Slashdot Mirror


Verizon Exposes the Wrong 1,200 Email Addresses

netbuzz writes "If you're going to market your expertise by inviting 1,200 IT professionals to a seminar about securing data and protecting personal information, it's probably a good idea to protect the personal information of those you invite. On Tuesday, Verizon forgot that advice and blasted each of the 1,200 email addresses to everyone on the list ... and they did it 17 times."

19 of 94 comments (clear)

  1. Blunder by mfh · · Score: 5, Insightful

    Whenever email scripts have too many recipients, they do tend to refresh and try again, which can cause dupes. These addresses were likely supposed to be in the BCC field, or nonexistent (duh). So it was a mistake.

    That's an embarassing blunder, to hold a seminar on keeping private info secure and then spamming who is attending the seminar. I wonder how much time they will spend on that blunder, explaining how it can happen to anyone, even the mighty Verizon, but this foolishness will not strengthen Verizon's sales pitch.

    Spammers attend these conferences. Now spammers have known email addresses of everyone there.

    This would only make a difference if spammers made money based on sending targeted email. They don't. They make money based on volume of addresses when a shady merchant pays them. So maybe they could make $25 on this list?

    Apart from making one person in Verizon look stupid, this also enforces the theory that it only takes one idiot to... the whole internet.

    --
    The dangers of knowledge trigger emotional distress in human beings.
    1. Re:Blunder by Spacepup · · Score: 5, Funny

      Spammers attend these conferences. Now spammers have known email addresses of everyone there.

      If it's just spammers attending, then they only got the email addresses of other spammers. The spammers can spam themselves all they want for all I care.

    2. Re:Blunder by Ethanol-fueled · · Score: 3, Funny

      As your score(1, insightful @ 12:38pm pacific time) demonstrates, there are mod points available for short-winded wastes of time.

    3. Re:Blunder by omega_dk · · Score: 5, Interesting

      That would be insightful, if it were not so clearly wrong. Plenty of spammers target specific individuals; see http://searchcio.techtarget.com/news/article/0,289142,sid182_gci1259674,00.html for a specific example. Now, one could argue that targeting IT professionals would be an exercise in futility. Would you bet your livelihood on it? Would you bet access (possibly high-trust access, depending on how high up this IT professional is) to your company's network on it?

      Because that's what's at stake. It's not a question of sending email selling \/|agra to these people. It's a question of a very specific, highly targeted spam operation with the express purpose of getting access to the networks of these specific individuals, in the hopes that they can provide the access the infiltrator would want to the company as a whole.

      Now, I am not saying that this is a big deal; it's not like these emails wouldn't have been available from some other source than this email list. However, I will say that by completely dismissing an entire segment of spam email, that of targeted emails to specific individuals, you are unnecessarily lulling both yourself and anyone who reads your comment into a false sense of security. Highly targeted spam is a real risk; don't discount it as a very real attack vector. You must be ever vigilant, and I don't think you can be with that kind of attitude.

      --
      Just because you don't like the truth, does not make it false.
    4. Re:Blunder by Obfuscant · · Score: 3, Interesting
      Now, one could argue that targeting IT professionals would be an exercise in futility.

      Similarly, you'd think that spamming "postmaster" or "abuse" at a domain would be futile and wasteful, but I get more spam there than at my actual address.

    5. Re:Blunder by Anonymous Coward · · Score: 5, Funny

      you showed him dude, I certainly wouldn't want to be him because I would be reeling from that burn

    6. Re:Blunder by AndrewNeo · · Score: 3, Insightful

      Probably because they assume it will be a valid address.

    7. Re:Blunder by Anonymous Coward · · Score: 4, Funny

      enforces the theory that it only takes one idiot to... the whole internet.

      You accidentally... the internet? The whole thing?!

  2. Title is Misleading by rehtonAesoohC · · Score: 4, Insightful

    It's not that Verizon exposed "the wrong" 1200 emails, it's that Verizon exposed any email addresses at all.

    /bad title?

    1. Re:Title is Misleading by Anonymous Coward · · Score: 4, Insightful

      Sometimes you can get away with doing something stupid because nobody notices.

      This was not one of those times.

    2. Re:Title is Misleading by reymyster · · Score: 4, Insightful

      I believe the "wrong" referred to in the title meant to imply that it was particularly bad to expose these specific emails, like when people say "you just messed with the wrong guy"

    3. Re:Title is Misleading by Gewalt · · Score: 4, Insightful

      It's not that Verizon exposed "the wrong" 1200 emails, it's that Verizon exposed any email addresses at all.

      If ever there was a worst-case-scenario set of 1200 email addresses, this list was it.

      --
      Modding Trolls +1 inciteful since 1999
    4. Re:Title is Misleading by Naughty+Bob · · Score: 4, Insightful

      If ever there was a worst-case-scenario set of 1200 email addresses, this list was it.

      Yes and no. In terms of potential harm done, these people are much more equipped than your average person to be able to mitigate this fuck up.

      On the other hand, if there was ever a subsection of people who you donn't want to piss off in this regard....

      --
      "Be light, stinging, insolent and melancholy"
    5. Re:Title is Misleading by flyingsquid · · Score: 5, Funny

      It's not that Verizon exposed "the wrong" 1200 emails, it's that Verizon exposed any email addresses at all.

      While I agree that the email slip-up was pretty bad, I was more concerned about some of the other sensitive information that Verizon publicized. In addition to those 1200 emails, Verizon also emailed other sensitive information including:

      1.the secret herbs and spices that go into KFC's chicken

      2. the combination to the door of the Bat Cave

      3.The location of Dick Cheney's 'undisclosed location'

      4. The chemical composition of Kryptonite

      5. The burial site of Jimmy Hoffa

      6. the nuclear launch codes for U.S. Trident nuclear missile submarines

      7. the full name, post office box address, and social security number of the The Good, the Bad, and the Ugly's Man with No Name

      8. the address and repository information for that government warehouse that contains the Ark of the Covenant (it's on rack 12, shelf 7, box 336)

    6. Re:Title is Misleading by Teun · · Score: 3, Funny

      No, no.

      Verison is so sure about their new security policies that they wanted to show the experts that publishing their collective addresses is no longer a problem.

      --
      "The likes of Facebook and WhatsApp are free to those whose privacy is of zero value."
  3. Verizon responds by MarkGriz · · Score: 5, Funny

    "We just wanted to make sure you could hear us now"

    --
    Beauty is in the eye of the beerholder.
  4. Simple fix: boycot & save time by Alwin+Henseler · · Score: 4, Interesting

    If I were one of those invited, then a thing like this would immediately make me loose interest in whatever they'd have to say. Show in advance you can't do yourself what you're preaching about. Duh!

    I'd just decline the invitation, and spend my time elsewhere (probably more productive). If a majority of the invited folks would do this, the event would be dead in the water. Killed by stupidity of the organization.

    1. Re:Simple fix: boycot & save time by mrchaotica · · Score: 3, Funny

      ...a thing like this would immediately make me loose interest...

      Why, was your interest tight before?

      --

      "[Regarding the 'cloud,'] ownership was what made America different than Russia." -- Woz

  5. Re:I know this is /. and all... by david_thornley · · Score: 4, Insightful

    Except that there is absolutely nothing to distinguish some clerical errors and actual security issues. If information is leaked by clerical error, it's leaked just as effectively as if it were hacked out of an on-line database through cross-site scripting. Maybe more effectively.

    --
    "When you have eliminated the unacceptable, whatever is left, however improbable, must be the truthiness" - Holmes