21 ms·
Trello handed over my personal account to my previous company
- hashkb 6y agoThis sucks but isn't Atlassians fault. The lesson is of course to never connect an account you don't own to anything you can't afford to lose.
- jaimex2 6y agoCurious how this isn't Atlassians fault. Can you elaborate?
- hashkb 6y agoUser should have removed work account from valuable personal account immediately after leaving job.
- deleted 6y ago[deleted]
- CRConrad 6y agoSure. But he forgot. That's not a reason to give the company, with which he is no longer affiliated and to whose boards he hasn't had access for years, ownership of his personal account and all its boards.
- dvhh 6y agoGoing on a stretch here, but assuming that the user also use the company email for SSO, means that company (paying client) trade secret were potentially in some of the trello board the user was using. Considering that it would be an invasion of privacy and confidentiality for Atlassian to access the content of the board to assess which one is corporate and which one is personal, Atlassian to the safer approach to satisfy a paying client. Consider that as a free user, with no advertising to monetize you, one could guess that Trello used you for advetising (Unless you are a paying user for your personal account, that could change the story). Of course I am not big fan of the approach, because the user probably linked personnal and work account for convenience, and that trello probably didn't make it easy to make the switch between work and personal. On the other hand, how do you prove that an email address is a personal one ?
- shashanktomar 6y agoI am the user in this case. When I linked the accounts almost 6-7 years ago, Trello was not part of Atlassian and there was no SSO in place. At some point, they introduced it, but still, the regular way of login was working. There was no notification from there side that it will stop working abruptly. The company email address in this case what @comany.com and the personal one was @gmail.com. This is how they handed over all the accounts ending with @company.com to my previous company.
- dvhh 6y agoI understood you were the user, and that what Atlassian was way too cold and lazy on their part. but again, to play devil's advocate, Gmail do offer professional account part of the G Suite. Without knowing your work history, it would be difficult to know if the Gmail address is also not a "professional one". On another hand do you think notification would have solved the issue ? And wouldn't a more malicious employee just delete all the boards if they did not part with their previous company on good term. Obviously I don't know everything from the story. And my assertions are very far from the truth. I am trying to understand what would motivate such a decision (beside the obvious Atlassian is a heartless money-grabbing company that rot everything it touches)
- shashanktomar 6y agoThe ownership of the board is by account. In this case, all the company accounts were anyways invisible to me as my login email was personal gmail account and I only had the permissions to delete board owned under my account.
- pdonis 6y ago> When I linked the accounts almost 6-7 years ago When you did this, was the Trello account used for just your work with that employer? Or for both work and your personal stuff? Or just your personal stuff? [Edit: I see from your response elsewhere in this discussion that it's the second of the options above. I'll respond further in that subthread.]
- shashanktomar 6y agoI understand Atlassian's part here. But Atlassian did this on purpose. They clearly understand the implication and the ownership of accounts, but they deliberately ignored individual users over big corporate accounts. And in my case, they didn't even have the courtesy to notify me in any way. I just stopped working one day leaving all my data unbale to use.
- nerdbaggy 6y agoWhy would they allow an account with multiple email addresses to login with the non SSO one? In your case you aren’t malicious but there could be used maliciously - add your person email - get fired and login with that email and now have all the data
- jakelazaroff 6y agoWhy not just prevent the user from accessing boards owned by the company?
- toomuchtodo 6y agoI would argue that the "right" course of action is to immediately require human intervention when an SSO email is added to an account (or an existing account with an email address, such as a startup "going big league", becomes SSO managed), so that account ownership issues are resolved at that point in time by the parties with ownership interest, not Atlassian having to do so.
- shashanktomar 6y agoThe ownership of data is attached to the email. As soon as i left my workplace, none of the data created under my company account was visible to me. On top of that, they launched SSO support lately. It was not SSO when I connected my accounts years back.
- itronitron 6y agoWhy would they allow an account to have more than one email address?
- 6y ago
- deleted 6y ago[deleted]
- JMTQp8lwXL 6y agoIn this day and age, sharing this community forum discussion here is the only way to get resolution. I'm happy helping people out and tweeting my displeasure with companies, but we need some way to scale this. We can't just help the people that get enough publicity. We think we're helping, and we are, but only a small amount of situations end up getting front paged.
- chatmasta 6y agoInteresting idea re: scaling. I agree this is a pattern we see time and time again with different companies on here. I wonder what a service built around this idea might look like? It’s basically outsourced customer service, isn’t it? It seems like HN is in a sort of Goldilocks zone, where it isn’t as crowded as Twitter but gets enough attention that companies are pressured to respond. I’m not sure how replicable these characteristics would be to a platform tailored specifically to this customer service problem.
