7 ms·
Yes, surprisingly, there is no other news source that I've found as yet. Worth noting, in the email from HIBP, they include the following full information: "Br
by rshaban 3y ago
Yes, surprisingly, there is no other news source that I've found as yet.
Worth noting, in the email from HIBP, they include the following full information: "Breach: Trello
Date of breach: 16 Jan 2024
Number of accounts: 15,111,945
Compromised data: Email addresses, Names, Usernames
Description: In January 2024, data was scraped from Trello and posted for sale on a popular hacking forum. Containing over 15M email addresses, names and usernames, the data was obtained by enumerating a publicly accessible resource using email addresses from previous breach corpuses. Trello advised that no unauthorised access had occurred."
- rozenmd 3y ago> scraped from Trello they'll argue it isn't a hack then, intentionally public endpoint
- sidmitra 3y agoI don't know about Trello, but i understand why B2B SaaS have this problem. The main issue is the ability to support various authentication systems, protocols, eg. Okta SSO, Google, Password, Mobile apps, Custom SAML and dozens of other enterprise-y stuff. To be able to support that most apps do it as first step is ask for an email to be able to redirect them to the right flow. So the problem is bootstrapping how does a user confirm it's him before he can login to the right system. Most B2B apps are forced to deal with this because there's no one protocol here, and different paying customers have different internal systems. Asking the user to choose from a dropdown of 20+ paths is proving to be impossible of the extremely high customer support costs. It's a cycle of misery