Live data from Hacker News

SendGrid isn’t emailing about ICE or BLM – it’s a phishing attack

fredbenenson.com

141–150 of 152 posts

Re: SendGrid isn’t emailing about ICE or BLM – it’s a phishing attack

#141
I get a flood of these every single day. Because we use SendGrid as a critical part of our product, I have to look for any emails from them pretty closely. It’s gotten impossible to do with all of these phishing attempts. I gotta hand it to them, though, the attempts are excellent.

Re: SendGrid isn’t emailing about ICE or BLM – it’s a phishing attack

#142

It would be good to hold carriers accountable for fishing and spam. Sendgrid , Twilio and other saas messaging carriers need to do a better job with integrity. I don’t expect them to carry the whole burden, but some negative incentive to promote investment . It could be as simple as enforcing sender pays metering . We all know spam is 60+ % of traffic, so sender pays would drive down spam very quickly

SendGrid and their competitors are already the very definition of “sender pays” for email. “Sender pays” is how they make money. This isn’t a problem of monetary incentives.

The problem is that companies get their SendGrid credentials compromised via password re-use or phishing.

Re: SendGrid isn’t emailing about ICE or BLM – it’s a phishing attack

#143

It would be good to hold carriers accountable for fishing and spam. Sendgrid , Twilio and other saas messaging carriers need to do a better job with integrity. I don’t expect them to carry the whole burden, but some negative incentive to promote investment . It could be as simple as enforcing sender pays metering . We all know spam is 60+ % of traffic, so sender pays would drive down spam very quickly

SendGrid and their competitors are already the very definition of “sender pays” for email. “Sender pays” is how they make money. This isn’t a problem of monetary incentives. The problem is that companies get their SendGrid credentials compromised via password re-use or phishing.

I mean the carrier pays the recipient , so Twilio and sendgrid bear some cost

Re: SendGrid isn’t emailing about ICE or BLM – it’s a phishing attack

#145

Earlier quoted context omitted.

SendGrid and their competitors are already the very definition of “sender pays” for email. “Sender pays” is how they make money. This isn’t a problem of monetary incentives. The problem is that companies get their SendGrid credentials compromised via password re-use or phishing.

I mean the carrier pays the recipient , so Twilio and sendgrid bear some cost

They understood just fine. But because that cost passes through to the sendgrid customer, it wouldn't motivate sendgrid to stop enabling spam.

Re: SendGrid isn’t emailing about ICE or BLM – it’s a phishing attack

#146

Earlier quoted context omitted.

Still absurd that "free" "democratic" elections are allowed to require party membership, even for the primary.

What's the purpose of a primary election? It's to select a party's candidate for a general election. It's not very obvious that this should even be a democratic process, but if it is, why shouldn't party members be the ones selecting their own candidates?

It's funded by tax dollars, and regulated by local and state laws.

If they want their own private primaries, then it should happen internally and at the parties' own expense.

Re: SendGrid isn’t emailing about ICE or BLM – it’s a phishing attack

#147

Earlier quoted context omitted.

I mean the carrier pays the recipient , so Twilio and sendgrid bear some cost

They understood just fine. But because that cost passes through to the sendgrid customer, it wouldn't motivate sendgrid to stop enabling spam.

currently the costs are too low to affect policy. that's my point. and the recipients are making extremely high margins on ads, so they don't have much reason to push back, either.

Re: SendGrid isn’t emailing about ICE or BLM – it’s a phishing attack

#148

Earlier quoted context omitted.

They understood just fine. But because that cost passes through to the sendgrid customer, it wouldn't motivate sendgrid to stop enabling spam.

currently the costs are too low to affect policy. that's my point. and the recipients are making extremely high margins on ads, so they don't have much reason to push back, either.

For any reasonable email fee, sendgrid can continue passing it on to the customers and not care.

If you make the fee super high, then many email workflows completely break and sendgrid goes out of business.

I don't think there's a number where it does what you want and incentivizes sendgrid to be careful.

(And you might say to seek a middle ground, but I don't think there is one. My guess is that "too low for sendgrid to care much more about a couple percent of mail from hacked accounts" and "too high for sendgrid to still attract customers" probably overlap.)

Re: SendGrid isn’t emailing about ICE or BLM – it’s a phishing attack

#149

Earlier quoted context omitted.

currently the costs are too low to affect policy. that's my point. and the recipients are making extremely high margins on ads, so they don't have much reason to push back, either.

For any reasonable email fee, sendgrid can continue passing it on to the customers and not care. If you make the fee super high, then many email workflows completely break and sendgrid goes out of business. I don't think there's a number where it does what you want and incentivizes sendgrid to be careful. (And you might say to seek a middle ground, but I don't think there is one. My guess is that "too low for sendgri…

spam volume is 10000x-1e6x higher rate, so even small fees would impact them much higher than legit senders.

Re: SendGrid isn’t emailing about ICE or BLM – it’s a phishing attack

#150

Earlier quoted context omitted.

For any reasonable email fee, sendgrid can continue passing it on to the customers and not care. If you make the fee super high, then many email workflows completely break and sendgrid goes out of business. I don't think there's a number where it does what you want and incentivizes sendgrid to be careful. (And you might say to seek a middle ground, but I don't think there is one. My guess is that "too low for sendgri…

spam volume is 10000x-1e6x higher rate, so even small fees would impact them much higher than legit senders.

These are the accounts of legit senders being coopted to send very targeted spam. I don't think you can distinguish it by volume, because the volume needed to make these schemes work is just a fraction of the basically-legitimate volume these services process.

The real bulk bulk spam is a different issue entirely.

Post reply on HN