- deleted 6y ago[deleted]
- g_delgado14 6y agoI don't think technology will be a long term solution. What I think the industry needs is tighter regulation and incentives for companies to not "move fast and break things", lest they get slapped with large fines. The issue is that I don't think the majority of politicians are informed on the social cost of, say, not serving a website over HTTPS or encrypting data at rest. Until then, this sort of thing will keep on happening because ultimately companies don't have a disincentive to do otherwise.
- thulecitizen 6y agoI think the only way will be by growing an agent centric web, where companies don't have much power over us to begin with.
- momokoko 6y agoCompanies in markets at scale are very much 80/20. That's one of the reasons government services are so expensive. If these services were fair to everyone, they would be orders of magnitude more expensive.
- nerdbaggy 6y agoSounds kinda like the users fault, having a corporate and personal email on the same account. Atlassian probably could put a warning though about the issues that could arise.
- sgk284 6y agoThis is just laziness on Atlassian's part. They should simply remove access to the Trello boards associated with the SSO account. See: Github - where you can SSO into your organization's repositories but this is completely separate from your personal repositories.
- nerdbaggy 6y agoProblem is they don’t know which boards are part of the SSO org since both emails are on the same account.
- shashanktomar 6y agoA board is owned by the user. In my case, my boards are clearly created by email ending in @gmail.com and not @company.com
- shashanktomar 6y agoI am the user in this case. I understand Atlassian's position in this case but this is so hard to track over such a long period of time. I left this workplace almost 5 years back and the account worked fine. Then it suddenly stopped working without any notification from their side.
- gumby 6y agoI think atlassian’s position is correct here, sad to say. They had to make a branch cut and i don’t think the other arm would be safe for them (company stuff leaked to a private account). Of course that stuff was already leaked, but I think the liability would fall on Atlassian if the company count delete that stuff. Don’t connect your personal stuff to your work stuff. That’s messed me up more than once — lesson learned, painfully.
- Wowfunhappy 6y agoThe user's account contained a secondary email address from five years ago. The user probably didn't even remember it was still on their account. Should you lose your account over that?
- javagram 6y agoAtlassian sent me an email earlier this year warning that all @company.com accounts were about to be converted to corporate accounts and that I had a month to opt out. (I did not opt out, because my @company.com Trello account was intended for use with my company) This person’s warning email probably ended up in spam. In general I’m not sure the best way Atlassian could have handled this. The recent upgrade to move @company.com accounts into having a better security posture and control by the administration of the company does make sense. Perhaps the person’s account should have just been disabled entirely until they removed either their personal email or @company.com email from the account to choose which way they wanted to go... That might have been the best solution to both protect corporate security and also the individual.
- jamiewildehk 6y agoIMO they should handle secondary emails differently to primary emails. Some sort of in your face warming when you login to trello before the migration may be appropriate.
- BostonFern 6y ago
- frenchman99 6y agoAlways keep separate personal and company accounts. If not for security reasons, then for privacy reasons. Mixing them usually yields little benefit anyway.
- ScottFree 6y agoLet's take the personal out of it: what if you're a freelancer or a contractor and the email and account used (and subsequently lost access to) was your professional email and account? Something like scott@freetechnologies.com? This whole situation makes me think I should steer clear of trello and clients that use it.
- quanticle 6y agoIf you're a freelancer or a contractor, and you're doing work for someone who uses Trello to manage projects, you should sign up with a throwaway e-mail address. That's what I do for Github. That way, if that organization then decides to wipe the account or mess around with its permissions after I've stopped working for them, it's no skin off my back. Personal stuff is personal, work stuff is work and ne'er shall the twain meet.
- deleted 6y ago[deleted]
- danielhlockard 6y agoThe github bit doesn't make any sense. When you leave you just get kicked from the org...
- franciscop 6y agoI also separate Github personally and professionally as a FTE. In most countries the company where you work has full access to your work computer, which implies also to your personal github and everything related to it. As a freelancer they don't have access to your computer so things are different.
- agotterer 6y agoSomeone at my company had a Trello account they setup with their work email and recently received an email that said the account was being migrated to an existing Atlassian account. Since her email address matched the domain operated by that Atlassian account all of her todos would be migrated to that account. Very little information was provided about the migration. My company has multiple Atlassian accounts, so we weren’t even sure which account it was migrating to. The whole thing was a weird janky process. Anyone with an email address should be able to register for an account and information should never be forcefully migrated or merged. In her case the only way out was to migrate to an account using a different email address.
