DocuSign email address database breached and used for phishing campaign
trust.docusign.com
trust.docusign.com
We have already started seeing a tonne of DocuSign phishing emails as others have mentioned. They were already a popular target for phishing users but now with very realistic documents the users are expecting? Nightmare.
Canary has developed into a standard term for warnings which are detecting the danger allowing mitigation as opposed to predicting the danger which would allow avoidance.
More succinctly, a canary is an early warning system.
[0]: https://en.wikipedia.org/wiki/Sentinel_species#Historical_ex...
Not affiliated, just a happy long-time paying customer.
businessname@mydomain.io
Already caught a few selling my info
Edit: fixed :)
Looks cool though, I subscribed to the list.
Edit: fixed
Exact titles similar to this: "Accounting Invoice 630761 Document Ready for Signature"
"Delete any emails with the subject line, “Completed: [domain name] – Wire transfer for recipient-name Document Ready for Signature” and “Completed [domain name/email address] – Accounting Invoice [Number] Document Ready for Signature”. These emails are not from DocuSign. They were sent by a malicious third party and contain a link to malware spam."
Did you received phishing with other subjects?
----
Feature Request: Your software does not make it easy to buy drugs, money, or sex as buydrugsmoneyandsex-dot-com does. Please implement buydrugsmoneyandsex-dot-com functionality by directing users to that website through our affiliate link program: http://preview.tinyurl.com/2tx
Also Thanks Me for just using docusign w/ our employees when I was in charge.
Best response I've received when giving an email address of the form "company@mydoma.in" to a representative in person was "oh you work here too?". The concept of catch-all domains is so foreign to most laypeople that it takes quite some explaining ("I get everything that's sent to any address at that domain", "no it's not expensive at all", "it helps me automatically sort my email").
Most likely it is to stop you from making an address with "aliexpress" in it, so you don't look like affiliated to aliexpress in any way (think: phishing).
It was a massive headache at the time tho.
Some sites refuse to accept email addresses with more than one "." after the "@" but figure if they don't understand email addresses I don't want to trust them with my details (even throw-away ones) anyway so go elsewhere.
The combination of them knowing that this was valid and just wanting to strip off the extension kinda blew my mind for some reason.
Picking a short preposition for the subdomain can even help when you have to communicate the email to a clueless phone rep: "That's right, it's yourcompany@for.myname.com"
So, if I'm dealing with Walmart, I would give them:
[keyword].walmart@example.com
or
walmart.[keyword]@example.com
Then I configure my catch-all settings to reject any email addresses that don't have that keyword.
Of course, the keyword is not secret, so it's possible for someone to infer what I'm doing and construct an email address that passes my spam check, but in practice, nobody goes through the trouble, because I'm not a big enough target.
(fwiw, this domain is almost 20 years old, so that's forever in internet years)
https://www.fastmail.com/help/receive/domains.html
https://www.fastmail.com/help/receive/domains-setup-mxonly.h...
https://www.fastmail.com/help/receive/alias-catchall.html
Besides, there are 30 or so that I have black holes, from back when comment systems leaked email addresses.
Some sites refuse to accept email addresses with more than one "." after the "@" but I figure if they don't understand email addresses I don't want to be trusting them with my details, even throw-away ones, anyway!
Unfortunately I was added to docusign by someone else who gave them my main address...
1. Pay a reasonable rate for a full time server in services that are just truly awful, have no redundancy options, and are associated with a lot of unsavory activity or...
2. You pay a totally unreasonable rate to host it in a more reputable cloud service.
3. You run it out of your home or office and deal with your locale's interent. In my case (California Bay Area) it's bad.
One additional twist, I keep my site-spesific aliases on a short sub-domain (for now service-or-tld@s.mytld.com) - if I feel the need in the future I can burn down the whole sub-domain, exchanging s.mytld.com for eg: m.mytld.com.
How does clicking a link from an email prove identity? How does it work?
Most of these document signing services, as you point out, don't prove identity. They provide a more convenient simulation of the "download, physically sign, scan and return, a pdf document" process. Which doesn't prove identity either.
Personally, I appreciate the shift. It's just as silly, but less cumbersome.
Joking aside, this is an inevitable event and we just have to be cautious and ready when it does happen.
If it's linked to a savings account and it's a Visa/MC debit card, for example, then it's a different story. The funds are not insured and so if you loose it it's on you.
With a debit card, the money is just gone and the burden is generally on you to find some way of recovering it from whoever stole it.
Not true. Not in Europe.
https://www.consumer.ftc.gov/articles/0213-lost-or-stolen-cr...
In both cases, fraud disputes are handled in the same way. Either the issuer or the account holder suspects fraudulent transactions and the bank engages an investigation in order to determine veracity of the claim.
Where things differ is that the onus of proof for credit card accounts is on the merchant to prove the transaction is legit. When an offline debit card is used, the funds are deducted from the account when the merchant captures funds and, therefore, the onus of proof lies with the card holder to prove it is fraudulent.
Liability, in this context, is non sequitur as fraud claims exist in either scenario and one party or the other must provide proof to support their position. The other, by definition, is responsible for said funds.
I'm not really sure what you mean regarding "a reversible ledger", as this has nothing to do with credit card transactions.
EDIT: clarified liability phrasing.
Your note about "onus on proof lies with the cardholder" is less true for Visa, for example.
The best resource I've seen is this one: https://www.minneapolisfed.org/~/media/files/about/what-we-d... See pages 6 through 18.
This is annoying but not a big deal or a privacy breach, DocuSign is so prevalent your email being in there means basically nothing.
Uh, really, endorsing antivirus? They could at least have written something like "Ensure your system is properly secured" if they felt they need to stress that out.
