←back to thread

199 points orangeteacups | 1 comments | | HN request time: 0s | source
Show context
lapcat ◴[] No.41872346[source]
> In July, before the latest WP Engine blowup, an Automattic employee wrote in Slack that they received a direct message from Mullenweg sending them an identification code for Blind, an anonymous workplace discussion platform, which was required to complete registration on the site. Blind requires employees to use their official workplace emails to sign up, as a way to authenticate that users actually work for the companies they are discussing. Mullenweg said on Slack that emails sent from Blind’s platform to employees’ email addresses were being forwarded to him. If employees wanted to log in or sign up for Blind, they’d need to ask Mullenweg for the two-factor identification code. The implication was that Automattic—and Mullenweg—could see who was trying to sign up for Blind, which is often a place where people anonymously vent or share criticism about their workplace.

> “We were unaware that Matt redirected sign-up emails until current Automattic employees contacted our support team,” a spokesperson for Blind told me, adding that they’d “never seen a CEO or executive try to limit their employees from signing up for Blind by redirecting emails.”

replies(4): >>41872397 #>>41872717 #>>41873208 #>>41873512 #
orev ◴[] No.41872717[source]
> never seen a CEO or executive try to limit their employees from signing up for Blind by redirecting emails

I get that it’s creepy that this is being done, but I highly doubt that nobody at Blind has “never seen” this. Blind sends spam using multiple different domain names trying to get people to sign up. The domains are rotated so they can get around blocking on the email server, and the fact they do it means they already know that companies try to block them.

replies(2): >>41872951 #>>41874276 #
1. kelipso ◴[] No.41874276[source]
Yeah, it's like the most obvious security problem with blind that anyone would think of. Maybe this is the only company that made it obvious that they are monitoring for blind but there are probably plenty of smaller companies monitoring blind in secret.