Jump to content

Ghostery AdBlock exposes hundreds of emails in an attempted GDPR notice

ItsMitch

S: https://www.ghostery.com/blog/ghostery-news/ghostery-email-incident-update/

On the same day GDPR was officially enforced, Ghosty, an ad blocking addon for Chrome made a huge blunder by exposing hundreds of emails of it's clients in an apparent notice for GDPR. Awk for them

Quote

Dear Ghostery Users,

We are very sorry! Ghostery sent out an email yesterday that resulted in the exposure of account holders’ email addresses to other Ghostery account holders and Ghostery users. We would like to provide some clarification and transparency regarding our GDPR email that unintentionally revealed the email addresses of some of our user accounts.

Summary

Ghostery sent out an email on May 25, 2018 that unintentionally resulted in the exposure of some account holders’ email addresses.

Only email addresses were exposed.

You are not affected if you use Ghostery but did not provide an email address to us.

You are not affected if you did not receive the GDPR email from Ghostery.

As soon as we found out, we stopped using the email distribution tool.

Ghostery is currently working to rectify the incident and we will keep our users updated.

This is a fairly huge blunder, especially because it's the GDPR email, you know, the one to better your privacy. Ghosty has since informed the EU about the incident and will stop using the email service. 

Quote

What will Ghostery do now?

We take our privacy and security practices very seriously; after all, they are both part of the value statement for our own products. This incident was a clear mistake, and we deeply apologize to our users and anyone else affected.

We will be reporting the incident as mandated by the GDPR.

We have already terminated the email distribution and already determined what went wrong. It was a simple human mistake.

Furthermore, while this was an error with update emails that all account holders will continue to receive (e.g., when we’re legally required), we are providing clear instructions on how to opt out of future Ghostery product and marketing emails or delete an account for those who wish to do so, as well as permanently expunge any user data upon request. If you prefer to not receive these updates you may delete your account.

 

Link to comment
Share on other sites

Link to post
Share on other sites

Classes to skip in college:

Business Management I

How to Computer I

Short Story I

 

Ghostery decided to skip the first two and ace the third in their exciting new poem Tackle, Bait, and Phishing

 

I was hooked once @yahoo.com was revealed. 

Cor Caeruleus Reborn v6

Spoiler

CPU: Intel - Core i7-8700K

CPU Cooler: be quiet! - PURE ROCK 
Thermal Compound: Arctic Silver - 5 High-Density Polysynthetic Silver 3.5g Thermal Paste 
Motherboard: ASRock Z370 Extreme4
Memory: G.Skill TridentZ RGB 2x8GB 3200/14
Storage: Samsung - 850 EVO-Series 500GB 2.5" Solid State Drive 
Storage: Samsung - 960 EVO 500GB M.2-2280 Solid State Drive
Storage: Western Digital - Blue 2TB 3.5" 5400RPM Internal Hard Drive
Storage: Western Digital - BLACK SERIES 3TB 3.5" 7200RPM Internal Hard Drive
Video Card: EVGA - 970 SSC ACX (1080 is in RMA)
Case: Fractal Design - Define R5 w/Window (Black) ATX Mid Tower Case
Power Supply: EVGA - SuperNOVA P2 750W with CableMod blue/black Pro Series
Optical Drive: LG - WH16NS40 Blu-Ray/DVD/CD Writer 
Operating System: Microsoft - Windows 10 Pro OEM 64-bit and Linux Mint Serena
Keyboard: Logitech - G910 Orion Spectrum RGB Wired Gaming Keyboard
Mouse: Logitech - G502 Wired Optical Mouse
Headphones: Logitech - G430 7.1 Channel  Headset
Speakers: Logitech - Z506 155W 5.1ch Speakers

 

Link to comment
Share on other sites

Link to post
Share on other sites

12 minutes ago, SC2Mitch said:

-snip-

This email in a nutshell:

 

CPU: Intel Core i7-5820K | Motherboard: AsRock X99 Extreme4 | Graphics Card: Gigabyte GTX 1080 G1 Gaming | RAM: 16GB G.Skill Ripjaws4 2133MHz | Storage: 1 x Samsung 860 EVO 1TB | 1 x WD Green 2TB | 1 x WD Blue 500GB | PSU: Corsair RM750x | Case: Phanteks Enthoo Pro (White) | Cooling: Arctic Freezer i32

 

Mice: Logitech G Pro X Superlight (main), Logitech G Pro Wireless, Razer Viper Ultimate, Zowie S1 Divina Blue, Zowie FK1-B Divina Blue, Logitech G Pro (3366 sensor), Glorious Model O, Razer Viper Mini, Logitech G305, Logitech G502, Logitech G402

Link to comment
Share on other sites

Link to post
Share on other sites

Damn, and I use ghostery... on Chrome.

