4 ms·
I understand Atlassian's part here. But Atlassian did this on purpose. They clearly understand the implication and the ownership of accounts, but they deliberat
by shashanktomar 6y ago
I understand Atlassian's part here. But Atlassian did this on purpose. They clearly understand the implication and the ownership of accounts, but they deliberately ignored individual users over big corporate accounts. And in my case, they didn't even have the courtesy to notify me in any way. I just stopped working one day leaving all my data unbale to use.
- nerdbaggy 6y agoWhy would they allow an account with multiple email addresses to login with the non SSO one? In your case you aren’t malicious but there could be used maliciously - add your person email - get fired and login with that email and now have all the data
- jakelazaroff 6y agoWhy not just prevent the user from accessing boards owned by the company?
- toomuchtodo 6y agoI would argue that the "right" course of action is to immediately require human intervention when an SSO email is added to an account (or an existing account with an email address, such as a startup "going big league", becomes SSO managed), so that account ownership issues are resolved at that point in time by the parties with ownership interest, not Atlassian having to do so.
- shashanktomar 6y agoThe ownership of data is attached to the email. As soon as i left my workplace, none of the data created under my company account was visible to me. On top of that, they launched SSO support lately. It was not SSO when I connected my accounts years back.
- itronitron 6y agoWhy would they allow an account to have more than one email address?
- tomphoolery 6y agoSounds like an Atlassian move to me...
- hashkb 6y agoYou actually were lucky that this didn't bite you until now. Not fair to blame your old job for waiting this long to force mfa. Edit: you can't say what they did deliberately or not. They're doing what makes the most sense for their business. Almost no support team I know would give you access to this account.
- wyattpeak 6y ago"They're doing what makes sense for their business" is a weak argument against an accusation of unethicality. Owning slaves is very good for business.
- pdonis 6y ago> They clearly understand the implication and the ownership of accounts Clearly understand what "implication"? From what I can see, all Atlassian knows is that there is an account with two email addresses attached to it. They have no way of knowing which email belongs to the "right" owner of the account. That's something the two parties involved--the two owners of the two emails--need to work out between them, and then give Atlassian a common response.
- tastroder 6y agoLast time I used Trello they had a relatively extensive concept of organizations and board ownership, while they might not have an idea about which email is the fictitious canonical owner of the account this still falls on Atlassian. They created this system that allowed AcmeCorp to change a setting and subsequently lock an ex employee out of non-organisation data. They know which of this accounts content is related to the organisation, they allow using a single identity for both private and corporate use cases at the same time. That's a use case their user facing interface actively encouraged. When I left the last company using Trello that distinction was pretty clear cut when I removed ties to the organisation. The linked thread reads like deliberate design decisions that turned out to be user hostile in favour of AcmeCorp. You don't have to assign a correct owner. Their data model seems pretty clear cut on which parts of an account are owned by which identity. If they develop a system that allows me to login via a private and a corporate email, have a data model that allows them to determine data ownership for the two, and yet decide to give one of those identities leverage over the other - it's okay to at least blame them partially. There's three parties involved here, none of them did everything correctly but only one had negative impact from this.
- pdonis 6y ago> they allow using a single identity for both private and corporate use cases at the same time. That's a use case their user facing interface actively encouraged. This seems to me to be the root of the problem, because to me this is obviously a bad idea and should be actively discouraged, if not prohibited altogether. If Atlassian, or some predecessor owner of Trello, did actively encourage this, then I agree they bear some culpability.