- g_delgado14 6y ago> The whole thing was a weird janky process Atlassian's MO
- mjd 6y agoThey emailed me about this back on January 30: Subject: Your company ExampleCo will soon manage your Trello account Good news! Your Trello account is getting an upgrade. ExampleCo will now manage Trello accounts with a example.com email address, which includes yours (mjd+trello@example.com). The "Good news" part looked like marketing bullshit, but the rest of the message was menacing enough that I was able to contact them by email and get instructions about how to avoid having my personal Trello handed over to ExampleCo. It still sucks. The lesson I take from this is: “Software as a service” is always a security risk. Unless my data is on my server, someone else owns it and might sell it to a higher bidder. This is one of those “fool me twice, shame on me” moments.
- deleted 6y ago[deleted]
- cbhl 6y agoI feel pretty lucky that I've only ever used Trello with one ExampleCo -- so when I got this email, I signed in, removed myself all ExampleCo boards, and deleted my old ExampleCo email address from my account. This process isn't too bad if you actively work at ExampleCo, but if you left it years ago and are still on some boards... yuck.
- LeifCarrotson 6y agoMy takeaway is that you shouldn't link personal data to an example.com email address.
- dx034 6y agoIsn't it standard to open separate accounts for companies? My employers would've never even allowed me to use a personal account or personal email for business content. In the end, they need to be able to claim the content if an employee leaves the company. Mixing personal and company accounts or even accounts of several employers sounds dangerous to me.
- mjd 6y agoI opened the account with my personal address. Then later, I added a secondary email address to it so that I could post items to my personal account by emailing them from my work email. I didn't realize that Trello would interpret this as the account now being owned by my employer and, in hindsight, I don't think I could have foreseen this.
- deleted 6y ago[deleted]
- awinter-py 6y agooauth is net negative IMO Convenience is cool, the fact that one or more third parties has control of your account on the saas service is less cool also not so hot that it's used for login and information sharing. I had an experience where I read the oauth permissions carefully on a first login, and then on a subsequent login the app included contacts in the permission set. I noticed it too late. Super shady & I'll never use oauth personally again.
- mindB 6y agoIn 2016 I lost access to some repos on bitbucket after a similar occurrence. I made the mistake of using my (student) university email account to register with bitbucket (it was the primary email account I used for everything at the time). At some point, my university apparently decided to use Atlassian services which completely disabled any ability I had to login to that account. I don't know if linking together all accounts under a domain is just the default behavior from Atlassian or if both this former employer and my university decided to screw people over, but either way it's a stupid situation and unsurprising at this point.
- shashanktomar 6y agoIn this case, I did not even use the company email. I was my personal gmail.
- pdonis 6y ago> In this case, I did not even use the company email. I was my personal gmail. From the Atlassian community page it looks like the Trello account in question was linked to both your personal gmail account and an email account belonging to your former employer. Was that Trello account only for work items for that former employer? Or was it a mixture of both work items for that employer and personal items for you? Or was it just your personal account that happened to have your work email as an alternate email address? If it was just a work Trello acccount with your former employer, then I'm not sure why you would need access to that Trello account now that you're no longer with that employer. Atlassian is giving you the option of disconnecting your personal gmail from that account so you can create a new one if you want a personal Trello account. If it was a mixture of work and personal items in the Trello account, then the obvious lesson learned for the future is to not do that. If it was just your personal Trello account, I don't see why your previous employer would have a problem with telling Atlassian that it's not their account and that the email address in their domain can be removed. In any case, it doesn't look to me like this situation is Trello's fault. You say in a comment on the Atlassian community page that "It is very evident from the reply that Atlassian favors corporate accounts over individuals", but I don't see that they are favoring either party here. In fact they are refusing to favor either party, by refusing to make a decision--which email the account "really" belongs to--that they should not be making. This is something the two parties involved--you and your former employer--need to work out. It's not something Trello should be deciding. They have no way of knowing which party--you or your former employer--is the "right" owner of this account.
- JiNCMG 6y agoThe question that I have is... Will the control panel show the multiple addresses and can you delete one off. I just checked both accounts (personal and company) and they seem separate. In everything I do I always keep my work account separate from my personal accounts. I use separate browsers, never check personal email on company PC or network.
- stevoski 6y agoWhenever I get a “Good news! We’re changing things” email from Atlassian, I get an ominous feeling. It typically means they are making some changes to one of their products. The changes don’t benefit me at all, but do cause me disruption. I think any warm feeling I had towards Atlassian evaporated with the whole HipChat-to-Stride-to-nothing fiasco. 1. “Good news! We are replacing HipChat with Stride, which is a worse product with less features” 2. Soon after, “Good news! To serve you better, we are discontinuing Stride.”
