NHacker Next
  • new
  • past
  • show
  • ask
  • show
  • jobs
  • submit
What to know about a recent Mixpanel security incident (openai.com)
clark-kent 72 days ago [-]
They need to own up to their mistake sending PII to an analytics tool. They could have easily sent a uuid identifier for each user instead of email, name and organisation. Seems like a major blunder on their side.
someone1998 72 days ago [-]
Why would they share name & email with a frontend analytics tool, this feels super amateurish. This information serves no purpose for analytics.
Hannah203 72 days ago [-]
Good write-up. Incidents like this show how easy it is for data to leak through third-party tools, even with good internal policies. The more dependencies a product has, the harder it is to keep the full chain secure.
polack 72 days ago [-]
That’s why you should only export anonymous information to external parties. There is no valid reason for OpenAI to export my personal information like this.

I will report OpenAI to the data protection agency in my country and I encourage others to do the same. They can not blame Mixpanel when they sprinkle others personal information around like this. NOT OK.

dependency_2x 72 days ago [-]
PII info

    Name that was provided to us on the API account 

    Email address associated with the API account

    Approximate coarse location based on API user browser (city, state, country)

    Operating system and browser used to access the API account

    Referring websites

    Organization or User IDs associated with the API account
Rookie mistake for a billion dollar plus company, let alone the most valuable in the world.
Ntrails 72 days ago [-]
I find throwing mixpanel under the bus whilst ignoring the giant elephant of "why were you giving them that user data in the first place" to leave a sour taste
ngcazz 72 days ago [-]
Pretty big red flag, as if the revelation they were having a data protection amateur hour wasn't enough
rvz 72 days ago [-]
Oh dear. Appears that there is another impending disaster with lots of affected customers about to respond to this incident from Mixpanel. CoinTracker had the same problem. [0]

[0] https://news.ycombinator.com/item?id=46065208

myth_drannon 72 days ago [-]
That's a lot of PII sent to an analytics tool. How is that even possible? That's a gross violation of GDPR and done by an established company not some amateurish startup.
72 days ago [-]
moi2388 71 days ago [-]
“ Was this caused by a vulnerability in OpenAI’s systems? No. ”

Yes. You guys sent PII to analytics. Entirely your fault.

Pretty sure this violates the GDPR.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact
Rendered at 10:13:08 GMT+0000 (Coordinated Universal Time) with Vercel.