Live data from Hacker News

DocuSign email address database breached and used for phishing campaign

trust.docusign.com

91–100 of 141 posts

Re: DocuSign email address database breached and used for phishing campaign

#91
post #74
post #69

Earlier quoted context omitted.

As a general rule, if you receive an email referencing wire transfers, it's probably bogus.

Given the ratio of spam to ham, as a general rule every email is probably bogus.

Youd think that, but I never seem to get spam bug reports or feature requests. Always sex, drugs or money related it seems.

Re: DocuSign email address database breached and used for phishing campaign

#92
post #78

I would like to urge the Google team to solve one aspect of this problem, forever. It takes no more than 20 minutes to prototype and then approximately 1 day to fully test the final solution that is necessary on their end to keep compromised emails from being fully compromised addresses forever, without any chance for you to ever know at any point in the future where mail REALLY comes from. Here is a description: 1 -…

> The full and complete solution is to allow me to create a new inbox in Gmail through a single step, for example "j45rsdfjdocusign" which is linked to jsmith747 in a single direction. When hosting your own email on your own domain you get this benefit out of the box now, without waiting for google to add it for you. I've been doing this for years, each different company gets a unique email address. Real easy to see…

I realize that this took you 0 minutes to set up, but Google has 20,832 employees in Research and Development (2016 figure[1]), many, if not most, with PhD's. What might be obvious or intuitive for you and me might require them to have a team examine, do an internal publication with peer review, etc. I would prefer them to set this up but understand it takes a bit of time. Still, I think they should fast-track and get it it up. For amateurs, it's a 0-minute solution. I am sure they can do it quickly and professionally. Security by obscurity really isn't enough - someone there needs to do it. Cases like what we're reading about here show the importance of this. They're already done the bulk of the work.

[1] https://www.quora.com/How-many-software-engineers-does-Googl...

Re: DocuSign email address database breached and used for phishing campaign

#93
post #78

I would like to urge the Google team to solve one aspect of this problem, forever. It takes no more than 20 minutes to prototype and then approximately 1 day to fully test the final solution that is necessary on their end to keep compromised emails from being fully compromised addresses forever, without any chance for you to ever know at any point in the future where mail REALLY comes from. Here is a description: 1 -…

> The full and complete solution is to allow me to create a new inbox in Gmail through a single step, for example "j45rsdfjdocusign" which is linked to jsmith747 in a single direction. When hosting your own email on your own domain you get this benefit out of the box now, without waiting for google to add it for you. I've been doing this for years, each different company gets a unique email address. Real easy to see…

That solves this one issue, but now you're fully responsible for your email server's security. While this may be a feature for some, for the general (developer) public, it's a bug.

Re: DocuSign email address database breached and used for phishing campaign

#94

I'm not sure DocuSign has a full handle on what happened here yet. I received six (6) DocuSign emails, half of which used a convincing subject derived from actual DocuSign documents I have signed or processed through the system. Perhaps a coincidence? Or these hackers gained access to more than just "email addresses".

At my work we too have received dozens of phishing emails purportedly from DocuSign. Most are getting caught but a few are making it to people's inbox. Which is terrible because a lot of my coworkers use DocuSign and think nothing of clicking on a link in one of these rather convincing emails.

Re: DocuSign email address database breached and used for phishing campaign

#95
I did get an email from them which looked actually legit and opened it. It redirected me to a 404.

Is there a chance I could've been compromised in any way? I'm guessing they couldn't have gotten much more than my IP address, maybe some cookies, all my passwords, private life?

Re: DocuSign email address database breached and used for phishing campaign

#96

Earlier quoted context omitted.

With credit cards, you personally do not have much to worry about, since your card issuer holds the ultimate liability for any fraud that occurs. Just be careful to use a credit card (attached to a reversible ledger) and not a debit card (attached to a less-reversible cash account).

This is not an accurate description of the difference between credit cards and offline debit cards with regard to disputed transactions. In both cases, fraud disputes are handled in the same way. Either the issuer or the account holder suspects fraudulent transactions and the bank engages an investigation in order to determine veracity of the claim. Where things differ is that the onus of proof for credit card accoun…

It's not really that simple either. For the US, there are different paths for liability limits, reporting periods, etc, for the different combinations of credit vs debit and card-present vs card-not-present and Visa vs Mastercard. The rules are a mix of various consumer laws like "Truth in Lending" as well as Visa and MasterCard policy. There are areas where Visa and MC differ in policy.

Your note about "onus on proof lies with the cardholder" is less true for Visa, for example.

The best resource I've seen is this one: https://www.minneapolisfed.org/~/media/files/about/what-we-d... See pages 6 through 18.

Re: DocuSign email address database breached and used for phishing campaign

#98

Earlier quoted context omitted.

I do the same without using 33mail. I have my mail hosted on zoho mail which gives me infinite aliases that get redirected to my main address and in case I ever need to forward a mail from an alias I can create a new address with that alias, use it and then delete it. So when I register to a new site I usually input @mydomain.com and then if I want I can create a filter to sort them automatically

me too. any new email address is businessname@mydomain.io Already caught a few selling my info

Same. Particularly interesting when you start getting spam to massiveCreditReportingCo@mydomain.com, or who sends mail to boughtaNewCar@mydomain.com after giving that address at the car dealership.

Re: DocuSign email address database breached and used for phishing campaign

#99
post #28

> Ensure your anti-virus software is enabled and up to date Uh, really, endorsing antivirus? They could at least have written something like "Ensure your system is properly secured" if they felt they need to stress that out.

And ~90% of the recipients would think "ensure my system is properly secured? How the heck do I do that?"

Re: DocuSign email address database breached and used for phishing campaign

#100

Earlier quoted context omitted.

AliExpress does this, they don't accept "aliexpress@foo.bar". I suppose it's meant to stop you from providing "foo@aliexpress.com", implemented lazily by rejecting anything that contains the substring "aliexpress". Best response I've received when giving an email address of the form "company@mydoma.in" to a representative in person was "oh you work here too?". The concept of catch-all domains is so foreign to most la…

A catchall on my domain was all fun and games till the second dictionary spam run.

The way I get around that is by having a static keyword that must also appear on the user side of the email address.

So, if I'm dealing with Walmart, I would give them:

[keyword].walmart@example.com

or

walmart.[keyword]@example.com

Then I configure my catch-all settings to reject any email addresses that don't have that keyword.

Of course, the keyword is not secret, so it's possible for someone to infer what I'm doing and construct an email address that passes my spam check, but in practice, nobody goes through the trouble, because I'm not a big enough target.

Post reply on HN