Closed AlgorithmExperiments closed 2 months ago
I am experiencing this bug now. I login and get notes written in cyrillic by some Dmitry. I don't even want to think about what would happen if anyone gets my notes. Whose responsibility is this?! Fix this ASAP
Related support forum thread:
🔗 https://forums.simplenote.com/forums/topic/simplenote-security-breach-tonight/
Thanks for the reports, y'all, and sorry for the mix-up. This has been addressed.
⚠IDENTITY MIX-UP / SESSION MISROUTING / USER DATA CROSSOVER ISSUE
Priority: likely
P0
issue Affecting: Actively affecting browser sessions (using manual user/password login option) at app.simplenote.com Upon login, user sessions for electron web app are currently fetching the incorrect user's data for some users. First noticed Aug 16 2024, and saw another user also posted an alert earlier today on the simplenote help forums.Expected
User is shown their own user data upon login
Observed
❗ User is shown the wrong user's data (including wrong email address) upon login, with full access to all of that user's private notes. Immediately logged out of web app, used mobile app to export all personal data (Android session data still seemed intact), then used mobile app to delete account.
Reproduced
📸 screenshots omitted to preserve user's privacy - redacted photo proof available upon request
Where did you see the bug