Security Hole in Sendgrid
71–80 of 97 posts
Re: Security Hole in Sendgrid
#72My first thought was to whois chunkhost.info, which returns a clear name, email address and phone number. Or is it that easy to register a domain with a fictitious persona?
Re: Security Hole in Sendgrid
#73So what they are saying is that SendGrid should have had two-factor auth and this would have never happened.
SendGrid's policy (as stated in their first email) is that the support people shouldn't be changing account emails in this fashion. Even if SendGrid had 2 factor auth, who's to say the support guy wouldn't have just disabled that?
Re: Security Hole in Sendgrid
#74Earlier quoted context omitted.
Please, no. Consider a determined attacker. A posted signed letter has zero cost and is easily forged and a phone call is free via Skype. There's plenty of low-tech ways to circumvent security.
How exactly does Skype let me take over a business's phone number? I am saying that SendGrid should call the company to verify, not the other way round.
Re: Security Hole in Sendgrid
#75So what's the answer? Here's two very legitimate scenarios: 1) You sign up, enable two-factor auth, then lock yourself out (lost password and your second-factor). How do you prove to the service provider that you are you? 2) You sign up, enable two-factor auth, then Mallory claims that they locked themselves out. How does the service provider prove that Mallory is not you?
Text message or phone verification of details only you should know about the account history, payment methods, etc. As others mentioned, a waiting period during which they try to contact using any means s previously authorised for a response. Compare IP addresses and deny logins from strange countries or origins without further verification, etc. Of course, every measure and countermeasure needs to be justified, sinc…
Re: Security Hole in Sendgrid
#76Re: Security Hole in Sendgrid
#77Earlier quoted context omitted.
SendGrid's policy (as stated in their first email) is that the support people shouldn't be changing account emails in this fashion. Even if SendGrid had 2 factor auth, who's to say the support guy wouldn't have just disabled that?
If their policy is that support staff should never be able to change an accounts email address... why does the system let them do it?
Re: Security Hole in Sendgrid
#78Another title for this submission could have been: "Massive Security Hole in ChunkHost. Non-2FA accounts can be owned." Because it turns out anyone with a Sendgrid Support account also effectively had potential access to any account at ChunkHost not using two-factor authentication. Which is also true of thousands of other companies that are relaying their password reset emails through third party SMTP services. SendG…
Re: Security Hole in Sendgrid
#79Social engineering will almost always work. I don't really fault Sendgrid for this (though I could see this not working as well if you were using Amazon SES...no support to even talk to!). It sucks that they got caught with their pants down but I bet a good social engineering attempt on ChunkHost might have yielded similar results. The lesson here is to have multiple defenses. 2 factor auth is a great start and it wo…
They literally handed over a customer's credentials over the phone. What's more, there didn't appear to be any ID verification.
I don't see how that could be anything but a huge, glaring, faultable security hole. I'm a Sendgrid user, and this is pretty scary.
Re: Security Hole in Sendgrid
#80Earlier quoted context omitted.
Are there any web hosting companies that don't rely on the "send a reset link to your email address on file" model of password resets? You're right, that model is deeply broken if anyone can intercept those emails (as happened in this case), but it seems unfair to single out ChunkHost for criticism.
With that same logic in mind - we could say that anyone working at amazon AWS or Rackspace (or any other hosting companies) could gain access to your application. The thing is we trust these companies to have processes in place so that their representatives won't have the ability to potentially do something destructive and if they can because they are the highest ranked rep and they need that kind of access - then at…
If you omit it, the assigned tech will frequently ask for it. Always sends a little shiver down my spine.