- discordance 6y ago"Good news, everyone. Tomorrow you'll be making a delivery to Ebola 9, the virus planet." ― Professor Hubert J. Farnsworth
- thaumasiotes 6y ago"In our quest to improve our service for you, the user, we're making it worse" http://chainsawsuit.com/comic/2017/12/07/improvements/ http://chainsawsuit.com/comic/2017/12/07/improvements/
- addHocker 6y agoAtlassian shrugged
- yodon 6y agoWe had one of these at work earlier this year, except a 3rd party contractor suddenly found that their Atlassian account, including all their other clients, were now listed as part of our account. Neither we nor they wanted this.
- Mandatum 6y agoSo I just clicked on that link with a private browsing window and I'm logged in as someone else in my org's account. Someone I've never met, talked to or been in the same room as. They live on the other side of the world. I suspect some sort of IP-based cache has stored their cookie or a set auth-header. Very creepy, Atlassian.
- brentis 6y agoMy company recently started using trello and noted my old login was hijacked somehow and associated with my work domain. How do I unfuck this situation while still employed with access to both my gmail and wor email?
- saagarjha 6y agoAsk someone in your company to disassociate you?
- deleted 6y ago[deleted]
- whalesalad 6y agoAtlassian, at its core, is a software integrator. They buy stuff and add it to the heaping pile of duct tape garbage they’re schlepping. Trello is just another skull and crossbones on their long list of pillages. It was only a matter of time before the integration got some steam and the atlassian cancer began to take residence. Sad because it’s my go to tool. It’ll hold on for a while longer but at some point they will turn it into some sort of Jira Kanban+
- dreyfiz 6y agoGitHub did this to me a few years ago. I still feel violated. Not by my idiot former employer. I feel violated by GitHub. I got my account back. Sort of. They detached a significant amount of my content from my account, and returned to me a gimpy lobotomized version of myself. All my old GitHub comments are credited to “ghost” now. I was somewhere in the first 12,000 GitHub accounts. My relationship with GitHub significantly predated my dalliance with this one employer years ago. I trusted GitHub. My GitHub account was a formative part of my identity. I still can’t believe it and I still can’t forgive them. I lost some of my sparkle that day.
- rorykoehler 6y agoWhy would anyone think that is ok?
- jimbob45 6y agoThe million dollar question is what you use now instead of GitHub.
- mikorym 6y agoNot OP, but have a look at sourcehut.com; it used to be sr.ht if the name is unfamiliar. The latter URL is still used internally for some parts of it.
- zck 6y agoA note -- it's sourcehut.org. And all the actual content (repos, bug tracking, even the login page) is at sr.ht.
- ajobforme 6y agoatlassian's?
- Accacin 6y agoSourcehut! I love it and have moved most of my stuff over. I'm not sure how it works for teams, but for my personal stuff I couldn't be more pleased.
- snack_man 6y agoUnbelievable. I've been waiting for the other shoe to drop since the Atlassian acquisition, now strongly reconsidering my Trello usage. What's an easy platform to migrate my data to?
- brentis 6y agoToo soon to start talking about Trello Alternatives or should we give them another 5 minutes?
- kyleee 6y agoNever too soon to talk about alternatives to Atlassian services
- scoot_718 6y agoIf this happened in my country that would breach privacy laws. It might also constitute hacking depending on what kind of administration the company does.
- mcv 6y agoI agree. This sounds a gross violation of EU data privacy laws. Not every country has those kind of data protections for their citizens, unfortunately. I hope that all Europeans hit by this will make an issue out of this that will make Atlassian and other companies think twice before doing something like this again.
- downerending 6y agoA reasonably well-known blogging site handed my account to a would-be porn star while I wasn't looking. That link is now way more interesting. And while it was linked to my LinkedIn. Yikes. The Internet gives, and the Internet takes away.
- shashanktomar 6y agoFrom the comments, there is some confusion about why did i attach my personal email to a company account. That was not the case, let me clarify it. I created my personal account long before Trello was acquired by Atlassian. It did not have any SSO at that point and the login was with username and password. At some point, while working on a side project and to share it with a teammate, I attached a secondary email to my account and created few boards under it. This email was my companies email @company.com The multiple account login used to work the same way it works for github now. The boards were very clearly labeled under the email/username they were created and clearly had the ownership well defined. As soon as I left the company and my email was disabled, all the boards under that email disappeared from my account. This was expected and kept using my primary email (i always used to login with my username) and completely forgot about an attached secondary email (which anyways is now deactivated). Fast forward 5 years with tons of personal boards under this account, one morning it stopped working without any notification (yes i revised my spam to be sure about it) with all my data gone.
