Live data from Hacker News

Mailgun Security Incident and Important Customer Information

blog.mailgun.com

11–20 of 66 posts

Re: Mailgun Security Incident and Important Customer Information

#11
post #9
post #3

> Finally, we’d like to assure our customers and partners that we take security at Mailgun very seriously. So very seriously that they don't even use https for their blog...

Wow, the certificate isn't even valid...

Well, it's for the wrong domain. Because they don't use SSL on their blog.

Re: Mailgun Security Incident and Important Customer Information

#12
post #3

> Finally, we’d like to assure our customers and partners that we take security at Mailgun very seriously. So very seriously that they don't even use https for their blog...

Former mailgun customer. Asked them to delete my personal data a couple of weeks ago (I was not able to do it myself... ) because I would rather they don't leak it in a security hiccup. They kindly refused to do so (as I don't believe any tech support can be that incompetent) and kept spamming my inbox instead. While the severity of this incident is not clear, never imagined curses can act on such a short notice.

Re: Mailgun Security Incident and Important Customer Information

#13
Why would employees need access to client API keys, as opposed to just client ID?

Furthermore, this seems to indicate that the API keys are not hashed. I would expect some bits of the API key to work as an identifier and the rest of the bits treated as secret material (properly hashed).

As a Mailgun customer, this is concerning..

Re: Mailgun Security Incident and Important Customer Information

#14
post #12
post #3

> Finally, we’d like to assure our customers and partners that we take security at Mailgun very seriously. So very seriously that they don't even use https for their blog...

Former mailgun customer. Asked them to delete my personal data a couple of weeks ago (I was not able to do it myself... ) because I would rather they don't leak it in a security hiccup. They kindly refused to do so (as I don't believe any tech support can be that incompetent) and kept spamming my inbox instead. While the severity of this incident is not clear, never imagined curses can act on such a short notice.

Hi there,

This is Chris from the Mailgun team. I'm sorry that this happened, this shouldn't have been the case. I'd be happy to help rectify this issue, would you be able to send an email to help@mailgun.com with details so I can review?

Re: Mailgun Security Incident and Important Customer Information

#15
post #4

This was used to steal bitcoin cash tips on Reddit by hijacking password reset emails ( https://www.reddit.com/r/bugs/comments/7obxkb/mailgun_securi... ) I find it amusing they still have a "trusted by Reddit" blurb on their homepage after this!

On 12/31, Reddit received several reports regarding password reset emails that were initiated and completed without the account owners’ requests.

We have been working to investigate the issue and coordinating with Mailgun, a third-party vendor we’ve been using to send some of our account emails including password reset emails. A malicious actor targeted Mailgun and gained access to Reddit’s password reset emails. The nature of the exploit meant that an unauthorized person was able to access the contents of the reset email. This individual did not have access to either Reddit’s systems or to a redditor’s email account.

As an immediate precautionary measure, we moved reset emails to an in-house mail server soon after we determined reset links were indeed being clicked without access to the user's email, and before Mailgun had confirmed to us that they were vulnerable. We know this is frustrating as a user, and we have put additional controls in place to help make sure it doesn’t happen again.

We are continuing to work with Mailgun to make sure we have identified all impacted accounts. At this time, the overall number of confirmed impacted users is less than twenty. For those affected, we have resolved the issue and assisted in account recovery.

Additional information about Mailgun’s security incident can be found on its blog here. We’re committed to keeping your Reddit account safe and will continue to monitor this situation carefully. u/sodypop, u/KeyserSosa, and I will be sitting around in the comments for any general questions.

Re: Mailgun Security Incident and Important Customer Information

#16
post #4

This was used to steal bitcoin cash tips on Reddit by hijacking password reset emails ( https://www.reddit.com/r/bugs/comments/7obxkb/mailgun_securi... ) I find it amusing they still have a "trusted by Reddit" blurb on their homepage after this!

Never would have occurred to me that this could be used to intercept password reset emails. Very scary.

Re: Mailgun Security Incident and Important Customer Information

#17
post #4

This was used to steal bitcoin cash tips on Reddit by hijacking password reset emails ( https://www.reddit.com/r/bugs/comments/7obxkb/mailgun_securi... ) I find it amusing they still have a "trusted by Reddit" blurb on their homepage after this!

Never would have occurred to me that this could be used to intercept password reset emails. Very scary.

At least it leaves a trail..

Many services state in the password reset emails that "if this was not initiated by you, ignore it", but it really should be the exact opposite - click the link below to report it!

Re: Mailgun Security Incident and Important Customer Information

#18
post #12
post #3

> Finally, we’d like to assure our customers and partners that we take security at Mailgun very seriously. So very seriously that they don't even use https for their blog...

Former mailgun customer. Asked them to delete my personal data a couple of weeks ago (I was not able to do it myself... ) because I would rather they don't leak it in a security hiccup. They kindly refused to do so (as I don't believe any tech support can be that incompetent) and kept spamming my inbox instead. While the severity of this incident is not clear, never imagined curses can act on such a short notice.

This is because Mailgun is in the practice of spam. The number of spam campaigns I've seen with Mailgun as the conduit is high, second only to Mailchimp.

Re: Mailgun Security Incident and Important Customer Information

#19
post #4

This was used to steal bitcoin cash tips on Reddit by hijacking password reset emails ( https://www.reddit.com/r/bugs/comments/7obxkb/mailgun_securi... ) I find it amusing they still have a "trusted by Reddit" blurb on their homepage after this!

This is a new class of attack. Instead of spear-phishing, it's spear-hacking.

It looks like the target was "bitcoin-ish tipped into /u/someredditor" and the hack/vuln was "intercept mail password resets in order to auth account in order to snatch crypto-currency"

ie: most people's reddit accounts (IMHO) are on the "not that important" on the scale of password protection. (Personal Email/Financial => Work => Medium Security [facebook, amazon, etc] => Low Security [discussion forums])

It's another way of saying that I would expect phpBB or reddit or pinterest to have lower password/server security than my gmail or bank websites.

However, because reddit is relatively high profile, and there was mixing of "cash and reddit", all of a sudden not just reddit was target of a hacking attack, but also reddit's 3rd party service providers.

I can choose to use reddit or not, but I can't choose that reddit uses or doesn't use some other random service provider that may or may not be vulnerable.

Re: Mailgun Security Incident and Important Customer Information

#20
When I get spam email, I usually check the headers and if it's coming from a reputable service (Postmark, Sendgrid, etc.) they usually have a web form or an abuse@ email to send the headers to so that they can shut down the account.

Months ago I received spam from a Mailgun server and tried to use their web form[1] to report it, but it was broken. I reported both that bug and the spam email to their support, which acknowledged it. Weeks later I got another spam email from that same domain, popped open that report form and it was still broken (FWIW as of today it seems to be working again). So I followed up on my initial support request with that info but got no response. Just a few days ago I received another spam message from that domain.

I personally consider all that a very bad sign in an email service provider and wouldn't use Mailgun myself. In contrast, I've been very happy with Postmark.

[1]: https://www.mailgun.com/receiving-spam-from-mailgun

Post reply on HN