Security Hole in Sendgrid
chunkhost.com
Security Hole in Sendgrid
1–10 of 97 posts
Re: Security Hole in Sendgrid
#2Re: Security Hole in Sendgrid
#3Re: Security Hole in Sendgrid
#4Re: Security Hole in Sendgrid
#5"Massive Security Hole in ChunkHost. Non-2FA accounts can be owned."
Because it turns out anyone with a Sendgrid Support account also effectively had potential access to any account at ChunkHost not using two-factor authentication. Which is also true of thousands of other companies that are relaying their password reset emails through third party SMTP services.
SendGrid seems lame, for allowing this and for their response promising to yell more loudly at their support people, but they're an SMTP relay service not an authentication service.
Re: Security Hole in Sendgrid
#6The problem is that it was technically possible, for a representative, to make this change without the proper verification. You just can't rely on humans for that.
This is the part that scares me. Do they not have auditing in the system where the representatives are able to change the email address on file?
Re: Security Hole in Sendgrid
#71) You sign up, enable two-factor auth, then lock yourself out (lost password and your second-factor). How do you prove to the service provider that you are you?
2) You sign up, enable two-factor auth, then Mallory claims that they locked themselves out. How does the service provider prove that Mallory is not you?
Re: Security Hole in Sendgrid
#8It's not like it is hard. At least not harder than integrating to a third party email sender.
Re: Security Hole in Sendgrid
#9Send your emails yourself. It's not like it is hard. At least not harder than integrating to a third party email sender.
Re: Security Hole in Sendgrid
#10Another title for this submission could have been: "Massive Security Hole in ChunkHost. Non-2FA accounts can be owned." Because it turns out anyone with a Sendgrid Support account also effectively had potential access to any account at ChunkHost not using two-factor authentication. Which is also true of thousands of other companies that are relaying their password reset emails through third party SMTP services. SendG…
You're right, that model is deeply broken if anyone can intercept those emails (as happened in this case), but it seems unfair to single out ChunkHost for criticism.