back to article El Reg in email address blunder

Between 8:58 and 10:20 BST this morning we sent an email to 3,521 of you that contained the names and email addresses of 46,524 of our readers. Obviously, this was an error. The two-stage send process that is the norm for all of our mailers was over-looked because someone was in a hurry. We would like to offer our genuine and …

COMMENTS

This topic is closed for new posts.

Page:

  1. Anonymous Coward
    Anonymous Coward

    ICO

    After all the derogatory stories about the ineffectuality of the ICO and the even worse comments this could be payback time for them. Let us know if the put their teeth in for this one.

  2. Remy Redert
    Joke

    Fired!

    Is what the culprit needs to be. No, not that way. Out a cannon!

  3. John Sager

    Just shows how hard it is to be good

    So, a relatively small organisation, with trained people and its heart in the right place can still screw up under pressure. Not perhaps too surprising. So even less surprising when big, essentially incompetent organisations do the same thing, even when they are not under pressure.

    Hope the Information Commissioner doesn't have to ceremonially thrash you all with a cat 'o nine tails smeared with ghost pepper sauce!

  4. John Brookes
    FAIL

    How incredibly embarrassing!

    ... I've been outed as a reg reader!

    Bad Reg, naughty Reg - wash your mail server out with soap and water, then stand in the corner of the datacentre and think about what you've done..... FACING THE WALL!

  5. Edwin
    FAIL

    Thanks?

    It is indeed an impressive list (and yes Neil, I found you on it)

    I agree a notification to the 46k plus recipients would be in order. I can send you a copy if you'd like.

    Sorry El Reg, but there is NO excuse!

    1. Neil Brown

      "yes Neil, I found you on it"

      *gulp*

      1. Neil Greatorex

        "yes Neil, I found you on it"

        Double gulp!

  6. codejunky Silver badge
    FAIL

    Accidents happen

    Noting how well our email addresses are used anyway on any site which bundles us up for marketting it isnt really much to worry about. Nearly any site wanting an account asks for our email and thats exactly what this site is too.

    Obviously there must be an effort not to repeat this but I hope you dont give too hard a time to whoever did this (although I am sure they are getting plenty stick).

    And at least you have the backbone to own up to it pretty quick.

    For people who are worried on here I will remind you that nearly every stranger you talk to will ask your name and I am sure you give it. And for every account you sign up to online you have given away your email address. While we prefer to be masters of our own information we unfortunately are not.

  7. Anonymous Coward
    Anonymous Coward

    So I can expect some emails from an El Reg "employee/lawyer" asking me to help him to get the money out of the company for a cut. All he asks for is my banking details, online banking password and I will be an instant millionaire. :-)

  8. Anonymous Coward
    Anonymous Coward

    Pot, meet kettle

    Fortunately I am registered with a keyboard-mash name and a 10 Minute Mail e-mail address.

  9. vilemeister
    Angel

    Well...

    At least the reg admitted to it giving exact numbers. More than other companies (ahem*Sony*ahem) would do.

  10. Dave W

    This is becoming an increasingly common occurrence across the globe, and you can bet for every time you hear about such a mistake, there are a few dozen data security breaches which are covered up.

    46,500 people affected pales into insignificance alongside the size of breaches by the NHS and local council authorities for example which often run into the millions of records.

    <exaggeration warning>Chances are, if you've been alive for more than a week then some of your data's probably been leaked somewhere. More than once.</exaggeration warning>

    So, fresh perspective, your name isn't sensitive information. Chances are your email address isn't all that sensitive either (are they both on your business card? You've never lost one of these incredibly sensitive wallet-sized documents, or handed one to someone you don't know right?)

    If it was financial or medical details I'd be livid, but with a sense of perspective it's not all that bad.

    At least the senders of junk mail might start spelling my name right now. And if they know I've got an interest in IT it might even be well-targeted spam. Exciting.

    1. Svantevid
      Thumb Up

      "At least the senders of junk mail might start spelling my name right now. "

      ---

      That's the spirit! ;-)

      But I must complain... I got no mail from El Reg (*sniff*) and no extra spam either... I feel neglected.

  11. Heironymous Coward
    WTF?

    Mistake

    I didn't get it - could you please resend.

    Thanks

    1. Anonymous Coward
      Anonymous Coward

      Come on everybody...

      Reply all!

  12. Steven Raith
    Paris Hilton

    so..

    Come on, 'fess up - who from the staff is on tea making duties for a month, then?

    Glad I used my old bt account to sign up, all those years ago, though!

