Live data from Hacker News

Mailgun Security Incident and Important Customer Information

blog.mailgun.com

21–30 of 66 posts

Re: Mailgun Security Incident and Important Customer Information

#21
Er, can we expect more information to follow?

1. How was the employee's account accessed? No 2FA?

2. Do employees ordinarily have access to customer secrets (e.g. API keys) or was there some further exploit?

3. The advice in OP for affected customers is to roll keys and SMTP logins. Couldn't/shouldn't you do that for them? Surely security should trump up-time/deliverability?

Re: Mailgun Security Incident and Important Customer Information

#22

When I get spam email, I usually check the headers and if it's coming from a reputable service (Postmark, Sendgrid, etc.) they usually have a web form or an abuse@ email to send the headers to so that they can shut down the account. Months ago I received spam from a Mailgun server and tried to use their web form[1] to report it, but it was broken. I reported both that bug and the spam email to their support, which ac…

Postmark costs money, Mailgun does not.

Re: Mailgun Security Incident and Important Customer Information

#23

When I get spam email, I usually check the headers and if it's coming from a reputable service (Postmark, Sendgrid, etc.) they usually have a web form or an abuse@ email to send the headers to so that they can shut down the account. Months ago I received spam from a Mailgun server and tried to use their web form[1] to report it, but it was broken. I reported both that bug and the spam email to their support, which ac…

Postmark costs money, Mailgun does not.

Postmark is free up to 100 mails / month. But mail deliverability issues are a hell that I'm happy to pay a small fee to avoid.

Re: Mailgun Security Incident and Important Customer Information

#24
post #4

This was used to steal bitcoin cash tips on Reddit by hijacking password reset emails ( https://www.reddit.com/r/bugs/comments/7obxkb/mailgun_securi... ) I find it amusing they still have a "trusted by Reddit" blurb on their homepage after this!

I don't believe this would even be an issue if they offered the option to not log sensitive data. I had requested that they provide something like this and someone quite senior reached out to me. He was very polite and professional. He explained that they had to keep this data for operational and compliance reasons and that all email providers are required to. However, that didn't resolve my security concern.

We ended up going with Mandrill which does offer the option to not log sensitive data ^1. Whether they log it somewhere else for the compliance reasons that Mailgun mentioned isn't mentioned anywhere in their docs or privacy policy, but doesn't seem to be accessible from everything I could find. You should never log or allow others to log password reset urls or other sensitive details.

1: See documentation here: https://mandrillapp.com/api/docs/messages.JSON.html#method-s... and search view_content_link

Re: Mailgun Security Incident and Important Customer Information

#25
post #3

> Finally, we’d like to assure our customers and partners that we take security at Mailgun very seriously. So very seriously that they don't even use https for their blog...

Come on, Mailgun.

Let's Encrypt is free and takes less than 5 minutes to set up (using certbot).

Re: Mailgun Security Incident and Important Customer Information

#26

When I get spam email, I usually check the headers and if it's coming from a reputable service (Postmark, Sendgrid, etc.) they usually have a web form or an abuse@ email to send the headers to so that they can shut down the account. Months ago I received spam from a Mailgun server and tried to use their web form[1] to report it, but it was broken. I reported both that bug and the spam email to their support, which ac…

Postmark is really nice indeed, even though a bit on the pricey side.

Still, I can recommend their free tool to monitor DMARC: https://dmarc.postmarkapp.com/

Re: Mailgun Security Incident and Important Customer Information

#27
post #4

This was used to steal bitcoin cash tips on Reddit by hijacking password reset emails ( https://www.reddit.com/r/bugs/comments/7obxkb/mailgun_securi... ) I find it amusing they still have a "trusted by Reddit" blurb on their homepage after this!

I don't believe this would even be an issue if they offered the option to not log sensitive data. I had requested that they provide something like this and someone quite senior reached out to me. He was very polite and professional. He explained that they had to keep this data for operational and compliance reasons and that all email providers are required to. However, that didn't resolve my security concern. We ende…

More and more "compliance" is an IT industry excuse for "because we want to."

Re: Mailgun Security Incident and Important Customer Information

#28
In those security disclosures, I often read what I see as contradictory language.

For example, I'm confused by this kind of statement:

> Mailgun has now completed its diagnostic of accounts that were affected and has notified each of the affected users. At this time, we believe less than 1% of our customer base was potentially affected. If you were not directly notified by Mailgun regarding this incident, then your account was not affected.

If you believe that less than 1% of users were affected, it means you don't know for sure how many accounts were affected.

From there, how can you state that "If you were not directly notified by Mailgun regarding this incident, then your account was not affected"?

Doesn't this last statement mean you know for sure my account was not affected? Isn't it in direct contradiction with the previous statement?

Re: Mailgun Security Incident and Important Customer Information

#29

In those security disclosures, I often read what I see as contradictory language. For example, I'm confused by this kind of statement: > Mailgun has now completed its diagnostic of accounts that were affected and has notified each of the affected users. At this time, we believe less than 1% of our customer base was potentially affected. If you were not directly notified by Mailgun regarding this incident, then your a…

Foremost, it was written by a human and unintended language contradictions are common. With that said, what you're suggesting isn't necessarily true -- the language can also indicate potential false positives, again because of the nuances of language.

Re: Mailgun Security Incident and Important Customer Information

#30

In those security disclosures, I often read what I see as contradictory language. For example, I'm confused by this kind of statement: > Mailgun has now completed its diagnostic of accounts that were affected and has notified each of the affected users. At this time, we believe less than 1% of our customer base was potentially affected. If you were not directly notified by Mailgun regarding this incident, then your a…

These sorts of articles always remind me of “We take security seriously”, otherwise known as “We didn’t take it seriously enough”: https://www.troyhunt.com/we-take-security-seriously-otherwis...
Post reply on HN