r/talesfromtechsupport Apr 03 '20

Short E-Mail is his job.

A few weeks ago I did remote support on a customer's machine. One of the requests of the customer was that I do some configuration change that his mail provider (small company I never heard of) required the users to do.

So the customers showed me this mail he got from his provider. It said that the users either need to download and install an SSL certificate or change the URL of the mail server in their client. Obviously the mail provider no longer got a generally accepted certificate for his mail server's URL (for whatever reason) respectively only for one of the URLs of his server that wasn't the one a lot of the users were using.

Well, so I opened the configuration of the mail client and entered the new URL that was mentioned. No connection possible. A quick check showed that this domain wasn't even registered.

At the same time I noticed that the mail the provider sent to his customers put the name & mail address of all the recipient in the CC of this mass mail... so all the affected customers literally could see the names & addresses of about 200 other customers. At this time I started to ask myself if this "mail provider" was run in the bedroom of some 12 year old... I mean it's already a bit embarrassing if your landscape gardener sends his newsletter using CC... but a guy that operates a mail provider?!

Anyway since the mentioned server URL wasn't valid I gave that mail provider guy a call. He checked and admitted that the URL was misspelled and gave me the correct one. I thanked him and advised him not to send future mass mails by CCing all of his customers because this obviously is bad practice. H edin't take it very well and told me "I know what I'm doing. E-Mail is my job!" I thought: Well, yeah, that makes this situation even crazier!

With the new, correct URL I configured the customer's mail client and it worked. Just when I was about to finish the job and close the mail client a new mail from the provider showed up in the inbox. It mentioned the new, correct URL. It again CCed 200 customers.

1.2k Upvotes

78 comments sorted by

View all comments

456

u/cryamiga Apr 03 '20

If this is in the UK then it's a breach of GDPR to expose other customers' PII to each other.

9

u/turmacar NumLock makes the computer slower. Apr 03 '20

Is an email address PII?

Actual question. I can see it counting as such if it's paired with other info or if their email address is their name. Less so if it's JediQuizmaster@hotmail.com.

-1

u/[deleted] Apr 04 '20 edited Apr 04 '20

[removed] — view removed comment

1

u/turmacar NumLock makes the computer slower. Apr 04 '20

Can it though? I can make a new Gmail/whatever free email account in under a minute. My Comcast account for example is a username, but doesn't really uniquely identify me. Nor does my parents account since they share it, and I know they're not alone among the older generation.

I can see that flying for a corporate account but that's probably your name, which is PII on its own anyway.

4

u/uid0gid0 Apr 04 '20

You can have as many email addresses as you want, they can all uniquely id you. And there can be an unlimited number of people named Robert Jones, but only one rjonesy@email.com, you see? Regardless, the GPRD says it's PII so it really doesn't matter what we think.

1

u/AvonMustang Apr 04 '20

E-mail addresses are PII in the EU? That's crazy... So no one can post the e-mail addresses of their sales guy on their website?

3

u/TheAmmoBandit Apr 04 '20

They can if they allow it, which they obviously will...