Trello handed over my personal account to my previous company
community.atlassian.com
community.atlassian.com
The multiple account login used to work the same way it works for github now. The boards were very clearly labeled under the email/username they were created and clearly had the ownership well defined. As soon as I left the company and my email was disabled, all the boards under that email disappeared from my account. This was expected and kept using my primary email (i always used to login with my username) and completely forgot about an attached secondary email (which anyways is now deactivated). Fast forward 5 years with tons of personal boards under this account, one morning it stopped working without any notification (yes i revised my spam to be sure about it) with all my data gone.
I started disentangling myself from Atlassian products a few years ago but I was still using Trello. Clearly that's going to have to stop.
No work stuff is hosted in my personal accounts, and work accounts are always created with a separate e-mail. I can just remove myself from everything work related without touching anything personal.
While I was working with a small group, we had our own domain and e-mail addresses as a perk. My relationship went sour with the lead of the project and, as a power move, she disabled my e-mail and other accounts related to that group, guessing that a lot of stuff is connected to this e-mail (since the domain was prestigious in that circles) and doing so will hurt me a lot.
Since only things related to the group/work was on that e-mail, literally nothing happened. I just broke off cleanly from the group and, a move designed to hurt me brought bliss to the parting process.
So do it the same way every other website on the planet does it: have an organization and users who have roles within that organization. It's beyond aggravating the way they have them so strongly linked.
> Two, nothing can happen to your personal account based on the actions of the company page or other people associated with it.
.... I'm guessing this hasn't happened to you. Yes, they will block your personal account for "certain" infractions committed by the business manager. Nearest I can tell it depends on how you set up the business. If you set up the business FB page first, your personal account is considered primary so all blame flows to it. If you set up the business manager first, and THEN set up the page using the business manager (NOT the page creator), then it won't affect your personal account; and if you invite someone, no, that person's account won't (generally) be affected either.
Except that FB always drives you to create the business PAGE first and LATER suggests the business manager... thus increasing the likelihood of blocks. It's pathological. Especially because you can blocked for nothing other than their AI misidentifies something in an ad or a post, kills all your accounts, and then you have to beg to get them back.
Point is, that relationship shouldn't exist in the first place.
I have yet to figure out how to deactivate that.. but since they're separate users (vs secondary email), I don't think the same will happen. But who knows? Not me.
Good luck getting this straightened out.
I really don’t recommend using in-app dual logins (for example Gmail’s dual login), and stick to using separate Chrome profiles or Firefox profiles, so that none of the cookies are shared. Even with that, I’ve had surprises with my mobile phone number being the only shared information between two Google Ads accounts, and Google mixing my data, but avoiding sharing cookies is really important.
That is also what I recommend my employees. « You can use Facebook or Youtube at work, but not in the same Chrome profile. »
You don't need separate Firefox profiles for that, you can use Firefox containers.
Firefox Containers are awful.
Only firefox profiles can give you true separation.
It would have been better if Mozilla had added a better interface to profiles.
Profiles in Chrome and their ease of use (Cmd+Shift+M to open a new window in a different profile) is the primary reason I still use Chrome over Firefox. I have a Personal, a Work, and a Development profile. The development profile is where I install dev extensions like React Devtools, Redux Devtools, etc. because they require full access to all sites in order to function. I don’t do regular web browsing with devtools installed. These tools seem trustworthy, but why risk giving them access to everything I do on the web?
I’ve tried Firefox Containers and can’t find the same power and ease of use Chrome Profiles have.
Thinking over about you said, now I think I like things from the two worlds, maybe better interface to containers or even better UI for profiles, with options to overcome the containers (maybe should be better for the average user instead of having both).
For the time being, I prefer to have both options (don't have it now) but I think both can be improved.
One might argue that chromium is, but in my opinion using chromium only enforces google chrome
But I prefer profiles myself, as I have different extensions in different profiles and I get the two completely separate instances of Firefox, while containers are just separate tabs instead.
I don't think containers are awful though, they are just less useful for my use case than profiles.
Do you ever experience that?
Would allow greater discovery if this `about:profiles` page was exposed somewhere in preferences, but at least there is something I guess.
$ cp /usr/share/applications/firefox.desktop .
$ vim firefox.desktop
Add -P onto the end of the 'Exec' line. Now your click button for firefox will open the profile manager.
Any details, how do they leak?
> Only firefox profiles can give you true separation
I don't think they would help a lot against fingerprinting. (I have no idea how commonly used fingerprinting is at the moment.)
Extensions, mostly. You have to be real careful which extensions you install because extensions run at the window level (mostly) rather than the container level and see across/through containers.
Also things like auto-fill (including password suggestions); if you like that being very specific to context, then you'd want different profiles rather than containers.
I've found I've been using a mixture of profiles and containers, myself, to balance ease of access (containers are fast to launch and can auto-launch per specific sites) versus better extension control and auto-fill/etc separation.
(ETA: As for finger-printing, both containers and profiles are equal on the most common finger-printing: cookies and localStorage. Neither protects you well from IP Address tracking, which is a growing concern, but not the approach of at least the big players like Google or Facebook, yet.)
Do you have any sources or reasons for this condemnation?
Also, you can backup/restore/move profiles independently of each other.
