Hacker News new | past | comments | ask | show | jobs | submit login
Tell HN: Slack revealed email addresses of users to others in same workspace
6 points by altdataseller on July 21, 2022 | hide | past | favorite | 4 comments
I just got this email from Slack:

"Hello,

We are writing to inform you of an issue we recently discovered. A number of members of your workspace were inadvertently included on the same email. This means that you're able to see each other's email addresses in the “To” line. You are receiving this notice because you were sent this email on July 19 or July 20, 2022.

What happened and when? Slack emailed members of your workspace about the upcoming changes to Slack’s free plan with the subject line “New features coming to your Slack workspace.” Instead of sending each workspace member individual emails as intended, the email recipients on your team were visible in the same email message.

Slack identified this problem and immediately took steps to stop additional emails from being sent in this way. We're also reaching out to inform all users who received the email. All of the content of the email is still accurate for your team.

How was I impacted? Since you received one of these emails, this means that other people on your workspace who received the email may have inadvertently seen your email address.

What should I do? We ask that you delete and not share, store, print, or in any way retain the original email with email addresses. If you have additional questions about this, you can reply to this email, or reach out to us at feedback@slack.com.

We know that the security and privacy of your data is important. We are very sorry for the inconvenience and concern this issue may have caused.

Sincerely, The team at Slack"

Guess they'll be dealing with some class action lawsuit soon.




This honestly doesn't seem like a big deal to me. Maybe I'm naive, but email addresses aren't really private these days, it was limited to only fellow members of your workspace, and they were up front about the seemingly honest mistake. I've personally made worse mistakes.


If it was a workspace for your company, no it is not a big deal but there are plenty of Slack communities around topics where some ppl are anonymous.


In 2022 if you enter your email into any service you should basically expect it to be public information at some point. It’s just a matter of time until something happens and it gets leaked.


The big issue with a breach like this isn't the email itself, but the association of the email with the service.

For example, the Ashley Madison breach.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: