Sync & possible security issues

So aside from the sync issues I've been having (there are other topics on that here), I've just turned on my desktop PC and discovered something rather worrying. I have two Todoist accounts - one for work, and one for personal. I've never logged into my work account from this PC, but I've just opened my todoist tab and found 6 tasks showing as Overdue from a completely separate Todoist account. They're showing at the top of my list under an 'Undefined' project, presumably because the project they actually belong to doesn't exist in this account.

How is it possible that todos from a completely separate Todoist account are showing up in this one? Making me rather concerned about the security of the platform now as well as the inconveniences of the sync randomly breaking.

David Trey  staff
Replied on Nov 29, 2013 - 19:46 UTC

Could you please clarify what sync issues did you experience exactly? From to what platform, what data got synced and what didn't? So far, we've had one sync-related report recently and we're looking into it.

Regarding your concern, we can guarantee you that it's technically not possible that you would see data from someone else's account. There's just no way our app could do that. The only possibility would be an issue with cached data. Are you 100% certain that you have never, not even accidentally logged into the other account on this computer (using any platform, app, add-on)?

An "undefined" project can be one that's archived, for example - are you sure these tasks weren't, for example, sent via email to another project or again - the other account was accessed through a browser or add-on (some of them share the cache)?

Daryl Knight
Replied on Nov 29, 2013 - 20:18 UTC

The sync issues I've had in the last couple of days, firstly is that items created on my iPhone weren't synced to the web version. Secondly, the iPhone app was displaying an out of date number of todos still left on it's badge until I deleted the app, restarted the iPhone and reinstalled it.

I believe the project the new tasks are assigned to is "Undefined" because the project has never existed under this account. I don't email tasks (don't know how to), so they've shown up completely randomly. As you say, it must be something to do with cached data leaking into the wrong account.

It appears that the issue isn't still occuring, it's just worrying to see tasks from another account show up under this one.

David Trey  staff
Replied on Nov 29, 2013 - 20:36 UTC


Thank you for this information. In the last few days, there was indeed one issue on our end due to a server outage that might have temporarily caused syncing issue, but all should be fixed by now and everyone who experienced it before confirms that it no longer occurs.

As for the leaked data, I can assure you this could only happen if at some point you've logged into this account and then something (maybe because of the syncing issues) went wrong and the local cache got broken, but there's no way that you could ever see tasks from some other random account or that anyone else would see your tasks, this could only happen locally caused by the cache.

If you ever notice it again and remember what exact steps you've taken to trigger it, please let us know and we'll look into this.

