Security Hole in Sendgrid
11–20 of 97 posts
Re: Security Hole in Sendgrid
#12Another title for this submission could have been: "Massive Security Hole in ChunkHost. Non-2FA accounts can be owned." Because it turns out anyone with a Sendgrid Support account also effectively had potential access to any account at ChunkHost not using two-factor authentication. Which is also true of thousands of other companies that are relaying their password reset emails through third party SMTP services. SendG…
Re: Security Hole in Sendgrid
#13Send your emails yourself. It's not like it is hard. At least not harder than integrating to a third party email sender.
Re: Security Hole in Sendgrid
#14So what they are saying is that SendGrid should have had two-factor auth and this would have never happened.
Re: Security Hole in Sendgrid
#15So what's the answer? Here's two very legitimate scenarios: 1) You sign up, enable two-factor auth, then lock yourself out (lost password and your second-factor). How do you prove to the service provider that you are you? 2) You sign up, enable two-factor auth, then Mallory claims that they locked themselves out. How does the service provider prove that Mallory is not you?
Re: Security Hole in Sendgrid
#16So what's the answer? Here's two very legitimate scenarios: 1) You sign up, enable two-factor auth, then lock yourself out (lost password and your second-factor). How do you prove to the service provider that you are you? 2) You sign up, enable two-factor auth, then Mallory claims that they locked themselves out. How does the service provider prove that Mallory is not you?
In this case, looping in the original email address on the SendGrid account before changing to a new one would have kept this from happening. SendGrid's support personnel should almost certainly not be able to change an email address without the change being signed off on through the old address first.
Re: Security Hole in Sendgrid
#17Send your emails yourself. It's not like it is hard. At least not harder than integrating to a third party email sender.
Re: Security Hole in Sendgrid
#18Another title for this submission could have been: "Massive Security Hole in ChunkHost. Non-2FA accounts can be owned." Because it turns out anyone with a Sendgrid Support account also effectively had potential access to any account at ChunkHost not using two-factor authentication. Which is also true of thousands of other companies that are relaying their password reset emails through third party SMTP services. SendG…
Are there any web hosting companies that don't rely on the "send a reset link to your email address on file" model of password resets? You're right, that model is deeply broken if anyone can intercept those emails (as happened in this case), but it seems unfair to single out ChunkHost for criticism.
Re: Security Hole in Sendgrid
#19Send your emails yourself. It's not like it is hard. At least not harder than integrating to a third party email sender.
Re: Security Hole in Sendgrid
#20Send your emails yourself. It's not like it is hard. At least not harder than integrating to a third party email sender.
Yes, sending an email is easy enough. It's all the other stuff we have services like this for.