    Steven R

  13. Red Bren

    Well done and watch out

    Well done for holding your hands up. Watch out the ICO don't decide to make an example of you.

    Will you be notifying the affected?

    1. Anonymous IV
      Unhappy

      Shows what happens when key staff leave....

      This email fiasco would never have been allowed to happen if Sarah Bee had still been working for you.

      1. Alan W. Rateliff, II
        Paris Hilton

        If only Sarah...

        Or, she might give said culpable individual a sound thrashing. Now THAT is most certainly PlayMobil-worthy.

        Paris... why not?

  14. Michael Jarve
    FAIL

    Well done!

    And added to my woes, the spacebar on my keyboard has started to act funny... Coincidence? I surely think not!

    But, as someone will undoubtedly point out, passing along the email addresses of 42k+ furry toothed, not entirely naive or defenseless geeks is not half as bad as say, your NHS leaving about the generous gift of names, numbers, addresses, whatever equivalent of SSN's you have over there, &t, for any old body to pick up, ???, and profit from. To that, I preemptively say: Bull cookies!

    Still, you apparently saw fit to at least acknowledge the, heh, mistake quite promptly, thereby if not minimizing the potential damage and outcry, at least foisting responsibility for what follows on to the owners of these misplaced readers. Trebles all around!

    In other words, welcome to humanity: the race was lost before it ever started.

  15. David Precious
    Facepalm

    Shit happens

    Accidents happen - kudos for immediately owning up to it and holding your hands up, rather than trying to downplay it or pretend it didn't happen.

    If the data leaked is just email addresses, I don't see it as too big a deal particularly.

  16. Anonymous Coward
    Anonymous Coward

    I never make these lists

    Thankfully

  17. Dabooka
    Flame

    This is seriously unfunny.....

    It's one thing being outed as a member of the BNP or finding out I sign up for Strictly Come Dancing updates, but if people were to discover I'm a reader of El Reg?

    The shame. I'd never live it down....

  18. Anonymous Coward
    Anonymous Coward

    Can I have ..

    .. the rest of the data? You're not government compliant if you don't lose other information with it such as bank details address, inside leg measurements and any biometrics gathered along the way..

    Ah - there are over 43k users waiting to rub it in.

  19. Stephen McLeod Blythe
    FAIL

    http://www.theregister.co.uk/2011/10/21/ico_public_secotr_data_breaches/

    Hilarious irony.

    No point posting anon since everyone here has my email/name now anyway! (or do they?)

  20. newbie1664
    Unhappy

    Not fair!

    I only got 46,493 sent to me.

    I want the other 31

  21. Jon Press

    The two-stage send process that is the norm ... was over-looked

    Was "overlooked" or was "actively bypassed"?

    In the former case you need some technical control over sending data to thousands of recipients not just a note pinned to the wall. In the latter case you need a member of staff pinned to the wall.

    Still, congratulations to Team Register for managing to foreswear Liam Fox's enthusiasm for the passive voice - at least until the third sentence.

  22. Stuart 22
    Pint

    I'll drink to that!

    This is really terrible. I shall be writing to the IPO immediately making clear the only acceptable way El Reg can compensate for this catastrophic error is to stand a pint for each transgression at its local hostelry.

    All attendees will, of course, have the right to a proxy drink for the few unable to find the pub, or London, or ...

  23. Tim Bates
    Happy

    I got my copy...

    Now I just need to start a competing website and spam everyone about it....

    Was it a complete list of subscribers? I searched for a few old friends who I know used to be subscribers and didn't find them - but they may have long since unsubscribed.

  24. I ain't Spartacus Gold badge
    Terminator

    Your pennace - should you choose to accept it.

    Is to compose a tune, possibly along the lines of Sirius Cybernetics' delightful 'Share and Enjoy'. Then get a choir of a million robots to sing the email addresses and names of all your users, to this new melody.

    Share and Enjoy!

    1. Ugotta B. Kiddingme
      Thumb Up

      Curiously, an edition of the Encyclopedia Galactica...

      ...which conveniently fell through a rift in the time-space continuum from 1000 years in the future describes the Marketing Department of The Register as:

      "A bunch of mindless jerks who were the first against the wall when the revolution came."

  25. Anonymous Coward
    Anonymous Coward

    Well mistakes happen. I know my details are for my fake 'alto-ego'.

    Credit to you for coughing and reporting it ASAP, it's a pitty government and private businesses aren't as forthcoming as you guys when they stuff up.

    Still, based on the PSN story, when do we get or freebies as a sorry?

  26. Vladimir Plouzhnikov

    What?

    So my email's on the internets now? Oh, noes!