Also, you can have different network settings for different profiles (not sure you can do that with containers).
For example I have a profile whose network connections are such that traffic is forwarded through a socks proxy (implemented via ssh). That's basically an ultra-simple vpn. I can then (via a script) automatically launch the tunnel open firefox with the appropriate profile and then exit firefox and gracefully stopping my tunnel.
Mozilla even has two official extensions, trying to explore the space of ease of use/user expectations. In addition to the main multi-container extension they offer Facebook Container which is an extension designed to be more entry level but for folks worried about privacy. (It does what it says on a tin, creates only one additional container, names it Facebook, and automatically moves all Facebook tabs and pretty much only Facebook tabs into it.)
I like to have several Container Tabs open all logged in to different accounts at the same time
Google Accounts fall into this category these days. Possible I’ll deprecate my use of those, as I don’t use gmail or drive any longer.
I have all my data backed up. I won't use a device or service that does not allow me to back it up.
Nice open source self hosting alternative.
Would love to get feedback!
Yea...so how does this solve OP's problem. Also desperation for sales leads eh?
All my old GitHub comments are credited to “ghost” now. I was somewhere in the first 12,000 GitHub accounts.
My relationship with GitHub significantly predated my dalliance with this one employer years ago. I trusted GitHub. My GitHub account was a formative part of my identity. I still can’t believe it and I still can’t forgive them. I lost some of my sparkle that day.
It's also why I oppose using social authentication with anything. While we have access to our [Facebook, Twitter, Github, Google, LinkedIn] account today, what happens if they shut it down? We have no clue of the real consequences and no appeals process. It's the worst of both worlds.
Tim Burners Lee was one of those people that caved with HTML5 standard, and several other standards under the W3C
https://montulli.blogspot.com/2013/05/the-reasoning-behind-w...
https://montulli.blogspot.com/2013/05/why-blocking-3rd-party...
He doesn't come across as overly prescient there, but there's definitely some of the familiar juggling trade-offs in his design decisions.
Do we have any protection besides moving to a new platform that's not big enough to betray its users yet?
The biggest danger back then was probably that if you changed ISP then you'd lose access to your old email address. That's still a danger with any email hosting service, including the likes of Google that people often use instead today, and it's why I advocate everyone registering their own domain for life. Email is still the root password to your online existence in almost every case, and letting any third party have more control of it than is strictly necessary is a really, really bad idea.
I would love to see a move back in that direction, which home ISP accounts allowing access to some sort of "starter kit" home server in the same way they probably provide most customers' starter modem/router/wifi equipment already, and with more software built that was aimed at being self-hosted and accessed via your home network or remotely through a VPN.
Sadly, I think this is unlikely, because there's just too much momentum behind the massive social networks and other online services. So instead, every now and then, a large chunk of someone's online life is going to get wiped out by the kinds of poor policies we're talking about today.
But that's not really self-hosting is it? If my ISP can decide to poke around in my user folder and there's nothing I can do about it?
I went through this with a Reddit account that got hacked. I was able to get the spammer shut down but had to create a new account, and really, it's okay. The people who know you will reconnect, and the others don't matter much.
It used to be that everyone got a new phone number when they moved, and we managed.
I feel like every netizen goes through this at one point of their life, where they trust an entity, get burned, and learn the lesson of never trusting another entity (100% without condition) again, keeping your data closer to yourself.
Much like in real life, where at one point you trusted some too much/naively, and after that point you're more careful, even of things/people you do trust.
Try suggesting that you can run a software business without using GitHub as your single point of failure^W^W^W^Wsource control system, and a lot of young developers will just laugh and wonder what you've been smoking.
Try challenging Apple's walled garden philosophy and suggesting that their mobile devices could implement standard protocols for transferring your own data on and off them directly like almost every other mobile device in the past decade, instead of relying on their not-properly-secured iCloud system, and plenty of Apple fans will wonder why you might care.
Even the HN community falls victim to this mentality from time to time. I find people here tend to be more rational about these issues than average, but any suggestion that one of the YC success stories that has become an HN idol has done something unwise or even bad can sometimes end up brutally suppressed.
It would be better, IMHO, if people kept in mind that behind these services they have allowed themselves to depend on so much is usually just a business, even if it's a big and famous one, and that businesses generally have no obligation to anyone to continue doing anything other than to the extent that either the law requires it or there is compensation changing hands and a contractual obligation.
TBH, I've never worked at a company that would host their source code at a third party service. At my first job, we wouldn't even use a web UI for the repositories (I still think that's not all that useful to begin with). At my current job, we use cgit. We use Jira (that we pay for, obviously), but as to source control --- a company hosting it on GitHub? Never seen it with my own eyes. But I work as a C++ dev, so maybe it's different here than, say, in webdev world.
Most likely that's the reason. I've only worked on web projects and everywhere I worked has been using GitHub for hosting the code and managing merge requests, except my first work where we used Redmine and then 6 months later migrated everything to GitHub.
One of their remote devs had his Github account hacked (pre 2FA) and then had access to Slack as well, and the hacker managed to socially engineer his way into a number of sensitive areas and increased access, to the point the company had all their code taken and a number of high GPU Amazon instances started to generate crypto coins to the tune of a $35,000 EC2 bill.
