4 ms·
Looks like Mixpanel is handling this well: they deleted the data, notified affected customers, and then are making sure it can't happen again. +1 for admitting
by RoboTeddy 9y ago
Looks like Mixpanel is handling this well: they deleted the data, notified affected customers, and then are making sure it can't happen again. +1 for admitting responsibility instead of deflecting or minimizing.
- spenvo 9y agoOk, they took responsibility... But they took about a month to notify clients via email and didn't notify the public until Techcrunch inquired for the purposes of writing this article. So -1 for not being upfront with end users and clients.
- ajeet_dhaliwal 9y agoTake away a few more for not noticing the problem for nine months.
- snissn 9y agoWould be a good move to put together a common password list and regularly check their data against it.
- perfectstorm 9y agoThey were notified on Jan 5th. They destroyed the stored passwords on the 9th and informed the customers on the 1st of February. It seems reasonable. Why would they inform the end user though ? The end user doesn't even know what Mixpanel is and would be confused if they emailed them directly. Informing the clients (BMW, Samsung etc.) is the right thing to do which they did. I'm sure they had to do a postmortem and make sure a fix is in place before informing the clients and urging them to update the SDK.
- anc84 9y ago> Why would they inform the end user though ? The end user doesn't even know what Mixpanel is and would be confused if they emailed them directly. So that the end users can grasp to which extent their privacy was violated? If a third-party I never heard of, contacted me and told me they got my login details, I would be bloody furious. And that is a good thing if people are enabled to this.
- AFNobody 9y agoThey notified their customers, not the people whose passwords they collected. They did minimize how many people they told. Lol.
- givehimagun 9y agoWeird that the title says 'accidentally' when other companies aren't given that kind of credit. Real talk, do we give internet companies (Google/Facebook) more leniency than traditional companies (Equifax/Target) in data leaks/hacks?
- mbesto 9y agoNo, but if you've ever done security before, you would know that it's a matter of "not if I hacked but when". Judging from their response, they seem to have pretty good procedures in place. Conversely, Equifax took months to respond and pulled a "it's not our fault".
- IntronExon 9y agoGoogle and Facebook have proven themselves about as trustworthy as a pair of starving animals, and frankly it took time and a lot of benefit of the doubt before plenty of people arrived at that conclusion. In the words of Nixon they “Earned everything [they] got.”
- matt_wulfeck 9y agoAm I missing something? Among the companies I would trust not to leak or expose my password (or incidentally collect it plaintext) google would be high on that list.
- bigiain 9y agoIt wouldn't surprise me greatly to notice Google serving me targeted advertising linked to key words in my password... "What're all these batteries and horses and staples doing coming up in my advertising???"