Live data from Hacker News

Security Hole in Sendgrid

chunkhost.com

71–80 of 97 posts

Re: Security Hole in Sendgrid

#72
post #65

My first thought was to whois chunkhost.info, which returns a clear name, email address and phone number. Or is it that easy to register a domain with a fictitious persona?

It's that easy. You can use anything you want.

Re: Security Hole in Sendgrid

#73
post #14

So what they are saying is that SendGrid should have had two-factor auth and this would have never happened.

SendGrid's policy (as stated in their first email) is that the support people shouldn't be changing account emails in this fashion. Even if SendGrid had 2 factor auth, who's to say the support guy wouldn't have just disabled that?

With TFA if the email got changed it would not make a difference. The attacker would need the second factor to rest the password and to log in. So the worst they could do is to lock out the account owner. The support staff being socially engineered is a different story, but yes this is a security hole in SendGrid's system and an easily patched one at that.

Re: Security Hole in Sendgrid

#74

Earlier quoted context omitted.

Please, no. Consider a determined attacker. A posted signed letter has zero cost and is easily forged and a phone call is free via Skype. There's plenty of low-tech ways to circumvent security.

How exactly does Skype let me take over a business's phone number? I am saying that SendGrid should call the company to verify, not the other way round.

Ahh sorry, my mistake. I missed the word "outbound".

Re: Security Hole in Sendgrid

#75

So what's the answer? Here's two very legitimate scenarios: 1) You sign up, enable two-factor auth, then lock yourself out (lost password and your second-factor). How do you prove to the service provider that you are you? 2) You sign up, enable two-factor auth, then Mallory claims that they locked themselves out. How does the service provider prove that Mallory is not you?

Text message or phone verification of details only you should know about the account history, payment methods, etc. As others mentioned, a waiting period during which they try to contact using any means s previously authorised for a response. Compare IP addresses and deny logins from strange countries or origins without further verification, etc. Of course, every measure and countermeasure needs to be justified, sinc…

Yep, so text messages and phone verification could really be considered a "third factor". I guess anything information you have already provided to your service provider is considered an X-factor.

Re: Security Hole in Sendgrid

#77
post #14

Earlier quoted context omitted.

SendGrid's policy (as stated in their first email) is that the support people shouldn't be changing account emails in this fashion. Even if SendGrid had 2 factor auth, who's to say the support guy wouldn't have just disabled that?

If their policy is that support staff should never be able to change an accounts email address... why does the system let them do it?

At some point someone has direct DB access and can do this. Sure, normal support people don't but this just makes the social engineering aspect a bit more complex, not impossible.

Re: Security Hole in Sendgrid

#78
post #5

Another title for this submission could have been: "Massive Security Hole in ChunkHost. Non-2FA accounts can be owned." Because it turns out anyone with a Sendgrid Support account also effectively had potential access to any account at ChunkHost not using two-factor authentication. Which is also true of thousands of other companies that are relaying their password reset emails through third party SMTP services. SendG…

Would you apply the same logic to your DNS provider?

Re: Security Hole in Sendgrid

#79
post #26

Social engineering will almost always work. I don't really fault Sendgrid for this (though I could see this not working as well if you were using Amazon SES...no support to even talk to!). It sucks that they got caught with their pants down but I bet a good social engineering attempt on ChunkHost might have yielded similar results. The lesson here is to have multiple defenses. 2 factor auth is a great start and it wo…

>I don't really fault Sendgrid for this

They literally handed over a customer's credentials over the phone. What's more, there didn't appear to be any ID verification.

I don't see how that could be anything but a huge, glaring, faultable security hole. I'm a Sendgrid user, and this is pretty scary.

Re: Security Hole in Sendgrid

#80
post #10

Earlier quoted context omitted.

Are there any web hosting companies that don't rely on the "send a reset link to your email address on file" model of password resets? You're right, that model is deeply broken if anyone can intercept those emails (as happened in this case), but it seems unfair to single out ChunkHost for criticism.

With that same logic in mind - we could say that anyone working at amazon AWS or Rackspace (or any other hosting companies) could gain access to your application. The thing is we trust these companies to have processes in place so that their representatives won't have the ability to potentially do something destructive and if they can because they are the highest ranked rep and they need that kind of access - then at…

SoftLayer still asks for admin/root passwords to your boxes in pretty much any support scenario. Their ticketing system actually has a field for it in the submission form.

If you omit it, the assigned tech will frequently ask for it. Always sends a little shiver down my spine.

Post reply on HN