Impact to DigitalOcean customers resulting from Mailchimp security incident
digitalocean.com
digitalocean.com
Interesting write up and 2FA by default sounds like a sensible move.
If you’re the type of user to have a DO account, you should be perfectly capable of using 2FA.
A number of accounts would have been accessed were it not for 2FA.
The best password won’t save you if a reset email is intercepted.
Something you have plus something you know should be what we cone to expect from any service that deals with anything of importance.
If both the email and DO account are behind strong, unique passwords, that won’t happen from a mere DO email leak.
Now, if the same, weak passwords are used for both accounts, sure. That’s terrible practice. But it’s also not what the GP was talking about.
That's not something fundamental to passwords. It's just that the culture of security in the industry seems to be more willing to lock people out of their account when they lose the factor they have than when they lose the factor they know.
It could be that losing what you have is easier for people to remedy than a forgotten password, but somehow I suspect that it probably comes down to which one generates the fewest angry customers/calls/support tickets. Maybe it's easier for us to blame ourselves if we forget to carry a token or our cell phone?
> One of the first discoveries was a non-DigitalOcean email address that appeared on a regular email from Mailchimp on August 7th.
> Soon after we discovered an issue with our Mailchimp account on August 8th, we initiated contact with Mailchimp, both via traditional support channels and other escalation methods. On August 10th, we had our first actionable response
I wish our industry could just be honest that many meaningful escalations have to happen via discriminatory back-channeling, contacting friends, family, former co-workers, ANYONE who might have an in with the organization.
Its discriminatory because if you don't know someone you can be SOL.
I no longer recommend or use Mailchimp.
Assume that you’ll have availability problems with email and engineer with that in mind.
The reason most just say "You're banned, bye" is because they don't want to do that work, and subsequently don't care about their users one bit.
I could say the same thing to you, you're making it sound harder than what it is. But if you're set to the mindset of saving money, I understand minimising work makes sense.
Of course they do. It’s just email/twitter/telegram/WhatsApp, and fraudsters are literally professional messaging automators. They open support cases, email execs, I have seen cases of them paying call center workers to call support lines and complain. Fraud is a serious business run by serious people, many of whom have a decade plus of experience.
You cannot attempt to stop fraud with manual effort if you operate at any kind of scale. Full stop.
> Assume that you’ll have availability problems with email and engineer with that in mind.
That goes for all dependencies, not just email. And not just third-party dependencies either.If PyStorm died today, I could carry on in VIM. I could rebuild my entire architecture on DO if AWS sours. If git takes a dump, I have four machines from which I could copy the code and migrate to e.g. mercurial. And if I get hit by a bus, my code is well documented and testable.
Thanks for explicitly explaining that part. Now that you've put it that way, it's a pretty apt term but I probably wouldn't have been able to figure out because that term is usually used for things like gender, race, etc. and my brain immediately jumped to that. Maybe I am just stupid, but sometimes it shouldn't be that hard to understand what people mean and it helps to be more explicit.
- Lonely people aren’t visible, by definition,
- Solitude increases racism, so it would be worth solving,
- They often end up creating companies and being one’s boss.
It's kind of funny that Mailchimp treats a company as large as Digital Ocean as if they're a one person newsletter.
We left Mandrill because they had a DB failure which took them a long time to recover, and we felt that all their focus were on newsletters, and that transactional email didn't get any attention.
I didn’t realise they’d discontinued it. I remember there being an uproar some years back when they ditched the free tier and made entry level pricing $20/mo.
Free options seem to be drying up.
It seems that most of these transactional email companies concept of "100% delivery guarantee" excludes you from that guarantee... they aggressively and pre-emptively protect their servers from being blacklisted by autoblocking you first based on some heuristics and then very slowly or possibly never unblocking you manually later through useless support staff. Guilty until proven innocent.
Settled on Postmark (after trying pretty much all the popular transactional mail services without success), which has so far been golden, customer support will actually help you resolve an issue if there is one, plenty of forewarning with transparency before any blocking, the front end is exemplary of clear usable UX. It also lets you sandbox transactional mail into "servers" so that one bad source can't affect another.
I want to say this is due to the threat landscape expanding by the day but some part of me suspects that when a service provider becomes 'comfortable' (mailchimp, Heroku, Twilio, etc.) they becomes complacent/cut costs in the security department.
The other day I got a clear phishing SMS from REVOLUT! Crazy!
