4 ms·
How was it possible to discover it, though?
by mistyq 6y ago
How was it possible to discover it, though?
- samthecoy 6y agoFrom the twitter comments: https://twitter.com/bicycult/status/1255122953798328320 https://twitter.com/bicycult/status/1255122953798328320 They were still logged in and refreshed the page; they found out by going to their user settings.
- KeepFlying 6y agoI noticed a similar thing being done for Bird scooters a while back. I forget the suffix but they did the same and I noticed because I was still authed on my phone after requesting deletion. My token has expired since then though so for all I know they have fully deleted the account since.
- deleted 6y ago[deleted]
- ashtonkem 6y agoHaving known people who worked at Bird, I doubt it. They had a real culture of “hack it up and then move on”, going back and fixing stuff like that isn’t in their culture.
- jasonbarone 6y agoI've seen this same method used on multiples apps I've requested an account deletion on. It's super frustrating. Most companies either don't respond back, say they deleted it when they merely disabled it, or they updated the account name to something else.
- three_seagrass 6y agoDisabling is understandable, because as a company you need a record of transactions or interactions such as TOS agreements for legal purposes. This requires keeping the records. Changing object name data though is a terrible practice to implement this.
- deleted 6y ago[deleted]
- malinens 6y agoactually GDPR forces You to have option to delete all data and not just d8sable user
- ptman 6y agoIt's a bit more complicated than that. You have a period of time to delete the data. And you can keep enough info to know what data you've deleted, so that if you restore from backups you are able to re-delete without having to go through your backups and delete everything. Probably more that I'm forgetting.
- Asuchug4 6y agoDepends on type of data and other laws. If you are a paying customer you can assume your data will be stay in database, until it is no longer required for audits. GDPR allows for anything that is 'absolutely totally required for providing service'.
- speleding 6y agoIn most countries you are required to keep payment records for tax purposes for 5 years or more. As this is a business necessity this trumps the GDPR. And since most business involves some kind of payment it's likely most businesses will not actually fully delete the information they have on file for you.
- three_seagrass 6y agoYou can keep contact info even after a GDPR deletion request, so long as you're not using it for business purposes. Otherwise imagine how easy it would be to violate the deletion request if you're running a business and can't remember the names of the people you had deletion requests for. Their data could come up again through normal channels and you'd treat them no differently than another sales contact, thus violating GDPR.
- gramakri 6y agoCatch all addresses? If you self-host email (we do), you are able to catch email with typos etc with a catch all address
- berkes 6y agoI once received an automated email to 'deleted@example.com'. Where example.com is my domain. I employ catchall, so that I can generate a new mail for each service. I contacted them and they apologised. The CTO personally explained that this was legacy they lost track of and thanked me for pointing out. You catch a lot, with catchall: dataleaks, hacks, sneaky data sales etc. When suddenly you recieve, say, marketing mail for shirts on 'jeansonline@example.com' something fishy is going down.
- HenryBemis 6y agoI have been doing the same since 2001, the amount of crap the net catches is unfathomable. Apparently there is a company somewhere on this planet with the same name as my last name "bemis.com" while my domain is "bemis.net" and I sometimes get invoices, CVs, PowerPoint presentations, emails from their external auditors.. I am waiting for the day they will ask me to buy my domain (which I use long before their company was created)(oh and it is my last name.. so good luck with that). Having done enough security audits, "this was legacy" is a BS excuse. I will go ahead and assume that NYT have an audit department. And that audit dept runs throug the full audit universe every 4-5 years. Someone would have captured that a long time ago (1st, 2nd, 3rd lines)(external auditors)(any sales pitch: "we have 438264728 subscribers") I call BS. They got busted and now they most likely change this from 1000 to 2000 and call it a day.. Ps: bemis is not my real last name.. but I am using a super cool name over here!!