Live data from Hacker News

Mailgun Security Incident and Important Customer Information

blog.mailgun.com

41–50 of 66 posts

Re: Mailgun Security Incident and Important Customer Information

#41
post #40

Earlier quoted context omitted.

Can you explain this a bit more, please? I am confused. How does ‘view_content_link’ cause a security problem?

It's the opposite. That is a link to the section of the Mandrill docs, not the Mailgun docs. The view_content_link option fixes the security problem. (In theory, anyway).

Right. I understand that having that option lets you mitigate some problem. Can anyone expand on what this option does and how it mitigates the problem? Did I miss something from the blog post?

Re: Mailgun Security Incident and Important Customer Information

#42
post #17

Earlier quoted context omitted.

Never would have occurred to me that this could be used to intercept password reset emails. Very scary.

At least it leaves a trail.. Many services state in the password reset emails that "if this was not initiated by you, ignore it", but it really should be the exact opposite - click the link below to report it!

My guess is they don't do this because somebody decided it would confuse users to have more than one link.

Re: Mailgun Security Incident and Important Customer Information

#43
post #40

Earlier quoted context omitted.

It's the opposite. That is a link to the section of the Mandrill docs, not the Mailgun docs. The view_content_link option fixes the security problem. (In theory, anyway).

Right. I understand that having that option lets you mitigate some problem. Can anyone expand on what this option does and how it mitigates the problem? Did I miss something from the blog post?

Sure -- AFAIK the problem was that Mailchimp was hacked, and the hacker was able to see and intercept the password reset links being sent to the customer by looking at Mailchimp log data. This option indicates that links should not be stored in log data, so even if an attacker has compromised your Mandrill account, they should be unable to see the exact reset links that are being sent.

edit: worth noting that there are obviously other ways a hacked Mandrill/Mailchimp account could be abused. This just shuts down one of the major abuses you could perform.

Re: Mailgun Security Incident and Important Customer Information

#44

When I get spam email, I usually check the headers and if it's coming from a reputable service (Postmark, Sendgrid, etc.) they usually have a web form or an abuse@ email to send the headers to so that they can shut down the account. Months ago I received spam from a Mailgun server and tried to use their web form[1] to report it, but it was broken. I reported both that bug and the spam email to their support, which ac…

> I've been very happy with Postmark.

Postmark's service is great but their new min $10/month pricing scheme is a retrograde step and penalises small companies sending less than 1000 emails a month.

Deeply unhappy with the change, and wish more companies would follow the Amazon AWS pricing model.

Re: Mailgun Security Incident and Important Customer Information

#45
post #43

Earlier quoted context omitted.

Right. I understand that having that option lets you mitigate some problem. Can anyone expand on what this option does and how it mitigates the problem? Did I miss something from the blog post?

Sure -- AFAIK the problem was that Mailchimp was hacked, and the hacker was able to see and intercept the password reset links being sent to the customer by looking at Mailchimp log data. This option indicates that links should not be stored in log data, so even if an attacker has compromised your Mandrill account, they should be unable to see the exact reset links that are being sent. edit: worth noting that there a…

Thanks. I did indeed miss critical parts of the post. I will review again.

Re: Mailgun Security Incident and Important Customer Information

#46
post #19
post #4

This was used to steal bitcoin cash tips on Reddit by hijacking password reset emails ( https://www.reddit.com/r/bugs/comments/7obxkb/mailgun_securi... ) I find it amusing they still have a "trusted by Reddit" blurb on their homepage after this!

This is a new class of attack. Instead of spear-phishing, it's spear-hacking. It looks like the target was "bitcoin-ish tipped into /u/someredditor" and the hack/vuln was "intercept mail password resets in order to auth account in order to snatch crypto-currency" ie: most people's reddit accounts (IMHO) are on the "not that important" on the scale of password protection. (Personal Email/Financial => Work => Medium Se…

"I can choose to use reddit or not, but I can't choose that reddit uses or doesn't use some other random service provider that may or may not be vulnerable." Which is similar to the same problem we all face of 'I can choose to work for company x' but I cant choose that they farm out background checks, HR, payroll, benefits etc. to random companies that may or may not be secure.

Re: Mailgun Security Incident and Important Customer Information

#47

Earlier quoted context omitted.

I don't believe this would even be an issue if they offered the option to not log sensitive data. I had requested that they provide something like this and someone quite senior reached out to me. He was very polite and professional. He explained that they had to keep this data for operational and compliance reasons and that all email providers are required to. However, that didn't resolve my security concern. We ende…

More and more "compliance" is an IT industry excuse for "because we want to."

[deleted]

Re: Mailgun Security Incident and Important Customer Information

#48
post #43

Earlier quoted context omitted.

Right. I understand that having that option lets you mitigate some problem. Can anyone expand on what this option does and how it mitigates the problem? Did I miss something from the blog post?

Sure -- AFAIK the problem was that Mailchimp was hacked, and the hacker was able to see and intercept the password reset links being sent to the customer by looking at Mailchimp log data. This option indicates that links should not be stored in log data, so even if an attacker has compromised your Mandrill account, they should be unable to see the exact reset links that are being sent. edit: worth noting that there a…

Mailgun, not Mailchimp.

Those are two entirely separate companies (unlike Mandrill and Mailchimp which is the same company.)

Re: Mailgun Security Incident and Important Customer Information

#49
post #17

Earlier quoted context omitted.

At least it leaves a trail.. Many services state in the password reset emails that "if this was not initiated by you, ignore it", but it really should be the exact opposite - click the link below to report it!

My guess is they don't do this because somebody decided it would confuse users to have more than one link.

And it also goes against the standard advice of never clicking on anything in an email.

Re: Mailgun Security Incident and Important Customer Information

#50

Earlier quoted context omitted.

I don't believe this would even be an issue if they offered the option to not log sensitive data. I had requested that they provide something like this and someone quite senior reached out to me. He was very polite and professional. He explained that they had to keep this data for operational and compliance reasons and that all email providers are required to. However, that didn't resolve my security concern. We ende…

More and more "compliance" is an IT industry excuse for "because we want to."

Honest question, why would you "want to" adhere to compliance? It's almost always more work and more cost, I think.
Post reply on HN