  27. dcd
    Go

    Bring it on!

    I don't care if my email address is in your list. Running a small piss-ant email service for the past ten years with lots and lots of mods of my own.

    It's hard. Fucking rock hard - so bring it on.

    On a slightly serious note: peeps should do a deep search for their email address on a number of engines - you may be surprised to find it!

  28. Rajiv Dhir
    FAIL

    I think you mean 46K ex readers!

    subject says it all

  29. Anonymous Coward
    Anonymous Coward

    Eh?

    You mean my willy wont get any bigger?

  30. Matthew Wombell
    FAIL

    Ooops

    Thanks for the free e-mail addresses earlier. As we're signed up for the DPA too then I'm one person that isn't going to be spamming or selling those e-mail addresses.

    No point in posting anonymously... I'm no longer anonymous anyway!

    But good on you for putting your hands up and telling everyone that it had happened. I'm sure those of us who have this list will be responsible IT professionals... but we know what the chances of that are.

    Let us know what the ICO has to say back...

  31. Anonymous Coward
    Anonymous Coward

    Hey

    where's my email?

  32. Anonymous Coward
    Thumb Up

    You're forgiven

    Not because it was an easy mistake (there's no excuse, really) but because you owned up immediately and accepted the embarrassment.

    As some others have suggested, it would be useful if El Reg were to post a follow-up article explaining exactly how it occurred and what is being done to make sure it doesn't happen again - as a useful Case Study.

  33. peter 45
    Coat

    What list?

    Sorry but the list does not appear to have been sent to me.

    If I send you a Memory stick, can you lose that as well please?. Don't send it to me in the post, just drop it outside your offices on the way home tonight and I will pick it up.

    Ta

    P.S. If the list is encrypted, can you attach the password as well. Cheers.

    P.P.S. Any Local Government Authorities been in touch with a job offer yet?

  34. vagabondo
    FAIL

    Why no outbound mail filter?

    This seems like dereliction of duty.

    Our Postfix servers have a header_checks rule:

    # catch multiple recipients

    /^(to|cc):.*\@.*\@.*\@/ REJECT Multiple "To:" addresses promote spam and identity theft. Try "Bcc:" or use a mailing list.

    I am sure that something similar is available for El Reg's Exim server.

    1. An0n C0w4rd
      Unhappy

      @vagabondo you can do that in Exim also, but like everything else you have to WANT to do it first.

      You can also add a dummy user to the address list and any time their name and address appear in the body reject the e-mail, or if it appears in the header with any other address reject the mail.

      P.S. I thought El Rego could time travel when I saw "Posted in Site News, 24th October 2011 10:07 GMT" and "Between 8:58 and 10:20 this morning" until I realised we were still on BST.

      P.P.S. anyone who implements the suggestion in the 2nd paragraph please contact me to pay me my usual consulting rates :-)

    2. Anonymous Coward
      Anonymous Coward

      Wouldn't have helped in this case - the delivery was made via MLM (or bcc'd) the addresses were in the body of the email.

    3. Chris Miller

      It wasn't a cc/bcc error, the list of names and addresses was the (only) message content. No doubt something similar could be set up to block that as well (if a message contains more than 20 '@' signs for example).

      1. vagabondo

        @Pete B, @Chris Miller

        Thanks for explaining what happened. It would be interesting to learn how it happened.

  35. Adam Foxton

    I assume

    that 'Lessons will be learned'. That the person in question wasn't named implies that they won't be 'reconsidering their position' too soon- probably okay for a simple list of email addresses and names.

    Thanks to El Reg for being honest and informing us about the existence of- and the scale of- the problem.

    I hope the affected will be notified?

  36. Stuart Elliott

    I didn't get an email

    Damn it, I demand a refund, I didn't get one.

  37. Anonymous Coward
    Anonymous Coward

    Least it doesn't leak....

    Or link all the details of your friends, possible connections, browsing habits, address book, pictures you may be interested in our suggest that you may like something or someone. Seems pretty tame compared to face book and linked in.

    Was steve ballmer, bill gates, zuckerberg, assange and steve jobs on the list?

  38. Dodgy Pilot
    Trollface

    Oh quit worrying and whining... it's not like El Reg could possibly have spelt them correctly anyway.

  39. ratfox
    Pint

    Quick, lemme check my never-used-crap-web-based-mail...

    Shoot. I am not one of the 3,521... Will you notify the 46,524, so that I know I should change to a further crap account, just for safety?

    I think my new address will be: "registerlogin1234@hotmail.com"

Page:

This topic is closed for new posts.