Instead they only supported TOTP (Google Authenticator is one implementation) second factor which is vulnerable to phishing attacks. But still better than SMS or nothing at all.
Afaict, the bug is that Firefox doesn’t support FIDO2. AzureAD also doesn’t support U2F, which is unsurprising.
It seems SES or mailgun are the primary options these days.
Besides, their technical skill is pretty poor when their site shows "page not found" of some sort on log in process for a split second and when you try to search through the logs, they will quickly show you that I've made excessive access after less than 10 searches.
They had an incident on themselves and I asked them to resend the emails that they failed to send and support couldn't do that and that got us off of SendGrid.
Large free plan limit is the only good part about SendGrid.
This is typical of single page apps. They have a default state of "no data" and then they update it when they get a response.
Mailgun still didn’t automatically rotate DKIM keys last time I looked, otherwise I’d rate them much higher. That one thing creates a detail I don’t want to have to worry about.
Not only do they not automatically rotate them, there's no functionality to manually rotate them either. The only thing you can do is delete the configuration for your domain entirely and recreate it, which of course nukes your Event log. Hopefully they are working to address this...
I was their paid client some years ago, never have I treated as badly (though Convertkit came a close 2nd). People keep recommending Mailchimp, when they are one of the worst companies for support.
And funny to see big million dollar corps are treated the same way us plebs are-- at least Mailchimp dont discriminate!
Why wasn't two factor authentication required to reset the password? This is Security 101: Greater risks need greater authentication.
Must suck for Mailchimp to lose a big account, but I guess that's not suprising. Mailchimp is going down by a thousand cuts - they could have stayed a great company if they wouldn't have focused on growth so much (I mean they now offer online ship builder and appointment scheduler products).
I would prefer that they fix their problems instead. They have 800 employees. I don't want those people to lose their jobs.
This thinking is how one rationalizes "bailing out" companies which have objectively failed in the market and should suffer the consequences.
Never has it been so easy to form a business and employ people. Gone are the days of a business being some kind of precious thing worth preserving because forming one is so involved.
Let the failures experience negative consequences, it's how we improve as a society.
You're thinking everything is some kind of an existential crisis.
You're the one thinking a company going bankrupt and 800 employees being out of work is some kind of existential crisis.
Companies fail, employees lose jobs get humbled and go find new work with lessons learned. It's how this is supposed to work.
What is the "current market" that you're talking about?
When a company goes bankrupt they give maybe 2 paychecks. How long until these people get new jobs? Maybe the company gives 4 paychecks? Still, how long is that going to last?
EDIT:
I'm seeing now that nobody on HN has ever been on the receiving end of your company going bankrupt. Carry on.
The one with all the layoffs and hiring freezes?
There is no excuse. None. Not for google. Not for anyone. In fact the other way is far more justified. When you're as massively profitable and market dominating as google if you don't respond well and fast you need to be broken up. Now. And Google clearly do need to be broken up. But for many, many other reasons too.
Just to hell with this excuse of "we're so successful we don't need to try because you're nothing to us!" Straight to hell. "You make so much money and dominate the market so comprehensively we must hold you to a lower standard." Seriously.
Dumping mailchimp? Ok. Dump google? Good luck with that one. You see it?
edit: and I have dumped Google. I use it for exactly nothing important in my life. It is possible and doable.
This is actually delusional. Email. You don't get a choice there. And your ad-blocking is unlikely to be 100% effective. How many websites you visit use google stuff? Never clicked on an amp link? That's just for starters. The decisions of others prevent you from living google free unless you leave modern society and find a nice place in the wild.
But more importantly, _No!_ Logistics do NOT matter at all in responsibilities. It doesn't matter how difficult it is. When you're the lynchpin in something and you don't deliver, screwing up someone's business or life to a non-trivial degree you are 100% responsible for that. You can't do it, GET OUT. "The logistics of driving drunk are really hard so it's ok when it goes wrong." Nope. It's not ok. Don't do it. The end. If you can't take responsibility for providing a critical service because you want huge scale you have zero business doing it.
Having more tolerance for smaller players trying to compete is fair. Having tolerance the market dominating force with the decreasing long run average total cost curve making billions is just madness. Break them up. Why are they in phone os development? Why isn't mail spun off from search? Why isn't 3rd party advertising spun off to a separate entity from those two? And so on.
"Because it suits their market dominance" has always been an argument for breaking up this kind of market power not in support of it.
Also some nonsense in there about Crypto scammers?