I'm from the old school and have never trusted third party services for anything critical to the company. I'll admit a bit of internal gloating after that incident.
While I am of the similar old school like you (I run my own mail server, web server, nextcloud, used to do ejabberd too...), I think it's more cost effective for smaller companies not to do it themselves, as long as they keep their own backups.
The difference is that when they self-host, they are more vulnerable to targeted attack (on average, for similar dollar investment), but if they host with SaaS providers, it's opportunistic attacks they should worry about more.
If that stuff is only hosted internally behind a firewall, with a VPN requirement to access, it would have been fine. Instead it was all on Github.
It's been a long time since I used it but I used to lean on gitweb for this at places that self-hosted git repositories but didn't have any UI layer on top. I remember it being perfectly fine for my needs.
To be fair, this example isn't quite as bad. It's simple enough to add a new remote to your working copies and host your repo elsewhere. It doesn't help with GitHub-specific features like comments or integrations though
"I want to make a change to a shared library. Why can't I make a pull request?" "Wait, I have to use this unfamiliar interface to make comments on other people's changes and I can't leave comments on specific lines?" "You know, if you used Jenkins and Github then you could show the status of passing or failing tests right here on the code review screen..."
These social pressures are really quite strong. They affect a bunch of open source projects especially: people who want to make changes expect code to be on Github and might even mirror it there themselves (creating confusing situations for anyone trying to contribute). Even if the project does host its code on Github to allow for contributions from Github users, Github is (naturally) not very good about directing its users off of its platform to where the existing discussion and development is going on. "It's easier if you just do everything on Github" says Github, and their users by and large agree, and slowly more and more process (code review, merging patches, CI, documentation) gets sucked onto Github by the platform effect.
I like to say that I was a free software developer before github, which means that I never really participated in it, but I frequently feel excluded when I am asked for my github profile ("sorry, there is nothing there, but I can point you at a dozen other repos...").
I am still resisting, but who knows for how long :)
I recently moaned and whined to my friend about how when i was growing up a person/entity (to my recollection) would feel.. like they received a magical gift just to send a message online.. having a web page was like.. winning the nerd superbowl.. Now it's like.. we are supposed to take a knee to any company that gets sufficient presence and significance (linkedin, etc trying to find a job).
What actions had you taken toward trying to remedy this ?
Isn't this how usernames started?
Aliases or nicknames are a common human choice, which allows one to be represented by a word/name of one's own choosing that portraits you in a light you want, without tying to your real identity which might have other implications (sometimes negative, of course).
It's bizarre to see so many companies handle this in such a user-hostile way. It looks like a clear sign not to use Atlassian or Github for anything private. Makes me wonder if Gitlab might be next...
GitHub organizations should make this a non issue. I assumed that they’re mostly competent, but if literally any past job I had could pull the plug that’d be a huge problem.
The risk is just too big.
With login via email I can still be in control of that account no matter what.
At least my company doesn't host anything on public guthub (guthub for enterprises has everything) so they don't need to be connected. If you have personal and company stuff you are in trouble even if you separate them.
Subject: Your company ExampleCo will soon manage your Trello account
Good news! Your Trello account is getting an upgrade.
ExampleCo will now manage Trello accounts with a example.com email address,
which includes yours (mjd+trello@example.com).
The "Good news" part looked like marketing bullshit, but the rest of the message was menacing enough that I was able to contact them by email and get instructions about how to avoid having my personal Trello handed over to ExampleCo.It still sucks.
The lesson I take from this is: “Software as a service” is always a security risk. Unless my data is on my server, someone else owns it and might sell it to a higher bidder.
This is one of those “fool me twice, shame on me” moments.
I understood that these were separate accounts in separate systems, they just had the same email address attached to both because it was convenient to log into each system from separate workstations - a little bit like using a company phone for a personal telephone call. When one company (Atlassian) acquired the other (Trello), the "accounts" were merged by someone who has no taste.
> In the end, they need to be able to claim the content if an employee leaves the company.
I don't agree with this at all, and thankfully tort doesn't work this way.
> Mixing personal and company accounts or even accounts of several employers sounds dangerous to me.
Indeed. This is a big reason why I don't like to create "free" accounts, because I know unless I pay them, I cannot sue them for fucking something like this up.
That's not what I'm seeing in any of the examples discussed in this thread. What I'm seeing is one account which started out as a personal account, then the person added their work email to it so they could get access to their employer's data through that account--instead of creating a separate work account under their work email.
Now their "personal" account isn't just personal any more; they have given their employer a means of controlling it, since their employer controls their work email. And then they have problems down the road. The solution to those problems is to never attach an email you don't control to an account you want to have sole control over.
They used to create an account using my professional contact email without asking, of course, and it would give me all sorts of problems with some SaaS services. Stuff similar to the ones in this post. Most of the time it was harmless (I'd lose access to another client), but it was always a headache.
The middle-of-the-road solution for me was to nicely ask them to remove it and use something like companyname@mydomain.com.
Of course the @mydomain.com solution didn't work for long as well (thanks, Salesforce), so I started using throwaway Google Accounts.
