flagged up in the mail which was a different format to old responses. That exposes my address as a reporter to both the mod responding and anyone looking at the reporting system. That shouldn't happen either.

Its shockingly bad software management that someone could bypass process in two places to create a breach. Its also shockingly bad data and privacy management, especially after the previous breaches which have included malicious actors from inside the business.

MyrtlethePurpleTurtle · 11/06/2022 13:39

Simbaya · 07/06/2022 20:07

No other company has ever breached my data.

(that you know of)

MyrtlethePurpleTurtle · 11/06/2022 13:42

Simbaya · 07/06/2022 20:13

Under GDPR, MN are required to protect my private data. They haven't. Three people with a grudge now have my details.

Why would they have a grudge?

VimFuego101 · 13/06/2022 23:58

AuntieStella · 11/06/2022 07:48

MN absolutely assured everyone, some time after Jeffery-gate, that old email addresses had been permanently deleted if users updated to a new address, as they put forward no business reason for retaining then.

I changed addresses then, and will be absolutely furious if

a) retained anywhere my old email address, and therefore

b) have reneged on their assurances that they were deleting all old eaddresses.

And b is the reason for the furious response. If that had happened it would clearly indicate untrustworthiness, and a bad attitude to their community (tell 'em one thing, do another - they're not worth straight dealing)

I still get emails from MN to the old email address that they supposedly deleted (after Jeffreygate I asked them to delete my account and posts and created a new acc with a burner email).

kittensinthekitchen · 14/06/2022 01:59

Has anyone had a satisfactory response yet from @MNHQ on any of the questions or points from this?

I'm beginning to feel (just slightly) concerned that Boris has had @JustineMumsnet taken out of action after her scathing interview.

daisychain01 · 16/06/2022 04:46

MNHQ are constantly telling MNers to report, report, report never troll hunt, don't discuss misgivings on the actual thread, etc. Well this is a sure-fire way of putting people off wanting to use the Report function if ever I saw one. It's always with the benefit of hindsight that these "glitches" (aka human cock-ups) come to light, when it's too late. The mess may get cleared up but the reputational harm remains. Trust is very very hard to earn, and very easy to lose. People are still talking about the Jeffrey-gate hack years after the event and now Report-gate.

I've been saying from the start (pre-go live) that the lack of controlled end-user testing is a shocking and highly risky strategy when you're talking about a public (and highly visible) platform like this. Asking MNers to "test some stuff" when they are not paid to do that and not qualified (good testing is a very skilled profession), is poor practice. Testing isn't only about "does it work", it's also about picking up risk areas that the untrained eye may not even realise is a problem. If I was the head of MN no way would I give such an important part of a new platform launch to unpaid, untrained, unqualified (no offence meant but it is a fact) "testers" who don't have skin in the game in MNHQ and won't be called to account if the law is broken in plain sight.

It's through controlled testing that you get to know of, document and mitigate potential security holes (in this case, that can be caused by procedural human error). If this platform software is a US product, they don't know the meaning of GDPR now DPA2018, Europe and U.K. are leaders in ensuring people's privacy is maintained by law, so it can be missed during the development cycle of this platform in a country that doesn't value data privacy, and that gap has to be plugged by human intervention (ie procedure/documented work practices, which HQ now admits was missed. I always have the perception they're "winging it" and perception can be 9/10th of reality!

daisychain01 · 16/06/2022 04:49

Not suggesting the poster was a troll btw, but troll hunting is just one example (along with reports about breaches to MN guidelines etc, which seems to be the case here), of what the Report feature is used for.

JaneJeffer · 16/06/2022 11:05

If you report something the email you get in response shows your email address. I thought this was being fixed?

Saucery · 16/06/2022 17:40

JaneJeffer · 16/06/2022 11:05

If you report something the email you get in response shows your email address. I thought this was being fixed?

I don’t think they were fixing that, although it would seem it’s neither necessary nor good practice to include the Reporter email in the reply to the Reporter, so maybe they should remove that inclusion.

YetAnotherBeckyMumsnet · 17/06/2022 10:32

@VimFuego101 you shouldn't be receiving mail from us if you've de-regged or changed your email address. We're keen to look into this - please get in touch at [email protected] with details of the emails you're receiving. We'll look into it right away.

We're going through the other recent questions on the thread and will respond shortly.

DragonwithoutaDungeon · 28/06/2022 18:20

YetAnotherBeckyMumsnet · 17/06/2022 10:32

@VimFuego101 you shouldn't be receiving mail from us if you've de-regged or changed your email address. We're keen to look into this - please get in touch at [email protected] with details of the emails you're receiving. We'll look into it right away.

We're going through the other recent questions on the thread and will respond shortly.

Funny, there's been no response from MNHQ yet?

This is serious, pretty concerning but no updates for 10 days? Hmm

New posts on this thread. Refresh page
Swipe left for the next trending thread