Oliver Moore sending email to PH members

Oliver Moore sending email to PH members

TOPIC CLOSED
TOPIC CLOSED
Author
Discussion

markiii

3,676 posts

196 months

Thursday 9th June 2016
quotequote all
TheExcession said:
rofl
And meanwhile the bloke that setup this site cannot get a reply from
adverts@haymarket.com!

Ollie, what do you actually do day to day?
Wouldn't we all like to know

DonnyMac

3,634 posts

205 months

Friday 10th June 2016
quotequote all
Fidgits said:
Hoofy said:
DonnyMac said:
Hoofy said:
Mistakes happen but I'm surprised you don't use something like MailChimp.
Because that would be breaking the Data Protection Act too (can't store EU data on US servers).

Hold on, I get what you mean - they probably are.
Oh, I'm not that clever to have meant that. biggrin

Wait, is that an EU directive?
No and yes

Data protection principal 8 states you cannot store personal information outside the EEA and is a UK law.

EU privacy directive reinforces the requirements to adequately protect personal data that you store or process.

I think
^This, but I thought you were being funny.

T'is my job as linked from my profile.

longshot

3,286 posts

200 months

Friday 10th June 2016
quotequote all
markiii said:
longshot said:
What do you guys do with our e-mail addresses?

It may be just a coincidence but a week or so ago I received a junk e-mail on a not commonplace subject I'd been posting about roughly 10 minutes earlier
You've seen the way their adverts work, and PH uses more tracking bots these days than any other website I've come across

Wouldn't surprise me at if they are monetising our email addresses
My thoughts too.
It's likely to remain forever a mystery.

Terminator X

15,284 posts

206 months

Friday 10th June 2016
quotequote all
markiii said:
it was apparently human error the last time it happened as well

still not acceptable
Don't worry the robots will be along shortly after the autonomous cars.

TX.

anonymous-user

56 months

Friday 10th June 2016
quotequote all
markiii said:
TheExcession said:
rofl
And meanwhile the bloke that setup this site cannot get a reply from
adverts@haymarket.com!

Ollie, what do you actually do day to day?
Wouldn't we all like to know
Chief Buck Passer aka The Teflon Don

Illforever

49 posts

128 months

Friday 10th June 2016
quotequote all
So it would seem escalating this to the ICO is the thing to do then?

22

2,336 posts

139 months

Friday 10th June 2016
quotequote all
Illforever said:
So it would seem escalating this to the ICO is the thing to do then?
The fob-off might have been weak (and used before), but it's hardly the end of the world (and I'm on the list of emails). Reports to the ICO need to include how it has impacted you etc and only after you have corresponded in writing with the company of concern.

With very little regulatory power, a training need would probably be highlighted - PH nod politely, then it's forgotten about until the next time.

ryanthescot

287 posts

156 months

Friday 10th June 2016
quotequote all
Might have been good to actually say what the breach was in that second email. The first one ended up in my junk folder so I didnt notice it. I saw the second email and had to come here to figure out what the breach was. Poor show.

petrolbloke said:
Not sure Data Protection has ever been PH's strong point, given that the login form is not https.

I wonder if our passwords are salted and use decent hashing algorithm?
Also I've never noticed this but not having https on the login page is unforgivable. This needs to be fixed asap. From what I gather you are using Thinktecture Identity Server as an STS which enforces https unless you override which should never be done in a production environment (this is made clear in documentation). Can you shed some light on what's going on here?

Dave Hedgehog

14,646 posts

206 months

Friday 10th June 2016
quotequote all
and this is why i use a sandbox email account

Ozzie Osmond

21,189 posts

248 months

Friday 10th June 2016
quotequote all
Ollie_M said:
We have looked into this and it was caused by a human error, it was a university student who is currently here on work placement
No, it's a gross failure of management to manage the business.

So rather then blaming this hapless student, why not identify the manager responsible for this shambles.

What does the Data Controller at Haymarket actually do all day? It clearly doesn't involve controlling any data...

AndrewEH1

4,917 posts

155 months

Friday 10th June 2016
quotequote all
Ozzie Osmond said:
What does the Data Controller at Haymarket actually do all day? It clearly doesn't involve selling ourcontrolling any data...
EFA

anonymous-user

56 months

Friday 10th June 2016
quotequote all
Ozzie Osmond said:
Ollie_M said:
We have looked into this and it was caused by a human error, it was a university student who is currently here on work placement
No, it's a gross failure of management to manage the business.

So rather then blaming this hapless student, why not identify the manager responsible for this shambles.

What does the Data Controller at Haymarket actually do all day? It clearly doesn't involve controlling any data...
Well unless the 'student' happened coincidentally to be called Ollie Moore then I think the manager is easily identified

Ozzie Osmond

21,189 posts

248 months

Friday 10th June 2016
quotequote all
Here's a link to Haymarket's job vacancies in the UK. Nothing there yet for a new "Community Experience Manager".

http://www.haymarket.com/work-with-us/build-your-c...

andburg

7,397 posts

171 months

Friday 10th June 2016
quotequote all
meh its an email address, i use a crapmail account when i sign up for forums etc anyway, worse things have happened and PH don't require anything of importance for signing up.

I'm sure Haymarket heave dealt with this and will put controls in place to prevent further issues.

Some Gump

12,745 posts

188 months

Friday 10th June 2016
quotequote all
PH,

Your email is an abortion. Why didn't you explain what the breech was, before using your "it was the new guy" excuse?

I opened it and am thinking- what data breech? OK my PH password is site specific, so no real danger there. H0wever, from competitions and adverts you have my name, address, telephone number, card details, the lot.

What did you expect as a reaction to someone receiving that? That we'd know instantly it was failure to BCC? Talk about creating a flap over something relatively small.


Oh, and FYI, it wasn't human error. It's your system at fault for having st controls. A correctly set up operation wouldn't let "human error" enter the fray, and a proper quality team wouldn't simply blame a student, they'd put controls in place to stop it reocurring. Guess you're not aiming for ISO9001 any time soon?
TOPIC CLOSED
TOPIC CLOSED