I don't understand how this is an issue. Just don't confirm the account. Or are there SaaS platforms where you can add users with arbitrary emails without confirmation?
In my experience, yes!
But the problem is not so much them adding without asking, it's the fact that the SaaS companies are making random assumptions regarding who owns the email account, or who owns the domain name of those accounts, and not letting users know that before accepting. Apparently only gmail/hotmail/yahoo are safe, unfortunately.
A few years ago I tried to sign up to LinkedIn only to find out I already have an account. But it was not my account - it was someone else's, who has a similar name (and apparently thought my email address was his? I don't know...). I could reset the password and log in to his account. I was a bit scared when I contacted LinkedIn support, because I was worried they would accuse me of hacking. Eventually they disconnected my email from his account.
Now, I know that LinkedIn isn't a SaaS platform, but you would think that such a big company wouldn't make such rookie mistakes. Even if they launched without email confirmation, and added it later, there should be some mechanism to "fix" the old accounts.
Ironic, considering that Twitter has started requiring phone validation recently!
"Use another Trello account for anything not related to [my previous company]. Grab a new, free Trello account in seconds and move your vacation board (or whatever should be elsewhere!) to that one."
My former company is not even using Trello and everything I have there is personal. I created the Trello with my personal email and only afterwards added the company email to it to access some experimental board we never ended up using.
I didn't comply and instead just removed the company email from the account. I seriously don't see why I need to create a new account and move stuff for no reason at all. Why does the organisation email trump my personal one that I actually created the account with? Should I be worried?
Because the organization a) pays them money, and b) demands this. Enterprise offerings like SSO tend to support the legal and pseudo-legal aspect of the security theatre of enterprise space. So if you connect a company e-mail to your personal account, that account suddenly falls under whatever random policies organization's IT team implemented.
This process isn't too bad if you actively work at ExampleCo, but if you left it years ago and are still on some boards... yuck.
I remember asking them every month years back their hand over to Atlassian - to create / enable backup codes functoonality.
Several months ago after changing countries and phones I discovered that my backup codes didn't work.
Their "support" offered me a "solution" - to delete all my boards associated with my email so that I could create fresh ones.
Zero apologies, zero explanation as of why my perfectly double-backed up 2FA codes were not working, all blames on me the user.
There were sensitive details for approx 16 projects collected daily over the span of 5 years.
That SSO 2FA is flawed the same way across all Atlassian products.
Never again would I trust my data to Atlassian.
WeKan is open source and welcome.
AVOID whenever possible sms-based 2fa. Use totp codes.
SMS makes your phone a single point of failure [1].
I currently use the OTP feature of keepassxc, so that I can still generate otp code but can have those codes replicated on my trusted devices. You can save the seed of the TOTP and re-install the otp on other devices too.
[1] plus you should really try and depend as little as possible on your smartphones. smartphones are the leash of the third millennium. the less you are dependant on it, the free-er you are.
Sad because it’s my go to tool. It’ll hold on for a while longer but at some point they will turn it into some sort of Jira Kanban+
Trello just notifided me that:
> At least one of the email addresses linked to your account belongs to an organization: [...] > This usually means it's a work email. If this organization begins using Atlassian products while this email address is linked, your account could become managed by that organization, which means you could potentially lose access. If you don't use Trello for work, just select a non-organizational email.
I use Trello myself, as well as in connection with several organizations. The idea that someone can "claim" and "manage" my account is outright ridiculous.
Even worse, in a show of incompetence, their "Confirm email" link doesn't work (times out because the server is seemingly down).
Now I'm no longer using Trello as I moved to tasksinabox.com 2 years ago, but I don't see why the information I have there should suddenly be transferred to a company, out of my control and without my permission, just because somewhere there is an email address with a company domain name attached.
I understand the old "lure shadow IT users in with a 'free' service, then offer IT to take back control at a price" scheme, it's a bit of a dark pattern, but then the per-existing users should have the option to opt out of the retroactive appropriation.
I do hope that once the 'confirmation' page comes up, there will be the option to remove the company email from the account, and assign a different address in its place.
As I got the same email from @trellis.coffee and assumed it was a phishing attempt.
znpy@eomdb:~$ nslookup trellis.coffee
Server: 127.0.0.53
Address: 127.0.0.53#53
Non-authoritative answer:
Name: trellis.coffee
Address: 10.253.0.237
Name: trellis.coffee
Address: 10.253.3.171
also: dig -t any trellis.coffeeIt seems like HN is in a sort of Goldilocks zone, where it isn’t as crowded as Twitter but gets enough attention that companies are pressured to respond. I’m not sure how replicable these characteristics would be to a platform tailored specifically to this customer service problem.
For example, it's hard to believe that an organisation not only handing over an obviously personal account to enterprise management but then failing to fix the problem when explicitly notified isn't in flagrant breach of the GDPR in Europe. The entire account tied to a personal identity could reasonably be considered personal data, which brings obligations in terms of properly managing and safeguarding that data and in terms of allowing the user to retrieve it and erase it, among other things.
I'm not generally a fan of how the GDPR was implemented in practice, but in cases like this, the sledgehammer-nut principle might well work in favour of the little guy. Going after both the hosting service and the former employer if they fail to disconnect the personal account and retain control over it when notified seems like exactly the sort of thing the regulators ought to be doing. This is such a flagrantly inappropriate policy that some sort of punitive fines to make an example don't seem out of the question.