Is it just me that feels this way, or should they not also apologize for the leak (which appears to have been from one of their systems)? I didn't see an actual apology.
[1] https://www.facebook.com/notes/protect-the-graph/securing-em...
This one I learned from Troy Hunt and never looked back.
https://www.troyhunt.com/only-secure-password-is-one-you-can...
Is there a chance I could've been compromised in any way? I'm guessing they couldn't have gotten much more than my IP address, maybe some cookies, all my passwords, private life?
It takes no more than 20 minutes to prototype and then approximately 1 day to fully test the final solution that is necessary on their end to keep compromised emails from being fully compromised addresses forever, without any chance for you to ever know at any point in the future where mail REALLY comes from. Here is a description:
1 - Currently they (Google) correctly do 99% by allowing you to type a + after your email address to create a new inbox that is marked in a special way. For example if your address is jsmith747@gmail.com then you can give the company jsmith747+docusign@gmail.com when you sign up - that inbox goes to you and when you start receicing spam in the future to "jsmith747+docusign" you can tell how they got it. The phishing mails associated with this breach would have gone to the same place.
2. The one and only problem with this, which currently has a "security through obscurity" solution, is that anyone can run a regex and remove +docusign to get at the primary, main inbox: jsmith747@gmail.com
3. The full and complete solution is to allow me to create a new inbox in Gmail through a single step, for example "j45rsdfjdocusign" which is linked to jsmith747 in a single direction. Sending mail is not necessary. This must be enabled through the Gmail interface for signed-in users who wish to create a new inbox. They must be able to generate an inbox there, which thereafter goes to the inbox.
4. Spammers have no way to programmatically get the original underlying address when going through a list. When they get to j45rsdfjdocusign there is no regex they can apply to get the original.
5. If in the future j45rsdfjdocusign starts getting spammed, etc, you can add a filter.
There's no special authentication around it, anyone signed into their inbox should be able to do do it. They already have the infrastructure up for it around their + coding shceme.
To emphasize how important it is, here is a comment from this thread:
>The phishing emails had the color scheme changed, making them very phony and easy to classify.
Today. Under the current status quo, if in 48 months a much more legitimate-looking mail is sent to any of the same addresses, none of the recipients have any way to know the source of those addresses.
However, after solving this security issue, in 48 months anyone receiving even a very convincing phishing email could know instantly "oh, that is that compromised docusign account" -- that is, if they haven't taken a moment to redirect that inbox to the trash already via a filter.
I urge Google, who has very talented engineers, to implement the correct solution today. Don't wait. You won't get a better example of how important this is, than what's been going on. There are no policy implications as you already do it via the + trick.
I hope you go the extra mile and add a small step to finish solving the problem. Thank you.
(Of course, you can do this, quite easily, if you run your own mail domain. You need not administer an MTA - I gather you can wire up a domain you own to Google Apps or G Suite or whatever they're calling it this week.)
If this is a concern then Google can generate an immutable part of it (with high entropy), for example I said "j45rsdfjdocusign " of which "j45rsdfj" may be generated and the user may rewrite only the end of it.
The reason it's good for the user to be able to write at least part of it is so they can include the tag and not have to add it as a separate step. Otherwise, it is hard to remember where tags go.
An alternative is that during the generation the user could supply their comment which is visible only to them. (So that under this scenario j45rsdfj is generated, and you comment it with "docusign" during generation. Then if j45rsdfj receives email it is tagged with "docusign" (the comment you added during generation).
There are no other policy implications. (Though I say that with a bit more hesitation, since you did point out one minimal effect.)
By the way this has an additional benefit. Most user-chosen names don't have enough entropy. If I sent an email right now to johnsmith433 there is a 100% chance that it has already been registered by someone. Today, spammers can guess email addresses. (This is a theoretical problem only.)
If Gmail generated high entropy as part of this feature, then this would further reduce this (theoretical only) avenue for spam. I don't think this is an actual problem though - I've never heard this being described as an issue.
Gmail as the receiving MTA will want to accept or reject a given email recipient. To do this they need to look up the information. They likely have a fancy distributed way of doing this now. If each user now exploded out to N aliases, you are likely adding a new network hop and loads more memory storage before the MTA can accept/reject. When you are processing many billions of email (lookups), this is a significant change.
Again, it is solvable if they wanted to do it. But it is nontrivial. Add onto this the need for the product team prioritize the work, other work to be de-prioritized, planning, testing, etc.
Nothing that you have stated is difficult or a choice, because johnsmith23+sketchy is live today. If you have a gmail account, you can give out your accountname + marker to anyone you want, so that later you can start filtering it.
This is security by obscurity, since this can be removed by a regex. I would like them to fix this.
As for your other point, where you call the extra data "nontrivial", I am afraid you are wrong, it is almost the definition of trivial. If you have a gmail account, go to it and type a name or any word into the search field. You will instantly receive search results from the entire history of your email archives.
That is because your email archives are fully indexed for fast searching. This takes a not-insignificant amount of space.
Adding a few bytes of aliases is absolutely trivial compared to the amount of storage and lookup that Gmail does on your behalf. It's almost the definition of trivial.
This isn't 1964!
When hosting your own email on your own domain you get this benefit out of the box now, without waiting for google to add it for you.
I've been doing this for years, each different company gets a unique email address. Real easy to see who has lost track of their email database, and very easy to turn off those that turn spammy as their business declines and they get ever more desperate to generate sales from their existing "customer list"
[1] https://www.quora.com/How-many-software-engineers-does-Googl...
I love how nothing changed about this malware payload delivery in about 2 decades.