- caseysoftware 6y agoI have separate personal and work Trello accounts. After seeing your report, I checked to make sure they're still separate. They are but each have access to each others' boards. I have yet to figure out how to deactivate that.. but since they're separate users (vs secondary email), I don't think the same will happen. But who knows? Not me. Good luck getting this straightened out.
- alexis_fr 6y agoAtlassian is not the only one who wrecked login by implementing SSO across all their instances. I really don’t recommend using in-app dual logins (for example Gmail’s dual login), and stick to using separate Chrome profiles or Firefox profiles, so that none of the cookies are shared. Even with that, I’ve had surprises with my mobile phone number being the only shared information between two Google Ads accounts, and Google mixing my data, but avoiding sharing cookies is really important. That is also what I recommend my employees. « You can use Facebook or Youtube at work, but not in the same Chrome profile. »
- antoncohen 6y agoTrello sent me this email today: > Using a work email address with Trello > At least one of the email addresses linked to your account belongs to an organization: > <redacted>.com > This usually means it's a work email. If this organization begins using Atlassian products while this email address is linked, your account could become managed by that organization, which means you could potentially lose access. If you don't use Trello for work, just select a non-organizational email. In my case the "organization" is my personal domain. I'm guessing they classify any email address that isn't with a common free email provider to be a work email address.
- Aeolun 6y agoThat’s on par with ‘things programmers believe about names’. What an idiotic conclusion.
- sbrother 6y agoThis is scary. I’m trying to understand - I have several Trello accounts, one that I use for my own personal work and some consulting clients, and several other accounts with @client.com emails. Does this mean that if I have my personal account added as a secondary email anywhere on a client owned board, they can take control of my personal account including other clients’ IP? If so that’s terrifying and we need to find alternatives ASAP.
- shashanktomar 6y agoThat is precisely what happened to me.
- austhrow743 6y agoElsewhere you wrote that the opposite scenario happened to you. You tainted your personal account with a work email. This person is worried about tainting their personal email with a work account.
- shashanktomar 6y agoIt's evident from their reply that they do not care about a primary or a secondary email. In my case the company email was secondary, in this case it is primary.
- harry8 6y agoThis is fantastic PR for Atlassian. All their customers present and potential are seeing them do exactly the wrong thing ethically in order to take a side against an individual in favour of an employer. Big gold star from corporate. Individual developers, rob them, that is fine. The customer is right. The user is not the customer. The other way around. Taking a firm's IP and denying access to it while giving it to a former employee who did not own it. Words like theft would be bandied about freely. Oh for the days of the rule of law and equality before it, huh?
- Aissen 6y agoIf a CISO looks at this, she might think "great, so anyone entering a commercial relationship with Atlassian can now eventually take control of the boards of some of my employees ?". And that's not good PR.
- hoppla 6y agoSounds to me that Trello should have asked users to unlink any old accounts in good time before making this move
- mcv 6y agoAnd what if the user is on vacation or in the hospital or something? Such a dramatic change to your account should be opt-in, not opt-out.
- lki876 6y agoThis sounds like a major GDPR violation. If they do business anywhere in Europe they could face major fines if someone were to lodge a complaint with a national national data protection authority. And here is a list of national data protection authorities in Europe: https://edpb.europa.eu/about-edpb/board/members_en https://edpb.europa.eu/about-edpb/board/members_en
- geocar 6y agoI’m not sure I agree. I have provided GDPR consulting in the UK over the last three years. What exactly do you think was a violation?
- lki876 6y agoGDPR protects personal data, which the EU interprets very broadly. When you are working and what you are working on is included, for instance. That's basically a Trello board. Processing of such data (e.g. handing it over to a third party) without explicit consent is subject to major fines.