From the Atlassian community page it looks like the Trello account in question was linked to both your personal gmail account and an email account belonging to your former employer. Was that Trello account only for work items for that former employer? Or was it a mixture of both work items for that employer and personal items for you? Or was it just your personal account that happened to have your work email as an alternate email address?
If it was just a work Trello acccount with your former employer, then I'm not sure why you would need access to that Trello account now that you're no longer with that employer. Atlassian is giving you the option of disconnecting your personal gmail from that account so you can create a new one if you want a personal Trello account.
If it was a mixture of work and personal items in the Trello account, then the obvious lesson learned for the future is to not do that.
If it was just your personal Trello account, I don't see why your previous employer would have a problem with telling Atlassian that it's not their account and that the email address in their domain can be removed.
In any case, it doesn't look to me like this situation is Trello's fault. You say in a comment on the Atlassian community page that "It is very evident from the reply that Atlassian favors corporate accounts over individuals", but I don't see that they are favoring either party here. In fact they are refusing to favor either party, by refusing to make a decision--which email the account "really" belongs to--that they should not be making. This is something the two parties involved--you and your former employer--need to work out. It's not something Trello should be deciding. They have no way of knowing which party--you or your former employer--is the "right" owner of this account.
The multiple account login used to work the same way it works for github now. The boards were very clearly labeled under the email/username they were created and clearly had the ownership well defined. As soon as I left the company and my email was disabled, all the boards under that email disappeared from my account. This was expected and kept using my primary email (i always used to login with my username) and completely forgot about an attached secondary email (which anyways is now deactivated). Fast forward 5 years with tons of personal boards under this account, one morning it stopped working without any notification (yes i revised my spam to be sure about it) with all my data gone.
This makes it seem like it's the third of the options I mentioned (personal account which happens to have a work email as an alternate email). But what you say a little further on (quoted below) makes it clear that it's the second: you used the same Trello account for both personal and work items. If the account had access to the company's boards, it's not just your personal account any more. It's a mixed work/personal account (which, as I and others in this thread have said, is not a good idea).
> As soon as I left the company and my email was disabled, all the boards under that email disappeared from my account.
But you apparently didn't remove that company's email from the Trello account. That's water under the bridge now, but in any case it seems like the company ought to be fine with telling Atlassian that you're no longer working for them and the email under their domain can be removed from the account.
What you seem to be wanting, though, is for Atlassian to just go ahead and erase that company's email from the account, or otherwise disconnect that account totally from the company so you can use it again, without any agreement from the company that that's ok. I don't see why Atlassian should do that.
And if this is technically difficult to do (because boards are not obviously linked to email addresses, or whatever), then that's still on them, but also solvable: allow you to remove BigCo email and just not give you access to any BigCo boards.
If you happened to have created a board yourself for BigCo, then that's still available to you. And if that's not acceptable for Atlassian, they should make boards more obviously connected to email addresses. Or something similar.
The equivalent to the current situation would be to allow you to add BigCo email to your personal Drobox account (for ease of logging in), and then remove you from the entire account when BigCo revokes your access. That's extremely unexpected!
The real devious behaviour was assigning your entire account to another entity to manage and without your permission. I've had to create a new account, ask the enterprise account manager to remove my account, and move my cards to another account. I've been using the account for 9 years and created many small integrations. Why would I want to give that up? Now my workflow is broken because the Trello app only allows one login so I have to decide is it going to be work or personal that I'm viewing because I can't do both.
If you're on Android, use Island or another app to set up a local Work account; you can now install a second instance of any app under the same profile, and log it into a different account. I'm unaware if iOS has similar.
Why? To me this is an obvious mistake. If you need to have sole control over your access to your account, then you should never attach an email to it that you don't control. You don't control your work email.
To me the sensible option is to have separate accounts for work and personal, and to never mix them. That way you're never even tempted to make the mistake of attaching an email you don't control--your work email--to an account that has your own stuff in it that you need to have sole control over.
It typically means they are making some changes to one of their products. The changes don’t benefit me at all, but do cause me disruption.
I think any warm feeling I had towards Atlassian evaporated with the whole HipChat-to-Stride-to-nothing fiasco.
1. “Good news! We are replacing HipChat with Stride, which is a worse product with less features”
2. Soon after, “Good news! To serve you better, we are discontinuing Stride.”
― Professor Hubert J. Farnsworth
Very little information was provided about the migration. My company has multiple Atlassian accounts, so we weren’t even sure which account it was migrating to.
The whole thing was a weird janky process. Anyone with an email address should be able to register for an account and information should never be forcefully migrated or merged. In her case the only way out was to migrate to an account using a different email address.
Atlassian's MO
In the first stage, they should have already made the right decision, handing over the account to its rightful owner, without any hesitation. I hate companies favoring companies over individuals. I thought this was a mindset of old school businesses, not our current tech ones, the ones that build their success on us.
I was already reviewing new tools for organizing plans, today I'm removing all my boards and closing my account on Trello, as my civil response.
"Apathy is the tyrant's greatest ally."
