Edison bug allowed access to other user's email accounts

Posted:
in iOS edited May 2020
The developers behind Edison Mail have rolled back an update to the email app issued on Friday, after some users discovered a security issue in a new synchronization feature where other people's accounts were accessible.

Edison macOS


On Friday, Edison gained a new feature that allowed users of the third-party email app to synchronize their account across their Apple devices, including the Mac and iPhone. The feature synchronized "email connections" between devices, but a bug in the software led to unintended consequences.

Users were posting to social media instances where the email accounts of a complete stranger were appearing on their devices, instead of their own, as reported by The Verge. Furthermore, the accounts were appearing without requiring any authentication by the original user, with the contents being immediately available to the viewer.

At 10:50 PM PST Friday evening a security bug was introduced for a small fraction of our iOS users. We have rolled that update back. All impacted users are being logged out and will need to re-login.

-- Edison (@Edison_apps)


Ten hours after its discovery, Edison confirmed there was a flaw in the app experienced by "a small percentage of our user base." The company quickly rolled back the update, and started to contact impacted users to notify them of the incident, and the possibility someone else may have had temporary access to their email accounts.

As part of the fix, all impacted users were forcibly logged out of the app to sever any remaining connections, and required users to re-authenticate with the app.

Edison was identified in February as one of a number of apps that gathered data on its users, monitoring the contents of user messages to provide one-click buttons for actions and canned responses. In the February report, it was alleged Edison sold data to finance, travel, and e-commerce customers derived by scraping user emails.

At the time, its developers defended the scraping by claiming it ignored personal and work email, extracted only anonymous purchase information from commercial emails, and allows users to opt out of data sharing with its research project.

Comments

  • Reply 1 of 7
    chasmchasm Posts: 3,291member
    I think you'd have to be a little bit nuts at this point to carry on using Edison at this point. They collected information without your consent, they made it more difficult than necessary to opt out (and are almost certainly lying about "only scanning commercial email"), and now a serious bug compromised security further.

    When a company tells you this plainly that security is an afterthought for them, believe them.
    Rayz2016PetrolDavesvanstromcornchipmike54razorpit
  • Reply 2 of 7
    mac'em xmac'em x Posts: 108member
    "Edison bug allowed access to other user's email accounts"

    Who was this other user?
    randominternetpersontokyojimusvanstromcornchip
  • Reply 3 of 7
    Any publicity is good publicity?
    cornchip
  • Reply 4 of 7
    mpantonempantone Posts: 2,040member
    Any publicity is good publicity?
    "The only bad publicity is your obituary." -Harvard Lampoon
    razorpit
  • Reply 5 of 7
    cornchipcornchip Posts: 1,949member
    mac'em x said:
    "Edison bug allowed access to other user's email accounts"

    Who was this other user?
    Charissa Thompson?
  • Reply 6 of 7
    razorpitrazorpit Posts: 1,796member
    mike54 said:
    Edison mail is free, so how do apps such as this make money for the developer?
    Is it through data collection and then sell that data?
    Display ads?
    Deals with other companies for using their API (eg facebook, google) so that company gets users data?

    chasm said:
    I think you'd have to be a little bit nuts at this point to carry on using Edison at this point. They collected information without your consent, they made it more difficult than necessary to opt out (and are almost certainly lying about "only scanning commercial email"), and now a serious bug compromised security further.

    When a company tells you this plainly that security is an afterthought for them, believe them.
    I just don't get the stupidity of people. Who in their right mind would use a service like this in the first place let alone continue to use it?
Sign In or Register to comment.