This was used to steal bitcoin cash tips on Reddit by hijacking password reset emails ( https://www.reddit.com/r/bugs/comments/7obxkb/mailgun_securi... ) I find it amusing they still have a "trusted by Reddit" blurb on their homepage after this!
Mailgun Security Incident and Important Customer Information
61–66 of 66 posts
Re: Mailgun Security Incident and Important Customer Information
#62Er, can we expect more information to follow? 1. How was the employee's account accessed? No 2FA? 2. Do employees ordinarily have access to customer secrets (e.g. API keys) or was there some further exploit? 3. The advice in OP for affected customers is to roll keys and SMTP logins. Couldn't/shouldn't you do that for them? Surely security should trump up-time/deliverability?
All Rackspace employees are issued hardware or software RSA tokens and a VPN client. I seriously suspect this was the job of an insider, not a compromised employee laptop.
Re: Mailgun Security Incident and Important Customer Information
#63Why would employees need access to client API keys, as opposed to just client ID? Furthermore, this seems to indicate that the API keys are not hashed. I would expect some bits of the API key to work as an identifier and the rest of the bits treated as secret material (properly hashed). As a Mailgun customer, this is concerning..
As a former Rackspace employee, I had access to every customer secret IN PLAIN TEXT through multiple web-based systems with a click of a button (IE: business as usual).
Re: Mailgun Security Incident and Important Customer Information
#64Why would employees need access to client API keys, as opposed to just client ID? Furthermore, this seems to indicate that the API keys are not hashed. I would expect some bits of the API key to work as an identifier and the rest of the bits treated as secret material (properly hashed). As a Mailgun customer, this is concerning..
Re: Mailgun Security Incident and Important Customer Information
#65Earlier quoted context omitted.
This is because Mailgun is in the practice of spam. The number of spam campaigns I've seen with Mailgun as the conduit is high, second only to Mailchimp.
To be fair, Mailgun is in the practice of sending email. It just happens to be that email is one of the main conduits of spam.
Re: Mailgun Security Incident and Important Customer Information
#66Earlier quoted context omitted.
Honest question, why would you "want to" adhere to compliance? It's almost always more work and more cost, I think .
The cost of paying fines for non compliance would be more.
I just thought the attitude/assertion was in discord with my own experience/understanding.