> Using a work email address with Trello
> At least one of the email addresses linked to your account belongs to an organization:
> <redacted>.com
> This usually means it's a work email. If this organization begins using Atlassian products while this email address is linked, your account could become managed by that organization, which means you could potentially lose access. If you don't use Trello for work, just select a non-organizational email.
In my case the "organization" is my personal domain. I'm guessing they classify any email address that isn't with a common free email provider to be a work email address.
Someone I've never met, talked to or been in the same room as. They live on the other side of the world.
I suspect some sort of IP-based cache has stored their cookie or a set auth-header.
Very creepy, Atlassian.
This whole situation makes me think I should steer clear of trello and clients that use it.
Personal stuff is personal, work stuff is work and ne'er shall the twain meet.
As a freelancer they don't have access to your computer so things are different.
"I've taken a look at your account, and ultimately, the problem is that the email address of your former employer was still attached to the Trello account. In their recent account claim, this triggered your employer to claim ownership of the Trello account, which is something Trello's terms allow Enterprises to do. Because the email address was still on the account, your employer identified it as an account that they should own, and ownership of this Trello account was transferred to your former employer, so no changes can be made to the account, and the company owns that account.
It sounds like you have personal content in this account that you want access to? Given the account ownership, that's not something that we can do on our end, unfortunately. If the company consented, they could remove your account from all company teams, and then we could remove the Enterprise association, but that's something you'd need to explore with them, if they'd be willing to do that."
1. Remove the example.com address from your account. Warning: You will lose access to all boards shared with this email address.
2. Accept the SSO migration. Warning: You will no longer be able to sign in with your Trello email and password.
If this is how Microsoft support works for real, no wonder the scammers getting people to install malware are successful).
The Internet gives, and the Internet takes away.
How do I unfuck this situation while still employed with access to both my gmail and wor email?
Using my employer's email addresses for services I want to control doesn't sound right. Of course, LinkedIn is a different story but for SaaS platforms like Trello, my employer should be the rightful owner of the data I store in there if I used it for work.
Imagine the other scenario, if that Trello account's control didn't move to the employer, the employee would still be keeping the content he created FOR the employer long after his employment has ended. I don't think that is cool.
Your data is your data, likewise, your employer's data is theirs. If you don't want any hassle, keep these two lives different.
Does that side project belong to you or to your company? If it belonged to you, why would you use office email ID for collaborating on it? and if it belonged to the company, why would you manage it on a personal Trello account?
Sorry to sound harsh, but unless I am missing something, to begin with, looks bad judgement on your part.
I hope that all Europeans hit by this will make an issue out of this that will make Atlassian and other companies think twice before doing something like this again.
All their customers present and potential are seeing them do exactly the wrong thing ethically in order to take a side against an individual in favour of an employer.
Big gold star from corporate. Individual developers, rob them, that is fine. The customer is right. The user is not the customer.
The other way around. Taking a firm's IP and denying access to it while giving it to a former employee who did not own it. Words like theft would be bandied about freely.
Oh for the days of the rule of law and equality before it, huh?
And that's not good PR.
You simply can't trust any corporation to do the right thing and GAF about people's right to privacy or access to their own information.
I think whoever solves the problem of making it easy to offer web application services while allowing users to own, protect and backup their own data will be rewarded.
You know, the one thing nice about using a cloud service is that your data is just there, nice and safe. You know, usually.
I contacted Atlassian support via my personal email account and they informed me that somehow my subscription is tied to my personal account, but I need to use my former work email to login.
I can't do that, so I've lost access to all my personal boards and apparently to my Gold Subscription too.
I also never, ever, for any reason, no matter what, no matter where, or who, or who I am with, or where I am going, or where I've been... ever, for any reason whatsoever link a business email account to a personal account. I use different browser profiles and keep all that stuff segregated.
And here is a list of national data protection authorities in Europe: https://edpb.europa.eu/about-edpb/board/members_en
I have provided GDPR consulting in the UK over the last three years.
What exactly do you think was a violation?
I guess people affected by this could submit a subject access request to get their data back.
I believe so, however this doesn't constitute legal advice (etc, etc)
This isn't accurate. Individual member states can and do interpret the GDPR differently.
For a European company, the country they are "at home to" is the one that will govern them, not the state that the individual belongs to. If the company is not "at home" in the European Union (for example, because it is in the US and has no European offices and does not trade in Europe), then the rules of the individual's member state will apply.
The details matter.
> When you are working and what you are working on is included [as personal data], for instance
No: Not in the UK or Ireland (which I'm most familiar with) and probably not in any other European country.
Personal data is data that identifies a natural person, or that can be used to identify a natural person, not that is produced by a natural person.
The ICO has excellent (English-language) literature on this subject:
https://ico.org.uk/for-organisations/guide-to-data-protectio...
It may be that storing (say) your email address on every Trello card would be personal data, but then you can follow the process to have this data identified and removed by sending a letter requesting it be returned to you and destroyed. Trello would not be required to figure this out on their own - you would have to tell them how to identify your personal data.
https://ico.org.uk/for-organisations/guide-to-data-protectio...
https://ico.org.uk/for-organisations/guide-to-data-protectio...
