Live data from Hacker News

Mailgun Security Incident and Important Customer Information

blog.mailgun.com

61–66 of 66 posts

Re: Mailgun Security Incident and Important Customer Information

#61
post #4

This was used to steal bitcoin cash tips on Reddit by hijacking password reset emails ( https://www.reddit.com/r/bugs/comments/7obxkb/mailgun_securi... ) I find it amusing they still have a "trusted by Reddit" blurb on their homepage after this!

I've always been impressed that Gandi (domain registrar) let you disable password resets by email in your account preferences.

Re: Mailgun Security Incident and Important Customer Information

#62
post #21

Er, can we expect more information to follow? 1. How was the employee's account accessed? No 2FA? 2. Do employees ordinarily have access to customer secrets (e.g. API keys) or was there some further exploit? 3. The advice in OP for affected customers is to roll keys and SMTP logins. Couldn't/shouldn't you do that for them? Surely security should trump up-time/deliverability?

All Rackspace employees are issued hardware or software RSA tokens and a VPN client. I seriously suspect this was the job of an insider, not a compromised employee laptop.

MailGun has been spun out of Rackspace almost a year ago.

Re: Mailgun Security Incident and Important Customer Information

#63
post #13

Why would employees need access to client API keys, as opposed to just client ID? Furthermore, this seems to indicate that the API keys are not hashed. I would expect some bits of the API key to work as an identifier and the rest of the bits treated as secret material (properly hashed). As a Mailgun customer, this is concerning..

As a former Rackspace employee, I had access to every customer secret IN PLAIN TEXT through multiple web-based systems with a click of a button (IE: business as usual).

Thanks for confirming this. I had my suspicions, especially after the last few years of using them and just seeing massive problems that seemed to be caused by the software at Rackspace.

Re: Mailgun Security Incident and Important Customer Information

#64
post #13

Why would employees need access to client API keys, as opposed to just client ID? Furthermore, this seems to indicate that the API keys are not hashed. I would expect some bits of the API key to work as an identifier and the rest of the bits treated as secret material (properly hashed). As a Mailgun customer, this is concerning..

Agreed. Super disappointed by this (cleartext details and the breach). Will be looking to move all services from Mailgun shortly.

Re: Mailgun Security Incident and Important Customer Information

#65
post #36

Earlier quoted context omitted.

This is because Mailgun is in the practice of spam. The number of spam campaigns I've seen with Mailgun as the conduit is high, second only to Mailchimp.

To be fair, Mailgun is in the practice of sending email. It just happens to be that email is one of the main conduits of spam.

No, that's just correlation. Email can be spam, but not all email is spam.

Re: Mailgun Security Incident and Important Customer Information

#66
post #51
post #50

Earlier quoted context omitted.

Honest question, why would you "want to" adhere to compliance? It's almost always more work and more cost, I think .

The cost of paying fines for non compliance would be more.

Exactly, that's very different from "because we want to," it's, "because there's a very big stick over our heads if we don't."

I just thought the attitude/assertion was in discord with my own experience/understanding.

Post reply on HN