News: 1595998565

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Reply-All storm flares as email announcing privacy policy puts 500 addresses in the 'To' field, not 'BCC'

(2020/07/29)


Some advice from The Register : when announcing a new privacy policy don’t do so with emails that reveal 500 addresses in the “To” field of the message.

We offer this advice after today finding ourselves on the receiving end of just such an email from newsletter-as-a-service platform Substack. Social media commentary on the mess mentions other mentions with hundreds of recipients’ addresses exposed.

Substack took to Twitter to abase itself before the Wrath Of The Internet™.

While we caught the error early, it was too late to retract that first batch. We are so sorry this happened – and we are aware of the irony. This was a genuine mistake, we feel terrible about it, and we will do everything in our power to never repeat it. — Substack (@SubstackInc) [1]July 29, 2020

But those who received the mail were merciless, mocking the message as clueless given that mass-mailers have been free and fabulous since Majordomo debuted in the early 1990s, while newer platforms like MailChimp also do a fine job. And then there’s the irony of a privacy policy being delivered by a privacy breach.

Substack just sent out an email announcing updates to their privacy policy... and accidentally cc’ed everyone in the batch. You’d think that they’d have nailed the whole sending bulk emails thing — nic carter (@nic__carter) [2]July 29, 2020

There may be some upside for Substack in the fact that many of the email addresses it exposed belong to people who have senior roles in major corporations, the Trump administration, governments and even a few media outlets that might on their best days be more prestigious than The Register . But while the company can say it has attracted quality readers, it has also ticked them off.

Reply-All action has so far focused on pointing out the ridiculous nature of the situation, but has been muted perhaps due to a desire not to inflict further privacy injuries on recipients. ®

Get our [3]Tech Resources



[1] https://twitter.com/SubstackInc/status/1288283848220893185?ref_src=twsrc%5Etfw

[2] https://twitter.com/nic__carter/status/1288319372260507648?ref_src=twsrc%5Etfw

[3] https://whitepapers.theregister.com/

hitmouse

Also if you emailed their published privacy email, the response is (from mailer-daemon@googlemail.com>)

We're writing to let you know that the group you tried to contact (privacy) may not exist, or you may not have permission to post messages to the group. A few more details on why you weren't able to post:

* You might have spelled or formatted the group name incorrectly.

* The owner of the group may have removed this group.

* You may need to join the group before receiving permission to post.

* This group may not be open to posting.

If you have questions related to this or any other Google Group, visit the Help Center at https://support.google.com/a/substackinc.com/bin/topic.py?topic=25838.

Thanks,

substackinc.com admins

Giles C

This sort of mistake sounds like they were doing the emails manually.

I run a small club and to avoid this we signed up with MailChimp to ensure that this didn’t happen when the gdpr regulations came in.

Even if you didn’t want to rely on a hosted service you can buy the mailing list software to run on a local machine.

Techical solutions are not a matter of voting. Two legislations in the US
states almost decided that the value of Pi be 3.14, exactly. Popular vote
does not make for a correct solution.
-- Manoj Srivastava