- geocar 6y ago> GDPR protects personal data, which the EU interprets very broadly. This isn't accurate. Individual member states can and do interpret the GDPR differently. For a European company, the country they are "at home to" is the one that will govern them, not the state that the individual belongs to. If the company is not "at home" in the European Union (for example, because it is in the US and has no European offices and does not trade in Europe), then the rules of the individual's member state will apply. The details matter. > When you are working and what you are working on is included [as personal data], for instance No: Not in the UK or Ireland (which I'm most familiar with) and probably not in any other European country. Personal data is data that identifies a natural person, or that can be used to identify a natural person, not that is produced by a natural person. The ICO has excellent (English-language) literature on this subject: https://ico.org.uk/for-organisations/guide-to-data-protection/guide-to-the-general-data-protection-regulation-gdpr/key-definitions/what-is-personal-data/ https://ico.org.uk/for-organisations/guide-to-data-protectio... It may be that storing (say) your email address on every Trello card would be personal data, but then you can follow the process to have this data identified and removed by sending a letter requesting it be returned to you and destroyed. Trello would not be required to figure this out on their own - you would have to tell them how to identify your personal data. https://ico.org.uk/for-organisations/guide-to-data-protection/guide-to-the-general-data-protection-regulation-gdpr/individual-rights/right-to-erasure/ https://ico.org.uk/for-organisations/guide-to-data-protectio... https://ico.org.uk/for-organisations/guide-to-data-protection/guide-to-the-general-data-protection-regulation-gdpr/individual-rights/right-to-data-portability/ https://ico.org.uk/for-organisations/guide-to-data-protectio... > Processing of such data (e.g. handing it over to a third party) without explicit consent is subject to major fines This isn't what the GDPR refers to as processing, and it is absolutely possible to process personal data without explicit consent. For example, the ICO suggests no less than five separate ways that are not explicit consent: https://ico.org.uk/for-organisations/guide-to-data-protection/guide-to-the-general-data-protection-regulation-gdpr/lawful-basis-for-processing/ https://ico.org.uk/for-organisations/guide-to-data-protectio... And again, I don't agree that "Trello cards" count as personal data. You can call the ICO (if you want) and ask them if you think otherwise; I have done this several times and they've happily sent me written clarification on any theory I might have (including on something that is similar to this): https://ico.org.uk/global/contact-us/ https://ico.org.uk/global/contact-us/
- subjectnull 6y agoI'm not blaming you by any stretch but this just further reinforces my view that everyone should be self-hosting wherever they can. You simply can't trust any corporation to do the right thing and GAF about people's right to privacy or access to their own information. I think whoever solves the problem of making it easy to offer web application services while allowing users to own, protect and backup their own data will be rewarded.
- Legogris 6y agoOT, but I had this with Azure. My MS account was tied to the AD of a previous customer. Can not access Azure dashboard or services at all. 5 years later and still not resolved, despite numerous e-mails, phone calls, with several people (they even insisted I install a .exe file in order to be able to do screensharing. It took some persistance to make them accept that I shouldn't have to install Windows and install a binary just to be able to restore my account. That was about 6 months ago. If this is how Microsoft support works for real, no wonder the scammers getting people to install malware are successful).
- jwr 6y agoI have a single E-mail account that I use for everything. I decided more than ~20 years ago that my E-mail is tied to my identity and not to any particular E-mail service or employer, and I started managing my E-mail myself. Trello just notifided me that: > At least one of the email addresses linked to your account belongs to an organization: [...] > This usually means it's a work email. If this organization begins using Atlassian products while this email address is linked, your account could become managed by that organization, which means you could potentially lose access. If you don't use Trello for work, just select a non-organizational email. I use Trello myself, as well as in connection with several organizations. The idea that someone can "claim" and "manage" my account is outright ridiculous. Even worse, in a show of incompetence, their "Confirm email" link doesn't work (times out because the server is seemingly down).
- PeterStuer 6y agoJust received the same email, and had the same experience as you. Servers are not responding. Now I'm no longer using Trello as I moved to tasksinabox.com 2 years ago, but I don't see why the information I have there should suddenly be transferred to a company, out of my control and without my permission, just because somewhere there is an email address with a company domain name attached. I understand the old "lure shadow IT users in with a 'free' service, then offer IT to take back control at a price" scheme, it's a bit of a dark pattern, but then the per-existing users should have the option to opt out of the retroactive appropriation. I do hope that once the 'confirmation' page comes up, there will be the option to remove the company email from the account, and assign a different address in its place.
- mattmanser 6y agoDid it actually come from @trello.com? As I got the same email from @trellis.coffee and assumed it was a phishing attempt.
- thedufer 6y agoI'm a former Trello employee - trellis.coffee is the domain the primary dev server is hosted at. It sounds like they failed to excise your email address from the dev database (at least, that's what we did when I worked there).
- 0k 6y agoBeware the Atlassian's SSO "2 factor authentication" (2fa). I remember asking them every month years back their hand over to Atlassian - to create / enable backup codes functoonality. Several months ago after changing countries and phones I discovered that my backup codes didn't work. Their "support" offered me a "solution" - to delete all my boards associated with my email so that I could create fresh ones. Zero apologies, zero explanation as of why my perfectly double-backed up 2FA codes were not working, all blames on me the user. There were sensitive details for approx 16 projects collected daily over the span of 5 years. That SSO 2FA is flawed the same way across all Atlassian products. Never again would I trust my data to Atlassian. WeKan is open source and welcome.
