Live data from Hacker News

Mailgun Security Incident and Important Customer Information

blog.mailgun.com

51–60 of 66 posts

Re: Mailgun Security Incident and Important Customer Information

#51
post #50

Earlier quoted context omitted.

More and more "compliance" is an IT industry excuse for "because we want to."

Honest question, why would you "want to" adhere to compliance? It's almost always more work and more cost, I think .

The cost of paying fines for non compliance would be more.

Re: Mailgun Security Incident and Important Customer Information

#52

When I get spam email, I usually check the headers and if it's coming from a reputable service (Postmark, Sendgrid, etc.) they usually have a web form or an abuse@ email to send the headers to so that they can shut down the account. Months ago I received spam from a Mailgun server and tried to use their web form[1] to report it, but it was broken. I reported both that bug and the spam email to their support, which ac…

Postmark costs money, Mailgun does not.

The free tier of Mailgun has significant delivery problems because those servers have a poor spam reputation.

Re: Mailgun Security Incident and Important Customer Information

#53
post #4

This was used to steal bitcoin cash tips on Reddit by hijacking password reset emails ( https://www.reddit.com/r/bugs/comments/7obxkb/mailgun_securi... ) I find it amusing they still have a "trusted by Reddit" blurb on their homepage after this!

On 12/31, Reddit received several reports regarding password reset emails that were initiated and completed without the account owners’ requests. We have been working to investigate the issue and coordinating with Mailgun, a third-party vendor we’ve been using to send some of our account emails including password reset emails. A malicious actor targeted Mailgun and gained access to Reddit’s password reset emails. The…

Carefully filed in an almost unread subreddit rather than in /r/announcements where it would be seen by everyone.

Re: Mailgun Security Incident and Important Customer Information

#55
I like Mailgun so much because of its simplicity but last November 2017 the default postmaster account of one of our domain in Mailgun was hacked. (I don't know where it was hacked but i suspect it was on the Mailgun server because I kept the secret key in my server very well). We moved to Sendgrid because my account in Mailgun got a very bad reputation. One of the hacked smtp credentials was used to send spam.

Re: Mailgun Security Incident and Important Customer Information

#56
post #13

Why would employees need access to client API keys, as opposed to just client ID? Furthermore, this seems to indicate that the API keys are not hashed. I would expect some bits of the API key to work as an identifier and the rest of the bits treated as secret material (properly hashed). As a Mailgun customer, this is concerning..

As a former Rackspace employee, I had access to every customer secret IN PLAIN TEXT through multiple web-based systems with a click of a button (IE: business as usual).

Re: Mailgun Security Incident and Important Customer Information

#57
post #21

Er, can we expect more information to follow? 1. How was the employee's account accessed? No 2FA? 2. Do employees ordinarily have access to customer secrets (e.g. API keys) or was there some further exploit? 3. The advice in OP for affected customers is to roll keys and SMTP logins. Couldn't/shouldn't you do that for them? Surely security should trump up-time/deliverability?

All Rackspace employees are issued hardware or software RSA tokens and a VPN client.

I seriously suspect this was the job of an insider, not a compromised employee laptop.

Re: Mailgun Security Incident and Important Customer Information

#58

Earlier quoted context omitted.

Postmark is free up to 100 mails / month. But mail deliverability issues are a hell that I'm happy to pay a small fee to avoid.

Do they have an overage charge for the free 100/month, like the 1.25/1000 they list for their non-free use? So you could be free most of the time with the occasional 1.25 charge if you have a busy month?

Unfortunately I don't think so. :(

> We offer a Free Trial plan for testing purposes only. The Trial is limited to 100 emails a month with no overages allowed.

https://postmarkapp.com/support/article/1107-how-does-monthl...

Re: Mailgun Security Incident and Important Customer Information

#59
post #44

When I get spam email, I usually check the headers and if it's coming from a reputable service (Postmark, Sendgrid, etc.) they usually have a web form or an abuse@ email to send the headers to so that they can shut down the account. Months ago I received spam from a Mailgun server and tried to use their web form[1] to report it, but it was broken. I reported both that bug and the spam email to their support, which ac…

> I've been very happy with Postmark. Postmark's service is great but their new min $10/month pricing scheme is a retrograde step and penalises small companies sending less than 1000 emails a month. Deeply unhappy with the change, and wish more companies would follow the Amazon AWS pricing model.

I didn't realize the new monthly plans were required for new accounts - that's unfortunate. I'm still on the old credits system (grandfathered I guess).

Re: Mailgun Security Incident and Important Customer Information

#60
post #25
post #3

> Finally, we’d like to assure our customers and partners that we take security at Mailgun very seriously. So very seriously that they don't even use https for their blog...

Come on, Mailgun. Let's Encrypt is free and takes less than 5 minutes to set up (using certbot).

Yea, I've been able to forget how painful getting SSL setup and configured used to be since letsencrypt + certbot came along.

Automating that crap in ansible is almost too easy.

Post reply on HN