> Processing of such data (e.g. handing it over to a third party) without explicit consent is subject to major fines
This isn't what the GDPR refers to as processing, and it is absolutely possible to process personal data without explicit consent. For example, the ICO suggests no less than five separate ways that are not explicit consent:
https://ico.org.uk/for-organisations/guide-to-data-protectio...
And again, I don't agree that "Trello cards" count as personal data. You can call the ICO (if you want) and ask them if you think otherwise; I have done this several times and they've happily sent me written clarification on any theory I might have (including on something that is similar to this):
What do you think the new subject access rights, notably the right to data portability, are intended to achieve, if you interpret the definition of personal data so narrowly?
The GDPR actually defines personal data as "any information relating to an identified or identifiable natural person (‘data subject’)...", which is significantly different to what you wrote.
It seems to be widely understood, including acknowledgement in various statements by EU officials, that these provisions were aimed squarely at businesses like social networks to avoid them locking users in by holding the user's data hostage. That seems to be exactly the scenario we're talking about here.
I am not going to speculate.
> The GDPR actually defines personal data as "any information relating to an identified or identifiable natural person (‘data subject’)...", which is significantly different to what you wrote.
I can't speculate on what you think qualifies as "significantly different". I copied and pasted my definition from the ICO's website, which I also linked to. You can disagree with them, but I suspect strongly, even in the current Brexit climate, that the EU courts would agree with the ICO's interpretation over yours.
You might find the part that follows the "..." useful though. It's in Article 4 § 1, if you're unaware.
> It seems to be widely understood, including acknowledgement in various statements by EU officials, that these provisions were aimed squarely at businesses like social networks to avoid them locking users in by holding the user's data hostage. That seems to be exactly the scenario we're talking about here.
That may be part of your confusion. "We" weren't talking about anything to do with social networks, but whether a GDPR regulator is going to levy a heavy fine to Trello for this behaviour.
My point is that what it actually says, unlike the definition of personal data you gave, clearly goes beyond just the identifying information.
Moreover, there was also clear intent, reflected in the provisions of the GDPR itself and in statements by officials involved in writing and interpreting it at EU level, for the safeguards on data portability and erasure to cover exactly the sort of data we are talking about with a service like Trello.
I'm not aware of any action so far that has actually tested this, but if a national regulator chose not to penalise flagrant non-compliance with both the letter and the spirit of the GDPR such as we see in this case in response to a genuine complaint, it simply wouldn't be doing its job, since it would essentially be unilaterally deciding that entire articles of the GDPR are pointless.
This certainly isn't beyond the bounds of possibility. Indeed, the vague nature of the GDPR in many respects and the reliance on subjective interpretation by all the different national regulators was one of the big criticisms that I and others made at the time it was introduced. But if that happened here and the regulators chose not to enforce in a situation like this, it really would turn the GDPR into a bit of a joke.
I really think the future needs to look more at "master" accounts with Azure/AWS and similar services, make it much easier to delegate access to third parties so that the third party contains the core logic/application but the data resides fully with your own account.
Data ownership is so important and overlooked by so many people who want an easy life and want to forget physical servers to look after.
If someone uses a 'personal' email for setting up their business' trello account (including what could be categorized as trade secrets); and at some point in the future, they added a different companies domain to their account as a secondary login; and then Trello hands everything over to that other company; how isn't that a violation of trade secrets?
1. You use Trello to track work with your team.
2. You invite your team to use Trello using corporate email accounts.
3. Someone leaves the company. You decommission their corporate email.
4. Five years later, you find out that person still has access to all of your work trello boards.
At this point, I'd be flipping my shit and threatening to sue Trello.
Trello's response would be: sorry, the employee associated a 2nd personal account.
This would be unacceptable from a corporate access control perspective!
That's not how it works and not how it has worked.
It used to work like Github does, where access control to boards is by account, not by associated email addresses.
So never make the mistake to mix private with work.
I don't think Atlassian is to blame here. Maybe they could have communicated this better to the owner of the account. But if you own an account it does not mean you own the content if you used it for work.
If a company thinks they own something on that account, they should address that with the owner of the account. In court, if necessary. But companies just seizing your data like that should be illegal, and companies should not enable it. They certainly shouldn't proactively give your data to someone else.
Note that Youtube is also guilty of similar things, allowing companies to claim ownership of independent users' original works. There need to be stronger laws to crack down on such abuses.
For some reason, they listed my cheap tier license under the work email. I still have no idea how this happened except for maybe laziness by some Atlassian support person.
I generally have little sympathy toward people expecting privacy on assets provided by the company, wether that be hardware or software. If you read your private email on a corporate asset, or enable sign-on with a corporate credential, all data can and should be inspected by your corporation. The fact that companies don't MitM _everything_ is what's surprising.
Convenience is cool, the fact that one or more third parties has control of your account on the saas service is less cool
also not so hot that it's used for login and information sharing. I had an experience where I read the oauth permissions carefully on a first login, and then on a subsequent login the app included contacts in the permission set. I noticed it too late. Super shady & I'll never use oauth personally again.
I was notified about the Apr 14 deadline by trello twice on both my personal (not connected to org in any way) and work email:
- on Jan, 30;
- on Feb, 29.
As much as I hate Atlassian for their other products this seems like a responsible timeline for such kind of change.
