Let's Encrypt certification authority admitted over the weekend that it accidentally revealed thousands of e-mail addresses to its users.
Josh Aas, executive director of the Internet Security Research Group (ISRG), apologized for the accidental spill of data, citing a advisory publication that the problem occurred due to an error in the Let's Encrypt subscriber email system.
The bug "accidentally added 7618 other email addresses" to an email that was sent to subscribers to notify them of a new version of the certificate authority (CA).
The result of course was disappointing and unacceptable for a security certification organization. And 7618 recipients were able to see the addresses of others who received the e-mail in a plain text format.
However, Let's Encrypt notes that the data leak could have been much worse if it had not noticed the problem, and had not reacted so quickly.
So the 7.618 emails revealed are only 1,9 percent of the users subscribed to the subscribers list. The system stopped sending e-mail before leaked 383.0000 addresses of subscribers.
Josh Aas also said that some users would be able to see more emails from others because each email contained the emails that were sent earlier than that.
George is still wondering what he is doing here….

