Live data from Hacker News

DocuSign email address database breached and used for phishing campaign

trust.docusign.com

131–140 of 141 posts

Re: DocuSign email address database breached and used for phishing campaign

#131

Earlier quoted context omitted.

A catchall on my domain was all fun and games till the second dictionary spam run.

I've heard that being a problem, though I've never had that issue using a sub-domain for the catchall (company@sub.domain.tld). Some sites refuse to accept email addresses with more than one "." after the "@" but figure if they don't understand email addresses I don't want to trust them with my details (even throw-away ones) anyway so go elsewhere.

I can confirm exactly this. I started with a root catchall on my personal .com (~15 years ago), and it was quickly overwhelmed with dictionary spam. Switched to a subdomain catchall, and haven't seen a dictionary run since.

Picking a short preposition for the subdomain can even help when you have to communicate the email to a clueless phone rep: "That's right, it's yourcompany@for.myname.com"

Re: DocuSign email address database breached and used for phishing campaign

#132

Earlier quoted context omitted.

Yeah, I wound up using name-tag@domain, but because I used a dash rather than plus, I'm forever doomed to run my own mailserver. (fwiw, this domain is almost 20 years old, so that's forever in internet years)

I use my domain with FastMail, they support aliases and catch-all and lots of other nice things on custom domains. They also do DKIM, SPF, etc. So you don't have to run your own mail server if you don't want to ;) https://www.fastmail.com/help/receive/domains.html https://www.fastmail.com/help/receive/domains-setup-mxonly.h... https://www.fastmail.com/help/receive/alias-catchall.html https://www.fastmail.com/help/rec…

Fastmail uses a +, I use a -. So, either I'd have to go in and alias all of them, or give up on the useful ones.

Besides, there are 30 or so that I have black holes, from back when comment systems leaked email addresses.

Re: DocuSign email address database breached and used for phishing campaign

#133
post #77
post #73

Earlier quoted context omitted.

To do something similar as an individual, I highly recommend 33mail.com [1], which provides a generous free tier, and lets you supply arbitrary . As well as knowing where a leak originated, you can easily block any inbound email address if it is being abused. Not affiliated, just a happy long-time paying customer. [1] http://33mail.com/rj37w3

I don't know what the HN policy on referral links is, but here's a link without affiliate tracking: http://33mail.com

That isn't strictly affiliate tracking, but yes, if you're uncomfortable with 33mail.com knowing you came from HN, don't click ATsch's link, but copy and paste it instead.

Re: DocuSign email address database breached and used for phishing campaign

#134

Earlier quoted context omitted.

I do the same without using 33mail. I have my mail hosted on zoho mail which gives me infinite aliases that get redirected to my main address and in case I ever need to forward a mail from an alias I can create a new address with that alias, use it and then delete it. So when I register to a new site I usually input @mydomain.com and then if I want I can create a filter to sort them automatically

If you set up a catch-all for your domain, then you don't even need to create addresses unless you need to reply from that address.

You don't need to 'create' addresses there either, it's a catch-all on your person subdomain, but with one0click blocking.

Re: DocuSign email address database breached and used for phishing campaign

#135

Thanks Every Employer I've Had In the Past 6 Years For Putting My Email In A Service I'd Never Want Otherwise. Also Thanks Me for just using docusign w/ our employees when I was in charge.

I strictly started handing out "companyname@mypersonaldomain.tld" as email when interacting with companies. That at least makes routing the inevitable spam to the trash bin slightly easier when a breach occurs. It also provides an indicator of who has (in)voluntarily given away my data.

I do that too, so far Adobe, Dropbox and LinkedIn are my only real sources for spam (due each of these being hacked). And oddly the occasional spam to an alias I used for the crypto-discuss mailing list.

One additional twist, I keep my site-spesific aliases on a short sub-domain (for now service-or-tld@s.mytld.com) - if I feel the need in the future I can burn down the whole sub-domain, exchanging s.mytld.com for eg: m.mytld.com.

Re: DocuSign email address database breached and used for phishing campaign

#136
post #74

Earlier quoted context omitted.

Given the ratio of spam to ham, as a general rule every email is probably bogus.

Youd think that, but I never seem to get spam bug reports or feature requests. Always sex, drugs or money related it seems.

Now you've just given me new, horrifying, nightmares of the future.

----

Feature Request: Your software does not make it easy to buy drugs, money, or sex as buydrugsmoneyandsex-dot-com does. Please implement buydrugsmoneyandsex-dot-com functionality by directing users to that website through our affiliate link program: http://preview.tinyurl.com/2tx

Re: DocuSign email address database breached and used for phishing campaign

#137

Earlier quoted context omitted.

I am skeptical as well. I feel like the standard procedure these days is for a company to acknowledge that their security has been compromised but that the breach was limited to only non-sensitive data.

I'm not an expert but once you are breached I feel it's very difficult to be sure what was or was not accessed. Maybe if the system breached was air-gapped or completely third-party (e.g. a mail list provider) you can safely say "no personal information" was accessed but as a user, my trust in DocuSign is now lower no matter what they say.

I agree on both points.

Re: DocuSign email address database breached and used for phishing campaign

#138

Earlier quoted context omitted.

I strictly started handing out "companyname@mypersonaldomain.tld" as email when interacting with companies. That at least makes routing the inevitable spam to the trash bin slightly easier when a breach occurs. It also provides an indicator of who has (in)voluntarily given away my data.

Yeah, I should stop being lazy and host a personal domain again. It just is such a bad situation these days. Either you: 1. Pay a reasonable rate for a full time server in services that are just truly awful, have no redundancy options, and are associated with a lot of unsavory activity or... 2. You pay a totally unreasonable rate to host it in a more reputable cloud service. 3. You run it out of your home or office a…

I host my email at runbox, but many other providers offer catchall on custom domains. No need to host your email yourself.

Re: DocuSign email address database breached and used for phishing campaign

#139

Emails and email addresses are very different in the context of DocuSign. The former includes the text of contracts. The latter is just a list of people who have ever given or received a job offer.

Emails from DocuSign do not contain the text of the contract. They contain a link to the contract and its text. I've signed a bunch of contracts via DocuSign and that's the consistent pattern I've observed.
Post reply on HN