- znpy 6y agoTHIS. AVOID whenever possible sms-based 2fa. Use totp codes. SMS makes your phone a single point of failure [1]. I currently use the OTP feature of keepassxc, so that I can still generate otp code but can have those codes replicated on my trusted devices. You can save the seed of the TOTP and re-install the otp on other devices too. [1] plus you should really try and depend as little as possible on your smartphones. smartphones are the leash of the third millennium. the less you are dependant on it, the free-er you are.
- raziel2p 6y agonowhere does the parent mention SMS - they're talking about backup codes, which exist regardless of whether you use TOTP or SMS or something else.
- thdrdt 6y agoIn most countries whatever job related work you do is owned by your job (even when you do it at home in your own time). So never make the mistake to mix private with work. I don't think Atlassian is to blame here. Maybe they could have communicated this better to the owner of the account. But if you own an account it does not mean you own the content if you used it for work.
- mcv 6y agoAtlassian is absolutely to blame. You still own the account and any personal data on it. It's not their to give away to someone else. If a company thinks they own something on that account, they should address that with the owner of the account. In court, if necessary. But companies just seizing your data like that should be illegal, and companies should not enable it. They certainly shouldn't proactively give your data to someone else. Note that Youtube is also guilty of similar things, allowing companies to claim ownership of independent users' original works. There need to be stronger laws to crack down on such abuses.
- savolai 6y agoHeads up: Notion works surprisingly well for trello boards, and they have import functionality straight from Trello. The only thing that didn’t import afaik is card tags/labels that didn’t have a name so I had to reimport after adding names to tags/labels.
- _wldu 6y agoI have seen 'secure storage' companies pitch to our management that 5,000 users with @example.com emails already use the personal version of the service offered by the company. Now, I'm wondering if we bought the 'enterprise' version of the service if the same thing would happen to these users. If so, it seems the users ought to be given a choice to convert to the enterprise version or change emails beforehand so they can keep their own personal service intact.
- arh68 6y agoDo any accounts have 2 work emails tied to them, I wonder? Would they hand it to Company A, who would gain whatever IP of Company B that was still in the account? Would they arbitrate who gets what? You know, the one thing nice about using a cloud service is that your data is just there, nice and safe. You know, usually.
- praestigiare 6y agoEasy answer: "An email address attached to your account is being set up for SSO. You must update your account: 1. Remove the example.com address from your account. Warning: You will lose access to all boards shared with this email address. 2. Accept the SSO migration. Warning: You will no longer be able to sign in with your Trello email and password.
- maest 6y agoWhat happens if I associate my Trello account with my personal gmail address and two different corporate emails? (from different corporations). Who wins between CorpA and CorpB?
- cassalian 6y agoI am far from a lawyer, so would someone with a better understanding of the law explain to me why this wouldn't potentially violate laws around trade secrets? If someone uses a 'personal' email for setting up their business' trello account (including what could be categorized as trade secrets); and at some point in the future, they added a different companies domain to their account as a secondary login; and then Trello hands everything over to that other company; how isn't that a violation of trade secrets?
- boraoztunc 6y agoAfter seeing the comment from Blair at Atlassian on Community forum, I also noticed that Support Team replied with a lot more care seeing that the conversation went public. Not good. In the first stage, they should have already made the right decision, handing over the account to its rightful owner, without any hesitation. I hate companies favoring companies over individuals. I thought this was a mindset of old school businesses, not our current tech ones, the ones that build their success on us. I was already reviewing new tools for organizing plans, today I'm removing all my boards and closing my account on Trello, as my civil response. "Apathy is the tyrant's greatest ally."
- megavolcano 6y agoThis is why I don't use SSO for personal affairs, unless required. The convenience is not worth it to me, especially because I just use a password manager to log me in anyway. The provider will just cut you off at a moment's notice and then tell you to shove it. Besides, logging in is faster than having to be redirected to another page just to use my password manager to log in to my google account, redirect me back and then I'm in...just log in directly. I also never, ever, for any reason, no matter what, no matter where, or who, or who I am with, or where I am going, or where I've been... ever, for any reason whatsoever link a business email account to a personal account. I use different browser profiles and keep all that stuff segregated.
- logicuce 6y agoSeems like unpopular opinion given comments on this thread, but here it is anyway. Using my employer's email addresses for services I want to control doesn't sound right. Of course, LinkedIn is a different story but for SaaS platforms like Trello, my employer should be the rightful owner of the data I store in there if I used it for work. Imagine the other scenario, if that Trello account's control didn't move to the employer, the employee would still be keeping the content he created FOR the employer long after his employment has ended. I don't think that is cool. Your data is your data, likewise, your employer's data is theirs. If you don't want any hassle, keep these two lives different.