But you created the problem in the first place by adding your work email to an account that had your personal boards in it. By doing that you gave your employer a means of controlling that account. You basically planted a time bomb that could go off at some unpredictable time in the future. And it went off.
HE didn't “plant a time bomb”; Atlassian ripped him off, plain and simple.
(Oh, sure, you could argue that he “planted a time bomb” by giving Atlassian the means — that email address — to rip him off... But please don't. That would be like arguing that a rape victim “planted a time bomb” be dressing too provocatively.)
Depending on the jurisdiction, if one suffers money damages as a result of the unapproved transfer Trello or its business clients may be exposed to liability. Also, I imagine there may be privacy or consumer protection laws that could apply too even in the absence of money damages.
While I understand, the pain - I sympathize: please note that no permissions management system (or identity and authentication is so perfect that every case can be handled perfectly). As others say, you should have verified spent a bit of time to cleanup - because at the end - you lose time/money/whatever.
In the worst case, any company or even govt can just say sorry or some credits.
Even if the company is to blame 99 % you need to take 1 % responsibility.
See: Github - where you can SSO into your organization's repositories but this is completely separate from your personal repositories.
Clearly understand what "implication"? From what I can see, all Atlassian knows is that there is an account with two email addresses attached to it. They have no way of knowing which email belongs to the "right" owner of the account. That's something the two parties involved--the two owners of the two emails--need to work out between them, and then give Atlassian a common response.
They created this system that allowed AcmeCorp to change a setting and subsequently lock an ex employee out of non-organisation data. They know which of this accounts content is related to the organisation, they allow using a single identity for both private and corporate use cases at the same time. That's a use case their user facing interface actively encouraged. When I left the last company using Trello that distinction was pretty clear cut when I removed ties to the organisation.
The linked thread reads like deliberate design decisions that turned out to be user hostile in favour of AcmeCorp. You don't have to assign a correct owner. Their data model seems pretty clear cut on which parts of an account are owned by which identity. If they develop a system that allows me to login via a private and a corporate email, have a data model that allows them to determine data ownership for the two, and yet decide to give one of those identities leverage over the other - it's okay to at least blame them partially. There's three parties involved here, none of them did everything correctly but only one had negative impact from this.
This seems to me to be the root of the problem, because to me this is obviously a bad idea and should be actively discouraged, if not prohibited altogether. If Atlassian, or some predecessor owner of Trello, did actively encourage this, then I agree they bear some culpability.
In theory I actually prefer this data model, one identity (because that's the physical reality) and a sane perspective model on who owns what data this identity has access to. But sadly nobody seems to have time to get that right in a mixed B2C/B2B product.
Edit: you can't say what they did deliberately or not. They're doing what makes the most sense for their business. Almost no support team I know would give you access to this account.
- add your person email
- get fired and login with that email and now have all the data
Considering that it would be an invasion of privacy and confidentiality for Atlassian to access the content of the board to assess which one is corporate and which one is personal, Atlassian to the safer approach to satisfy a paying client.
Consider that as a free user, with no advertising to monetize you, one could guess that Trello used you for advetising (Unless you are a paying user for your personal account, that could change the story).
Of course I am not big fan of the approach, because the user probably linked personnal and work account for convenience, and that trello probably didn't make it easy to make the switch between work and personal.
On the other hand, how do you prove that an email address is a personal one ?
When you did this, was the Trello account used for just your work with that employer? Or for both work and your personal stuff? Or just your personal stuff?
[Edit: I see from your response elsewhere in this discussion that it's the second of the options above. I'll respond further in that subthread.]
but again, to play devil's advocate, Gmail do offer professional account part of the G Suite. Without knowing your work history, it would be difficult to know if the Gmail address is also not a "professional one".
On another hand do you think notification would have solved the issue ? And wouldn't a more malicious employee just delete all the boards if they did not part with their previous company on good term.
Obviously I don't know everything from the story. And my assertions are very far from the truth. I am trying to understand what would motivate such a decision (beside the obvious Atlassian is a heartless money-grabbing company that rot everything it touches)
Don’t connect your personal stuff to your work stuff. That’s messed me up more than once — lesson learned, painfully.
Should you lose your account over that?
This person’s warning email probably ended up in spam.
In general I’m not sure the best way Atlassian could have handled this. The recent upgrade to move @company.com accounts into having a better security posture and control by the administration of the company does make sense.
Perhaps the person’s account should have just been disabled entirely until they removed either their personal email or @company.com email from the account to choose which way they wanted to go... That might have been the best solution to both protect corporate security and also the individual.
As far as I'm aware, Trello didn't actually have one email marked as more important in any way. Although they absolutely should have.
I still think Atlassian should have been able to predict this situation, and should not have considered it acceptable.
Once you attach an email you don't control to the account--like your work email that your employer controls--then it isn't "your" account any more. You have given someone else a means of controlling it. The solution is to not do that.
It's now the team of Trello lawyers, AND the team of ACME company lawyers, against Sole Person and their lawyers.
From Trello's perspective, that is much more of a winnable battle then Trello V Person V ACME.
If you're likely to be sued by the loser on the side of a battle, get sued by the one with a smaller warchest.