• Register
    • Help

    striker  0 Items
    Currently Supporting
    • Home
    • News
    • Forum
      • Try XenForo Demo
      • New Posts
      • FAQ
      • Calendar
      • Community
        • Groups
        • Albums
        • Member List
      • Forum Actions
        • Mark Forums Read
      • Quick Links
        • Today's Posts
        • Who's Online
      • Sponsor
        • Sponsor a Feature
        • List of Donors
    • Wiki
    • Support
    • What's New?
    • Buy Now
    • Manual
    • 
    • Forum
    • VaultWiki Discussion
    • General Discussion
    • Vaultwiki sent out an email and exposed a whole bunch of email addresses.

    1. Welcome to VaultWiki.org, home of the wiki add-on for vBulletin and XenForo!

      VaultWiki allows your existing forum users to collaborate on creating and managing a site's content pages. VaultWiki is a fully-featured and fully-supported wiki solution for vBulletin and XenForo.

      The VaultWiki Team encourages you to join our community of forum administrators and check out VaultWiki for yourself.

    View Poll Results: Whoever did this should be fired?

    Voters
    1. You may not vote on this poll
    • Ignore this blatant mistake

      1 100.00%
    • Reprimand the miscreant

      0 0%
    • Fire his/her ass

      0 0%
    Results 1 to 3 of 3

    Thread: Vaultwiki sent out an email and exposed a whole bunch of email addresses.

    • Thread Tools
      • Show Printable Version
    1. October 15, 2014 #1
      maryx
      • View Profile
      • View Forum Posts
      • View Blog Entries
      • View Articles
      maryx is offline
      Junior Member
      Join Date
      July 22, 2011
      Posts
      7
      Rep Power
      0

      Exclamation Vaultwiki sent out an email and exposed a whole bunch of email addresses.

      Are you people nuts? I just got an an email from you with this subject header
      VaultWiki Security Update: October 14, 2014

      It was to a group of maybe 50 people and YOU DIDN'T USE BCC

      So, now I have all these people's email addresses and they have mine.

      This is incredibly unprofessional, I am astonished.
      Whoever sent this out should be fired from your company. It is too, too stupid.
      It's inexcusable.
      Reply With Quote Reply With Quote

    2. October 21, 2014 #2
      pegasus
      • View Profile
      • View Forum Posts
      • View Blog Entries
      • Visit Homepage
      • View Articles
      pegasus is offline
      VaultWiki Team
      Join Date
      March 28, 2004
      Location
      New York, NY
      Posts
      2,959
      Blog Entries
      18
      Rep Power
      688
      We apologize for the duplicate mailing. One of the two messages that was sent out had corrupted body text, while the other contained the correct text.

      From what I understand, these two mails only went out to a small number of users. The first one repeated the Hello line in the body text multiple times with different user's display-names (usernames) in each line, rather than containing the appropriate security notice. This mailing was canceled within seconds but some users still managed to receive it. Again we apologize for this duplicate mailing.

      Aside from that, our understanding is that no sensitive data was released, not even email addresses. Our mail messages are not sent as 1 mail message with users CC'd or BCC'd. Each user receives 1 email that is addressed to exactly 1 user. So there should be no risk of email addresses being shared.

      The 'Hello user' line was the error that we are aware of and it only showed the site usernames of however many users received the mail before the process was killed. Site usernames are public information that can be accessed here in totality, as with other vBulletin forums: https://www.vaultwiki.org/users/list/

      I have run several tests against the original faulty mail script, to make an adequate response to your inquiry and can confirm that at least in my tests, the 1 email address per 1 message rule holds true and I cannot see other email addresses in the message headers, only the duplicated display-names.

      It is possible that some users had used their email address as their username. There is nothing we can do about that, unfortunately. The username is a public-facing name that other users will be able to see from time to time, and most users are aware of this when they sign up.

      If you believe our understanding of the duplicate message is incorrect, please forward a copy of the message you received back to us and we will investigate the matter further.
      - lead developer for VaultWiki
      Reply With Quote Reply With Quote

    3. October 22, 2014 #3
      DragonSigh
      • View Profile
      • View Forum Posts
      • View Blog Entries
      • View Articles
      DragonSigh is offline
      Junior Member
      Join Date
      August 26, 2011
      Posts
      9
      Rep Power
      0
      I received it too, but there is no e-mail addresses only a bunch of usernames. So I don't understand such aggression in the first post.
      Reply With Quote Reply With Quote

    Similar Threads

    1. A whole bunch of errors...
      By Jaxel in forum VaultWiki Questions
      Replies: 4
      Last Post: September 7, 2009, 4:39 AM

    Bookmarks

    Bookmarks
    • Submit to Digg Digg
    • Submit to del.icio.us del.icio.us
    • Submit to StumbleUpon StumbleUpon
    • Submit to Google Google

    Posting Permissions

    • You may not post new threads
    • You may not post replies
    • You may not post attachments
    • You may not edit your posts
    •  
    • BB code is On
    • Smilies are On
    • [IMG] code is Off
    • [VIDEO] code is
    • HTML code is Off

    Forum Rules

    • Contact Us
    • License Agreement
    • Privacy
    • Terms
    • Top
    All times are GMT -4. The time now is 6:50 PM.
    This site uses cookies to help personalize content, to tailor your experience, and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Learn more… Accept Remind me later
  • striker
    Powered by vBulletin® Version 4.2.5 Beta 2
    Copyright © 2025 vBulletin Solutions Inc. All rights reserved.
    Search Engine Optimisation provided by DragonByte SEO (Pro) - vBulletin Mods & Addons Copyright © 2025 DragonByte Technologies Ltd.
    Copyright © 2008 - 2024 VaultWiki Team, Cracked Egg Studios, LLC.