Researchers: Weak Security Defaults Enabled Squarespace Domains Hijacks
krebsonsecurity.com
krebsonsecurity.com
I kind of wish we could just pass a law that says you have to validate email addresses before attaching them to accounts at all. Because otherwise, competitive pressure will keep pushing people towards not doing it and aiming this gun at their foot in the name of conversions.
In the absence of a law: If your service insists on allowing unverified email addresses, you should store them in a completely different place in your database from verified ones. Maybe even obfuscate them with some encoding. Do whatever you can to make it really hard for anyone to accidentally rely on an unverified address. Ideally make it impossible for anyone except the team in charge of authentication to even see an unverified address.
On another note, holy shit. So many people (myself included) chose Google Domains specifically because they thought it would be secure and trustworthy, because it's Google. Won't make that mistake again.
I think the company eventually required verification, not because their trusted employee told them, but because a security review of the product pointed out the lack of email verification.
When it’s just a random staff member complaining they want to do something that makes it harder to onboard customers, there’s no proof of incompetence, and incompetence can still be blamed on the developers.
Also keep in mind that the company has full access to your work email account therefore they could delete the email if they wanted to. Not likely they would in general but people have been known to do all sorts of things in situations where a written record could hurt them.
What about for the purpose of improving the product you're (assumingly) full-time employed on?
Telling that that wasn't one of your hypothetical reasons :)
Therefore the main purpose of writing the initial suggestion down is so there's a record of it for future use. Either to cover your own ass when management/auditors/lawyers get involved, or to say you were right and management was wrong and make yourself feel superior.
>kind of wish we could just pass a law that says you have to validate email addresses before attaching them to accounts at all.
We did, the government can only collect the data it needs to complete it's stated objective. fedramp compliance. This exact exploit has happened at nearly every Fortune500 company. > otherwise, competitive pressure will keep pushing people towards not doing it and aiming this gun at their foot in the name of conversions
Market forces, people should be pressured to use more secured services.There is no such pressure in the market right now. Look at the email-provider market, where secure offering like Proton Mail are nowhere close to less secure ones like Gmail, Outlook/Live.com, etc. Why don't people just flock to Proton Mail?
Joker was recommended to me by another techie. Its German.
I was extremely disappointed google walked away from the domain game, because their interface was simple, logical and ironclad. I do not see how they possibly had costs in this which were not exceeded by the profits, and "click here" benefits for GCP and related product.
I'm probably misunderstanding you, but when you renew a domain you get an extra year (or whatever) measured from the expiry date, not measured from the renewal date. Renewing early doesn't lose you anything (except a bit of cash flow). This is true for .com and .uk anyway.
Would also help when people don't get their receipts or reminders or etc because they gave the company someone else's email. I think I've got three people who think my gmail is their address. And I can't just give up and close it because Google won't let you use a non gmail account as an Android account. Has to be gmail or whatever G Suite is called today.
Though personally, when I heard that Google is selling off Google Domains, I immediately transferred my domain elsewhere. Not necessarily because I hate any of the parties involved, but because a transfer at that time was fully within my control with fewer unknowns, unlike waiting for some bulk migration with no announced timeline.
Is your company using Google's cloud office products? Gmail?
> “Thus nothing actually stops them from trying to login with an email,” Monahan told KrebsOnSecurity. “And since there’s no password on the account, it just shoots them to the ‘create password for your new account’ flow. And since the account is half-initialized on the backend, they now have access to the domain in question.”
This sounds like gross security negligence, and should probably be considered a crime when you're at the size of Squarespace with (assuming) a dedicated security team. Hopefully executives/management can be held responsible for whatever damage was done because of this.
Domains are critical infrastructure, wasn't any reason to sell them other than Wall Street puffery. Obvious downside was leaving business customers who got them via Cloud exposed. Per my uninformed intuition at the time, there wasn't a secure way to do this sort of switchover without a lot of manual reaching out neither of them were going to do.