- shashanktomar 6y agoI believe that is not entirely true. Here is the explaination https://news.ycombinator.com/item?id=22874704 https://news.ycombinator.com/item?id=22874704
- logicuce 6y agoYou created a Side Project but used your company's email ID to share it with your teammate at work. Does that side project belong to you or to your company? If it belonged to you, why would you use office email ID for collaborating on it? and if it belonged to the company, why would you manage it on a personal Trello account? Sorry to sound harsh, but unless I am missing something, to begin with, looks bad judgement on your part.
- enesunal 6y agoI think this story proofs the saying: Never, ever, ever mix your personal and professional life.
- gravypod 6y agoDoes anyone have a good suggestion for ergonomic and functional ticket systems you can self host? Preferably with some board management? This is personally my key take away from this.
- matthewaveryusa 6y agoYou're a special kind of person if you are concerned about the privacy of your account and also enable your company's SSO on your account. I don't disagree that the conclusion of the story is that it sucks, but the moment you meld your private stuff with your company stuff you're asking for it. I generally have little sympathy toward people expecting privacy on assets provided by the company, wether that be hardware or software. If you read your private email on a corporate asset, or enable sign-on with a corporate credential, all data can and should be inspected by your corporation. The fact that companies don't MitM _everything_ is what's surprising.
- shashanktomar 6y agoWould you consider changing your opinion given more context https://news.ycombinator.com/item?id=22874704 https://news.ycombinator.com/item?id=22874704
- BerislavLopac 6y agoThe exact same thing happened to me. This was the Trello support team response: "I've taken a look at your account, and ultimately, the problem is that the email address of your former employer was still attached to the Trello account. In their recent account claim, this triggered your employer to claim ownership of the Trello account, which is something Trello's terms allow Enterprises to do. Because the email address was still on the account, your employer identified it as an account that they should own, and ownership of this Trello account was transferred to your former employer, so no changes can be made to the account, and the company owns that account. It sounds like you have personal content in this account that you want access to? Given the account ownership, that's not something that we can do on our end, unfortunately. If the company consented, they could remove your account from all company teams, and then we could remove the Enterprise association, but that's something you'd need to explore with them, if they'd be willing to do that."
- emmelaich 6y agoI've had a similar thing happen. I got the cheap tier for myself. (first.last@gmail). About the same time, I had a work email (first.last@example). For some reason, they listed my cheap tier license under the work email. I still have no idea how this happened except for maybe laziness by some Atlassian support person.
- bearer_token 6y agoImagine this from the other perspective: 1. You use Trello to track work with your team. 2. You invite your team to use Trello using corporate email accounts. 3. Someone leaves the company. You decommission their corporate email. 4. Five years later, you find out that person still has access to all of your work trello boards. At this point, I'd be flipping my shit and threatening to sue Trello. Trello's response would be: sorry, the employee associated a 2nd personal account. This would be unacceptable from a corporate access control perspective!
- raldi 6y agoThat's nothing like the real-world situation being discussed here.
- crooked-v 6y ago> Five years later, you find out that person still has access to all of your work trello boards. That's not how it works and not how it has worked. It used to work like Github does, where access control to boards is by account, not by associated email addresses.
- droithomme 6y agoWhat about sending Atlassian a cease and desist order, citing copyright law? They are not hosting your personal copyrighted content with your permission any more and have given access of it to unauthorized parties. I think you should consider seeing an IP lawyer. Since they are not being reasonable and are forcing you to legal measures, simply restoring your account is insufficient, you will want a settlement. Each violation of your copyrighted material might be good for $250,000 in fines.
- MrBoomixer 6y agoWell this was enough to give me some perspective. Time to clean up and delete some accounts. Thank you.
- drtillberg 6y agoSo next does Google get to dictate ownership of the Trello account, since there's an @gmail.com login?
- PerilousD 6y agoTrello has been advertising a lot on some podcasts that I listen to and I was considering using them. Sorry about the problems you are having - good luck with getting them resolved and thank you for posting this as I just crossed Trello off the consideration list :-(
- rsre 6y agoI'm on the same boat. I contacted Atlassian support via my personal email account and they informed me that somehow my subscription is tied to my personal account, but I need to use my former work email to login. I can't do that, so I've lost access to all my personal boards and apparently to my Gold Subscription too.
- daengh 6y agoAtlassian is starting to remind me of CA. Acquire something, rebrand it, make it worse.
- wilhil 6y agoI hear stories like this all the time - I'm all for "cloud" in certain areas, but, there are an increasing amount of companies that either don't care or have short sighted policies. I really think the future needs to look more at "master" accounts with Azure/AWS and similar services, make it much easier to delegate access to third parties so that the third party contains the core logic/application but the data resides fully with your own account. Data ownership is so important and overlooked by so many people who want an easy life and want to forget physical servers to look after.