Certificate authority Let's Encrypt admitted over the weekend that it accidentally exposed thousands of its users' email addresses.
Josh Aas, executive director of the Internet Security Research Group (ISRG), apologized for the accidental data leak, stating in an advisory that the problem that occurred was due to a bug in Let's Encrypt's subscriber email system.
The bug “accidentally added 7618 other email addresses” to an email that was supposed to be sent to subscribers to notify them of a new certificate authority (CA) release.
The result was of course disappointing and unacceptable for a security certificate issuing organization. All 7618 recipients were able to see the addresses of others who received the email in plain text.
However, Let's Encrypt notes that the data leak could have been much worse if it had not noticed the problem, and had not reacted so quickly.
So the 7,618 email addresses exposed represent only 1.9 percent of the users on the subscriber list. The system stopped sending emails before all 383,000 subscriber addresses were leaked.
Mr. Josh Aas also mentioned that some users would be able to see more email addresses than others, because each email contained the email addresses that were sent earlier than it.
