3 ms·
I didn't see it, but "who is the third party vendor?" is my key question, since this could be impacting anyone working with that vendor.
by traskjd 7y ago
I didn't see it, but "who is the third party vendor?" is my key question, since this could be impacting anyone working with that vendor.
- antoncohen 7y agoThe vendor might not have been compromised. > we will review our policies for enforcing 2FA on third-party accounts to the extent possible, and continue our transition to single sign-on (SSO) for all of our integrations I think it is more likely the CircleCI didn't enforce 2FA or SSO[1] with the vendor, and a CircleCI employee reused an already compromised password. [1] Nearly all SSO identity providers support 2FA, so using SSO is often the easiest way to get 2FA with third-party SaaS providers.
- traskjd 7y agoValid point, thanks :)
- gingerlime 7y agoNaming the vendor in this case should be fine. Shouldn’t it? In general what I’m missing is why they share my email and github account with a 3rd party. GDPR should prevent them from doing so (at least for European users) without a legitimate reason, or explicit consent.
- erikpukinskis 7y agoIs "they make graphs for us of what our users do" a legitimate reason? Or, "they store our error logs in a way we can easily find stuff"?
- gingerlime 7y agoI'm not sure "make graphs for us" is a legitimate reason to share personal information (and email is considered personal information under GDPR). Error logs might be a bit different I suppose, if they are used to help resolve specific issues for your users, but even then I suppose one could argue that pseudo-anonymised data would be better than sharing an email address. I'm no GDPR expert, but that's my understanding of it.
- PeterisP 7y agoThat's not exactly how GDPR works - the criteria depends on what you mean by "share with a 3rd party". If you as the data controller are allowed (according to GDPR) to do some particular processing of some particular data, then GDPR also allows you to subcontract that processing, and thus provide the data to third parties (data processors). There are a bunch of restrictions in place (you have to have a specific contract mandating that they only do the thing with the data you're contracting them to do, you're responsible if they violate that, some restrictions on "exporting" data out of EU), and you have to inform the customer to what third party 'data processors' you (as the data controller) are outsourcing these activities - so CircleCI would be required to give an exhaustive list of all the data processors to which they have given your data, but you don't need explicit consent or a very particular reason for that outsourcing. What is prevented by GDPR is the common (at least in USA) "sharing data with trusted third party partners" where the data is essentially sold to third parties which are free to use that data as they wish for their own business or re-sell it further. That would require a very particular reason or explicit consent, but this is not the common scenario of outsourcing to a GDPR-compliant vendor.
- gingerlime 7y agoMy (admittedly limited) understanding of it is that there still needs to be a legitimate reason to provide my email. So if the email is required in order to, say, send me notifications about CircleCI jobs that are running. That's a legitimate reason. If they share my email with the 3rd party to, for example, optimize their onboarding flows, then this isn't legitimate, unless I explicitly gave my consent to it. To me, "analytics vendor" as they stated it, usually implies something similar to the latter rather than the former. But since they didn't indicate the provider, nor the reason, I can't really say. I think we're not in any disagreement here by the way.