Trello Allegedly Breached
twitter.com
twitter.com
Probably also some internal debate whether this should be considered a breach or not and whether it’s worth the cost of announcing it vs. the risk of not announcing it
So they may not feel they need to say anything.
Whatever.
> > Trello In January 2024, data was scraped from Trello and posted for sale on a popular hacking forum. Containing over 15M email addresses, names and usernames, the data was obtained by enumerating a publicly accessible resource using email addresses from previous breach corpuses. Trello advised that no unauthorised access had occurred
For info, that same email address has been receiving many many haveibeenpwned warnings, it's everywhere and I consider it basically completely public lol.
Expect websites and apps to strong arm your phone number in the future as a result.
Why would you spread falsehoods like that?
https://stripe.com/resources/more/what-is-address-verificati...
Many of these services will also block signing up with throwaway email providers, of course Apple's service would require them to block to many "legit" users so it remains a good choice. The ones taking your phone number usually block land lines and voip providers, some even block prepaid mobile plans!
Meanwhile they lose your PI and shrug their shoulders or blame the users, but if you try to protect yourself from their garbage security the decide you must be a bad actor for practicing compartmentalization to limit the blast radius of their inevitable screw ups. It isn't like there is punishment for them screwing up so there's no reason for them to not take everything they can get.
Sorry, a little snarky. But I predicted Trello would suffer from joining Atlassian, and though this is not how I predicted that would happen (I predicted lots of utterly useless new features clogging up the UI until it's unusable), it is an indicator of The Atlassian Effect in action.
A credential stuffing attack found 15M email addresses that attackers already knew had Trello accounts.
> Trello In January 2024, data was scraped from Trello and posted for sale on a popular hacking forum. Containing over 15M email addresses, names and usernames, the data was obtained by enumerating a publicly accessible resource using email addresses from previous breach corpuses. Trello advised that no unauthorised access had occurred
> enumerating a publicly accessible resource
> Trello advised that no unauthorised access had occurred
That sounds like a credential stuffing attack to me!
Most likely the attackers used the password reset form, and that Trello acknowledge the existence of emails. This used to be considered bad practice, but it's more nuanced than that, provides basically no useful information, and is now considered to be a relatively safe practice.
Alternatively it's possible they used some sort of sharing functionality to try to share Trello content with other addresses, and again the availability of that for usage would be by-design.
> This used to be considered bad practice, but it's more nuanced than that, provides basically no useful information, and is now considered to be a relatively safe practice.
Against this:
> 15M email addresses
While you're saying that Trello leaked nothing, it strikes me as odd that an attacker could successfully interrogate a public resource enough times to confirm the existence of 15 million addresses without triggering some kinds of checks/balances to prevent such enumeration.
I understand this is meaningfully different than other kinds of leaks (i.e. an actual compromise), but it still indicates an issue on the Trello side.
I'd agree that 15 million requests should trigger something, but it depends on how long this happened over. Fundamentally, rate limiting access to a public resource is not a security mechanism against disclosure from that source, rate limiting is only a viable countermeasure against denial of service style attacks. So while there may be some improvements Trello could make here, I don't think they'd materially change this.
Which is surely far below the CTR one would expect for people actually using the share feature on Trello.
Even in 2017 it seemed to me Atlassian only bought it so anyone else couldn't have it and they would like it to die in the future but for the time being they could use it as future customer acquisition entry for their main products ( Jira and Confluence )
Their disinterest in Trello in recent years might just be what has saved it for so long. Once their crack teams of product development people arrives it will be game-over.
This is why I have my credit frozen with every agency, and all of my security question answers are plausible sounding, but entirely fake, answers stored in my password manager.
I'm not sure there is anything else we can do as consumers.
Much better to use a 'plausible' answer like "Fielder" or "Pitt" or any random real last name.
Sounds plausible enough, but clearly a fake.
People asking them do need an explanation though, but no chance someone could guess one because it was plausible but wrong.
I think the "random but actually meaningful" route is better. If you want it to get checked, grandma's name comes off fake name generator, not line noise from a CSPRNG.
A CSR is much more likely to expect correct or similar words than a correct or similar string of gibberish.
Correct Horse Battery Staple
WHat's your mothers maiden name?
Correct Horse Battery Staple
What's your favourite movie?
Correct Horse Battery Staple
1) Wrong information
2) Information you don't know, like an estranged family member's birthday
They don't need to be plausible sounding, by the way, a random string of characters is fine.
