Live data from Hacker News

Security Hole in Sendgrid

chunkhost.com

1–10 of 97 posts

Re: Security Hole in Sendgrid

#4
Looks like a deeply unsatisfactory response from SendGrid. They don't even know for sure ("it appears .. pretty much confirms") that their own support staff changed the email address?

Re: Security Hole in Sendgrid

#5
Another title for this submission could have been:

"Massive Security Hole in ChunkHost. Non-2FA accounts can be owned."

Because it turns out anyone with a Sendgrid Support account also effectively had potential access to any account at ChunkHost not using two-factor authentication. Which is also true of thousands of other companies that are relaying their password reset emails through third party SMTP services.

SendGrid seems lame, for allowing this and for their response promising to yell more loudly at their support people, but they're an SMTP relay service not an authentication service.

Re: Security Hole in Sendgrid

#6

The problem is that it was technically possible, for a representative, to make this change without the proper verification. You just can't rely on humans for that.

> "... confirms your suspicion that these people convinced one of our representatives to change the email address on file."

This is the part that scares me. Do they not have auditing in the system where the representatives are able to change the email address on file?

Re: Security Hole in Sendgrid

#7
So what's the answer? Here's two very legitimate scenarios:

1) You sign up, enable two-factor auth, then lock yourself out (lost password and your second-factor). How do you prove to the service provider that you are you?

2) You sign up, enable two-factor auth, then Mallory claims that they locked themselves out. How does the service provider prove that Mallory is not you?

Re: Security Hole in Sendgrid

#9
post #8

Send your emails yourself. It's not like it is hard. At least not harder than integrating to a third party email sender.

If you use EC2 or the like your IP address or the entire address block could have easily ended up on a spam list so your email will be blocked. I wish SendGrid was only necessary for people who sends lots of mail but the reality is that no cloy provider can guarantee that email from their IP addresses will be delivered.

Re: Security Hole in Sendgrid

#10
post #5

Another title for this submission could have been: "Massive Security Hole in ChunkHost. Non-2FA accounts can be owned." Because it turns out anyone with a Sendgrid Support account also effectively had potential access to any account at ChunkHost not using two-factor authentication. Which is also true of thousands of other companies that are relaying their password reset emails through third party SMTP services. SendG…

Are there any web hosting companies that don't rely on the "send a reset link to your email address on file" model of password resets?

You're right, that model is deeply broken if anyone can intercept those emails (as happened in this case), but it seems unfair to single out ChunkHost for criticism.

Post reply on HN