Mobo: Z97 MSI Gaming 7 / CPU: i5-4690k@4.5GHz 1.23v / GPU: EVGA GTX 1070 / RAM: 8GB DDR3 1600MHz@CL9 1.5v / PSU: Corsair CX500M / Case: NZXT 410 / Monitor: 1080p IPS Acer R240HY bidx

Link to comment
Share on other sites

Link to post
Share on other sites

Meanwhile, ABP on FireFox

The Workhorse (AMD-powered custom desktop)

CPU: AMD Ryzen 7 3700X | GPU: MSI X Trio GeForce RTX 2070S | RAM: XPG Spectrix D60G 32GB DDR4-3200 | Storage: 512GB XPG SX8200P + 2TB 7200RPM Seagate Barracuda Compute | OS: Microsoft Windows 10 Pro

 

The Portable Workstation (Apple MacBook Pro 16" 2021)

SoC: Apple M1 Max (8+2 core CPU w/ 32-core GPU) | RAM: 32GB unified LPDDR5 | Storage: 1TB PCIe Gen4 SSD | OS: macOS Monterey

 

The Communicator (Apple iPhone 13 Pro)

SoC: Apple A15 Bionic | RAM: 6GB LPDDR4X | Storage: 128GB internal w/ NVMe controller | Display: 6.1" 2532x1170 "Super Retina XDR" OLED with VRR at up to 120Hz | OS: iOS 15.1

Link to comment
Share on other sites

Link to post
Share on other sites

1 minute ago, D13H4RD2L1V3 said:

Meanwhile, ABP on FireFox

Wasn't abp the one that sold a shit load of user data and showed people ads

Link to comment
Share on other sites

Link to post
Share on other sites

6 minutes ago, SC2Mitch said:

Wasn't abp the one that sold a shit load of user data and showed people ads

At one point, yeah.

 

That sorta was the point. I currently just use AdBlock

The Workhorse (AMD-powered custom desktop)

CPU: AMD Ryzen 7 3700X | GPU: MSI X Trio GeForce RTX 2070S | RAM: XPG Spectrix D60G 32GB DDR4-3200 | Storage: 512GB XPG SX8200P + 2TB 7200RPM Seagate Barracuda Compute | OS: Microsoft Windows 10 Pro

 

The Portable Workstation (Apple MacBook Pro 16" 2021)

SoC: Apple M1 Max (8+2 core CPU w/ 32-core GPU) | RAM: 32GB unified LPDDR5 | Storage: 1TB PCIe Gen4 SSD | OS: macOS Monterey

 

The Communicator (Apple iPhone 13 Pro)

SoC: Apple A15 Bionic | RAM: 6GB LPDDR4X | Storage: 128GB internal w/ NVMe controller | Display: 6.1" 2532x1170 "Super Retina XDR" OLED with VRR at up to 120Hz | OS: iOS 15.1

Link to comment
Share on other sites

Link to post
Share on other sites

8 minutes ago, PineyCreek said:

Happens everyday...people using To or CC instead of BCC...

For this not even BCC should be used. Should be all individually processed direct emails with logging of when it was processed, created, sent and status so you can prove they were sent down to the person.

Link to comment
Share on other sites

Link to post
Share on other sites

5 minutes ago, huilun02 said:

Yes I agree Chrome is not good on privacy, but so is every mainstream browser.

Chrome is the worst of them though. I use Firefox personally.

 

I don't get why anyone would have given their email address to an adblock company though.

Make sure to quote or tag me (@JoostinOnline) or I won't see your response!

PSU Tier List  |  The Real Reason Delidding Improves Temperatures"2K" does not mean 2560×1440 

Link to comment
Share on other sites

Link to post
Share on other sites

In meanwhile I use Noscript and uBlock Origin on FireFox Quantum.

Chrome is such a cancerbrowser, can't believe that shit. It may be fast but oh boy, it can eat RAM like nothing.