Pet's name -> probably in your Instagram
Favorite color -> Hmm let's see what clothes you wear in your selfies
Street you lived on -> Hmm they probably already breached your credit report and the idiots at Experian leak all the streets you lived on without your consent
Had no idea, googled them… there’s some security theater that I don’t think anybody could have been reassured by.
> Select your favorite city:
> 1) Paris
> 2) New York
> 3) Banana
> 4) Beijing
Don't register to vote. It doesn't matter anyway unless you're in a swing state, and the idiots at the voting registration offices leak residential addresses.
This isn’t a prison, my location isn’t anyone’s business but my own.
Private businesses on the other hand can f off. My credit card co can't come and handcuff me for not giving them an address to leak to 3rd party auto ads.
Simplification sure, but you started.
Courts enforcing notional rights weeks or months later can’t get you un-murdered in your sleep by home invaders. Did we all forget that swatting is a thing?
The place that you sleep is secret, and you should never tell it to anyone that isn’t an invited guest, especially not apps or the DMV. Every other data leak can nominally be mitigated with time, inconvenience, or expense, but violence to your person or your children cannot be un-done after the fact.
When the DMV leaks your info to all your stalkers and crooks on the internet and they come after you they won't find you there.
Ron Swanson is parody; I am being sincere.
They seem to completely not notice that every individual and business would never know if another bank account existed in their name if it wasnt used in a different kind of crime or overdrawn forever.
there are plenty of people that just want access and dont do anything bad with it, aside frok the paradoxical standard of having access or impersonation to be bad
same is true of credit, although the original identity can see the extra credit line added, sometimes the phantom is a better steward of your credit than you are. Like “wow mixed lines of credit, paid on time! thanks undocumented person!”
Second, they need to make it illegal FIRST, or there would be no sanction evasion crime: if they don't act all naive and say "you cannot have an account here at all", then having an account would be fine... now the criminals need to cheat and lie, which they can be charged for.
Finally: not all crime will ever be punished and there's definitely a cost calculation: do we want to take fingerprints of all clients in banks to match them to a central id card database, to end up with criminals infiltrating the fingerprinting system anyway and everyone else having to do those dumb fingerprint checks for nothing ? Better keep it simple while the criming stays manageable.
The only cases where this doesn’t work are banking and airlines, which are required to check your government ID. Trello isn’t, and you can give them a burner forwarding email and fake name so this kind of thing doesn’t affect you.
You’d be surprised how much business you can conduct without providing your name. (pro tip: the “name” field in the credit card form is not matched against the cardholder.)
Also, make sure your CC billing address is a post box, so you’re not giving your residential address to everyone you transact with (the address/zip is matched).
I think it's a sort of option / depends on amount: some sites don't ask more than your card number and it works, some other you need to redo 5 times before they match properly. And anyway here you need to approve in the app like for a Google 2FA in Android.
Also, I have been asked to show ID with a card when making payment at plenty of retail establishments, just not necessarily restaurants.
Why do I have to tell a stranger over the phone my mother’s maiden name to confirm I own the account? That’s not my info to share, it’s my mother’s.
It's also, for many people, incredibly easy to find. People often keep their maiden names as a middle name, so if you can find someone's mother (relatively easy in the age of Facebook) it's not a far leap to figure it out from there. Even if they didn't keep their maiden name, finding it out is pretty simple by connecting the dots.
It made a bit more sense in the era before a majority of people started posting their private lives on the internet. These days it's a security disaster. Thankfully, the increasing popularity of non-traditional naming arrangements will probably do away with it soon.
Many things don't matter at a small scale, but they do at 15M-scale.
Trello users are about to get bombarded by phishing attempts and spam.
All of the emails present in this "leak" were taken from other dumps. That's how it's made, they took a list of known emails and tried to link them to a trello account.[1]
> What's the endpoint?
I think https://developer.atlassian.com/cloud/trello/rest/api-group-.... The endpoint allows you to get all public info (bio and username) from a trello account by its email.[2]
> Why did it provide personal information?
So users can invite other users to their boards via their email address.
> Why wasn't it throttled?
It should've been.
[1]: https://haveibeenpwned.com/PwnedWebsites#Trello
[2]: https://www.bleepingcomputer.com/news/security/trello-api-ab...
I can literally go to the tax assessor's website and search an address and find out exactly who owns that property.
But if a data leak finally gives me meaningful ads - that'd be nice.
If you’re having ad quality issues, it could be that they don’t have good advertisers matching your profile.
If you use a unique email for everything, attackers need to determine email+password+whatever, instead of just password+whatever, where "whatever" is security questions or compromising 2FA.