Trello! It is me... you locked the door? User warns of single sign-on risk after barring self from own account
- Reference: 1587030191
- News link: https://www.theregister.co.uk/2020/04/16/locked_out_of_personal_account_trello/
- Source link:
The story goes like this. Tomar created his personal Trello account "long before Trello was acquired by Atlassian", as he [1]told the Atlassian community board . The [2]acquisition took place in 2017.
He did not use single sign-on (SSO); his login was simply username and password. Wanting to share some work with a colleague, Tomar added a secondary email to his Trello account so he could create Trello boards under that identity. "As soon as I left the company and my email was disabled, all the boards under that email disappeared from my account. This was expected," he said.
Five years on, "with tons of personal boards under this account, one morning it stopped working without any notification," he continued.
Tomar raised the issue with support and also on the [3]Atlassian community forums . Calling Tomar's former company ACME for confidentiality reasons, Atlassian explained: "The ACME Trello Enterprise has enforced SSO, meaning any Trello user with one of their emails as a saved credential must log in with ACME SSO, even if the user also has a personal email address as a saved credential. The reason for this is because The Enterprise has claimed the ACME domain, and therefore, ownership of the Trello accounts containing their credentials, which is something Trello's terms allow Enterprises to do."
Atlassian refused to restore Tomar's account access without consent from ACME. However, the email address provided for ACME bounced. The best Atlassian can offer is to remove the personal email so that Tomar can open a new, empty Trello account. Further, all the boards in the existing account have been handed to ACME.
Tomar's problem was resolved, not by Atlassian, but because the Trello app on his phone was still logged in, seemingly a flaw in the security. "After a tedious work, I have moved my documents to another tool," he said.
Users are concerned. "Where in the Trello interface can I even check what other email addresses are associated with my account?" [4]asked one . "The exact same thing happened to me," [5]said another .
In a discussion on Hacker News, similar incidents cropped up regarding other companies. "I had this with Azure. My Microsoft account was tied to the AD of a previous customer. Can not access Azure dashboard or services at all," [6]said a comment . "GitHub did this to me a few years ago. I still feel violated," said [7]another .
Mixing personal and work accounts
Tomar cannot understand why Atlassian could not see the difference between his data and ACME's data. "A board is owned by the user. In my case, my boards are clearly created by email ending in @gmail.com and not @company.com," he said. He is understandably indignant that access to his personal data has been granted to a former company.
The issues here are fundamental. First, if you put data in a cloud service without a backup, you are trusting not only that the cloud service will preserve your data, but also that you will not get locked out, whether by mishap such as forgotten credentials, or some other issue. Second, individual users have limited recourse compared to large businesses, especially if using a free or low-end plan.
SSO is part of the problem because it puts multiple accounts under centralised control. Whenever you sign up for a service with Facebook, Google, or a company owned account such as Azure Active Directory, you are granting control over access to that company, whereas with a dedicated login for that service this is not the case. The oddity here is that Tomar signed up with a dedicated login, but this ended up being overridden by a retrospective SSO adoption by his former employer.
The obvious conclusion is: first, to back up data stored with external services, and second, never to mix personal and work accounts even in seemingly safe ways. As we become more dependent on cloud services, though, backup other than from one cloud to another becomes challenging.
We have asked Atlassian for comment and will update with any further information. ®
Sponsored: [8]How to Build Your Digital Experience Portfolio
[1] https://community.atlassian.com/t5/Trello-questions/Re-Re-Personal-gmail-account-claimed-by-SSO-can-t-logi/qaq-p/1349664/comment-id/23849#M23849
[2] https://www.theregister.co.uk/2017/01/09/trello_atlassian/
[3] https://community.atlassian.com/t5/Trello-questions/Personal-gmail-account-claimed-by-SSO-can-t-login-anymore/qaq-p/1293750
[4] https://community.atlassian.com/t5/Trello-questions/Re-Personal-gmail-account-claimed-by-SSO-can-t-login-an/qaq-p/1350029/comment-id/23887#M23887
[5] https://community.atlassian.com/t5/Trello-questions/Re-Personal-gmail-account-claimed-by-SSO-can-t-login-an/qaq-p/1350145/comment-id/23894#M23894
[6] https://news.ycombinator.com/item?id=22875305
[7] https://news.ycombinator.com/item?id=22874508
[8] https://go.theregister.co.uk/tl/1936/-8578/how-to-build-your-digital-experience-portfolio?td=wptl1936
Re: Never trust a data store that you can't touch
True Dat (I'm watching the Wire box set at the mo'). I even dump my Mac notes out into plain text every so often, just in case
comparison
You hand your money to a bank - These have independant global and national oversight bodies with power to enforce a large set of laws, regulations and punitive penalties. - you can be fairly certain your money is safe.
You hand your data to a cloud company - These have ever changing T&Cs, more money than you & almost nothing to lose if anything goes bad - what's their incentive to give a flying one?
Decide how much of a PIA losing your data will be, then keep an up to date local backup.
Personal IP rights?
He could sue (or threaten to sue) because the old company has no right to his personal IP.
If the tables were turned and Atlassian gave him access to ACME's code, you bet yer pants ACME would sue.
Still, not keeping local backups is 100% his fault.
Re: Personal IP rights?
"He could sue (or threaten to sue) because the old company has no right to his personal IP."
Dunno what jurisdiction(s) would apply but I'd bet a big load tht it would cost a big load and, if succesful, he might get his data back or destroyed and it would take another big load to get costs. Not something worth betting on for the average person.
Hence the reason I have personal devices and work devices. I also won’t use personal credentials to log into any work services (not that I have a job at the moment)
Would this come under GDPR or similar rules?
Assuming the personal Trello contained actual personal data, the sort that GDPR would cover (or similar laws in other locations), and the person involved lived in the EU (or location covered by those similar rules), could they not report Trello/Atlassian for breach of GDPR, due to handing over access of said personal data to a 3rd party that had no right to it? (i.e ACME in this case).
After all, GDPR and law in general, trumps any Ts&Cs a company might try to enforce.
The same could then possibly be true for any 3rd party trying to do the same thing on other services.
Just a thought anyway!
Old e-mail
The question in my mind is why he didn't remove the AQCME e-mail when he stopped working for them.
A simple bit of sanitisation and housekeeping on his part could have saved all this hassle
Re: Old e-mail
Arguably the company should have unlinked the ex-employee's email from their projects. The ex-employee shouldn't need to worry if the company is giving them access they shouldn't have. That's the company's problem.
But, whoever is to blame; it's simply not right that solely personal projects, never linked to the company, are no longer accessible.
Re: Old e-mail
The question in my mind is why he didn't remove the AQCME e-mail when he stopped working for them.
I think he is implying Trello's UI provides no obvious way of achieving this.
Never trust a data store that you can't touch
always keep a local backup. Yes: it is more work and management but anything that you do not possess can be taken away by whoever does own it.
It is not just unexpected policy changes, like with this story, but also a technical issue. Your data is worth much more to you than the company that has it, so they will not put much effort in to recovering it after some error.
Another issue: who can read your data when it is in someone else's cloud ?