DAC/AMPs:

Klipsch Heritage Headphone Amplifier

Headphones: Klipsch Heritage HP-3 Walnut, Meze 109 Pro, Beyerdynamic Amiron Home, Amiron Wireless Copper, Tygr 300R, DT880 600ohm Manufaktur, T90, Fidelio X2HR

CPU: Intel 4770, GPU: Asus RTX3080 TUF Gaming OC, Mobo: MSI Z87-G45, RAM: DDR3 16GB G.Skill, PC Case: Fractal Design R4 Black non-iglass, Monitor: BenQ GW2280

Link to comment
Share on other sites

Link to post
Share on other sites



What exactly happened?

Recently, we decided to stop using a third-party email automation platform. In an effort to be more secure, we wanted to manage user account emails in our own system, so we could fully monitor and control data practices surrounding them. 

 

wtf-meme.jpg

.

Link to comment
Share on other sites

Link to post
Share on other sites

You gotta admit, the irony and comedy is strong with this one, exposing client email addresses in an email containing updated privacy policies is pretty fucking dumb.

Main Rig:-

Ryzen 7 3800X | Asus ROG Strix X570-F Gaming | 16GB Team Group Dark Pro 3600Mhz | Corsair MP600 1TB PCIe Gen 4 | Sapphire 5700 XT Pulse | Corsair H115i Platinum | WD Black 1TB | WD Green 4TB | EVGA SuperNOVA G3 650W | Asus TUF GT501 | Samsung C27HG70 1440p 144hz HDR FreeSync 2 | Ubuntu 20.04.2 LTS |

 

Server:-

Intel NUC running Server 2019 + Synology DSM218+ with 2 x 4TB Toshiba NAS Ready HDDs (RAID0)

Link to comment
Share on other sites

Link to post
Share on other sites

11 minutes ago, Master Disaster said:

You gotta admit, the irony and comedy is strong with this one, exposing client email addresses in an email containing updated privacy policies is pretty fucking dumb.

still you got to give them credit, they did it so they could control the data themselves and not by a 3rd party app like they did before :D

 

we trust a lot of stupid and untrustworthy people with our data, it's my take on all this.

.

Link to comment
Share on other sites

Link to post
Share on other sites

5 minutes ago, asus killer said:

still you got to give them credit, they did it so they could control the data themselves and not by a 3rd party app like they did before :D

 

we trust a lot of stupid and untrustworthy people with our data, it's my take on all this.

Sounds like we should have trusted that 3rd party instead lol

Link to comment
Share on other sites

Link to post
Share on other sites

I was actually considering trying out Ghostery with Opera browser. If they're this incredibly incompetent, screw 'em! :P I'll just stick to ad blocking and such. 

Link to comment
Share on other sites

Link to post
Share on other sites

6 minutes ago, Crosseyed Sniper said:

I was actually considering trying out Ghostery with Opera browser. If they're this incredibly incompetent, screw 'em! :P I'll just stick to ad blocking and such. 

if you have opera you don't need it anyway.

.

Link to comment
Share on other sites

Link to post
Share on other sites

2 minutes ago, asus killer said:

if you have opera you don't need it anyway.

Yeah, Opera has native ad blocking and built-in VPN. I've never tried out the VPN, though. 

Link to comment
Share on other sites

Link to post
Share on other sites

15 minutes ago, Crosseyed Sniper said:

Yeah, Opera has native ad blocking and built-in VPN. I've never tried out the VPN, though. 

me neither, but the ad block part is the best out there in my opinion, not just because it works but because there are no bugs or issues ever.

 

.

Link to comment
Share on other sites

Link to post
Share on other sites

Using Opera so yey. 

| Ryzen 7 7800X3D | AM5 B650 Aorus Elite AX | G.Skill Trident Z5 Neo RGB DDR5 32GB 6000MHz C30 | Sapphire PULSE Radeon RX 7900 XTX | Samsung 990 PRO 1TB with heatsink | Arctic Liquid Freezer II 360 | Seasonic Focus GX-850 | Lian Li Lanccool III | Mousepad: Skypad 3.0 XL / Zowie GTF-X | Mouse: Zowie S1-C | Keyboard: Ducky One 3 TKL (Cherry MX-Speed-Silver)Beyerdynamic MMX 300 (2nd Gen) | Acer XV272U | OS: Windows 11 |

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×