/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

Princeton researchers show some analytics firms are still accidentally collecting user passwords, including Mixpanel, which issued fixes after earlier findings

Lily Hay Newman / Wired :

Wired Lily Hay Newman

Context & Ripple Effects

This story closes a loop on Mixpanel's earlier password-collection episode, when the analytics vendor was found to be accidentally capturing passwords in some clients' apps from March 2017 to January 2018 and was slow to notify clients and the public. The new Princeton work shows the failure mode was not one vendor's bug but a class of defect still present across analytics firms even after Mixpanel shipped its fixes.

It also fits a broader research pattern in the corpus: academics and independent researchers repeatedly surface data leakage that companies themselves miss, from an ad agency leaving a database with 150K+ personal records open to email addresses leaking to ads and analytics firms via URL query strings.

First-order effects

  • Analytics vendors named in the findings, Mixpanel foremost, face renewed client scrutiny of their SDKs just as they were rebuilding trust after the earlier incident and its delayed disclosure.
  • Sites embedding these analytics tools must audit what their third-party scripts actually transmit, since the collection happens inside client apps without the site operator's knowledge.

Second-order effects

  • Buyers of product analytics gain leverage to demand contractual data-handling guarantees and faster breach notification, pressuring vendors whose slow disclosure in the earlier Mixpanel case became part of the story.
  • The pattern echoes adjacent exposures — Spotify resetting user passwords after a bug exposed account data to business partners — pushing companies to treat every embedded third-party script as a potential credential leak vector.

Third-order effects

  • If academic audits keep outpacing vendors' own detection, third-party analytics becomes a standing compliance liability, likely driving consolidation toward vendors that can prove data minimization rather than merely patch after publication.
  • Repeated researcher-found leaks across analytics, ads, and cleartext storage point toward structural accountability for data flows between sites and their business partners, where responsibility today is diffuse enough that each party assumes another audited it.

The trend: Independent academic auditing is becoming the de facto inspection layer for third-party data collection, repeatedly catching credential and personal-data leakage that analytics vendors' internal processes miss.