Additionally, Google went out of their way to sweeten the deal by A) making Squarespace the reseller for any associated Google Workspace records which B) greatly widened the vulnerability surface. [1]
This sounded uninformed to me, until it happened, so [2] quotes the retrospective at length to show there was no secure and automated choice.
both via Security Alliance's "A Squarespace Retrospective": https://securityalliance.notion.site/A-Squarespace-Retrospec...
[1] "Furthermore, as Squarespace is an authorized Google Workspace reseller, any teams who had purchased Google Workspace through Google Domains had their license transferred to Squarespace. This allows the threat actor to create new administrators in Google Workspace via the hijacked Squarespace account."
[2] "However, what happens for [domain owner] emails which are not already registered to an [Squarespace] account? Well, you could preemptively create a new account for that email and send them a temporary password, but sending passwords in plain text is not a good practice, it would be pretty complicated to create millions of users with temporary passwords, and most people migrating probably want to use their Google account to sign in, not a password. Maybe your systems don’t even support creating temporary users like this."
It's the Hunger Games inside, for a 1000 reasons. tl;dr: MBAs won, thoroughly.
The Great Game* is figuring out how to cut people without seeming cruel. Easiest way to do this is cut whole teams at once. This almost assuredly was seen as a massive victory inside: made money to cut people that no one will miss because it was a political orphan.
* i.e. "What does my boss' boss' boss' boss think their marching orders are?" -- the MBAs won, so it's a non-sequitor for them to think it is about products, quality, consumers, or simply doing the right thing. In order its spend less $, AI, get more $.
Porkbun seems extremely competent, and they allowed me to register two yubikeys, reinforcing that. Hopefully we won't be back here in 2 years discussing where to hop to next.
In these types of situations I’ve been in, usually the developers already complained, and it’s really not the fault of the developers.
This creates this weird situation where developers have to do more and more to protect themselves from situations like this.
It doesn’t take more than a few seconds of thinking to realise that google should have made some kind of way for authentication to be transitioned over. Even something as simple as sending out a “transfer” email link or even just an api that squat space could have called to allow customer transfer verification.
Correct, you also need enforcement.
> The lowest guy on the payroll has no leverage beyond leaving. Companies have no reason to change what they are doing.
Leaving is a huge leverage. Even easily replacable corporate drones cost a lot to replace. If a company needs to find someone willing to risk going to prison they will are much less likely to be successful.
It is already criminal for people to hijack websites like this. It is also criminal to defraud people.
If you are damaged by a company's negligence in this way you just sue them.
This isn't as hard as seems. I've known people that make it a practice to take corporations to small claims court every time there is a data breach or some other problem with a company that has a account with them. It is usually pretty easy to win those sorts of cases as Judges have little sympathy for these mega corporations.
If you are lucky and the company involved is actually incompetent then chances are they won't respond to the small claims lawsuit and you win by default. Get whatever you asked for.
How is it possible that this team blew off backup functionality for a product that is targeted at low skill end users? Maybe they ran out of money paying designers for yet another template that utilizes a full screen image on the landing page?
That sounds to me like the perfect target market for blowing off backup functionality. That market doesn't demand that functionality. Backups are something that a more technically-literate purchaser might demand.
https://securityalliance.notion.site/A-Squarespace-Retrospec...
> As Squarespace has yet to release an official statement or postmortem, the following is our strongest theory on how the threat actor was able to gain initial access to Squarespace accounts. It is the most likely explanation given the information we collected from numerous affected companies and experiments we ran ourselves.
Any recommendations for a quality domain registrar? Might as well get started with the migration
Hard to please everyone I guess.
And exactly, I expect clear and correct communications. If you say "your domains will automatically renew in 1 month" then it needs to be in one month.
So, my process now is to put DNS service OUTSIDE the registrar - so that switching one doesn't have to impact the others.
Why these providers don't let me create the NS Zone before transfer confounds me.
IIRC Spaceship (Namecheaps soft-relaunch) lets you set up your DNS records as soon as you initiate a transfer to them, before it completes, so the records are ready as soon as the nameservers switch over. Not sure about the original Namecheap, I haven't used them for a while.
Domain registrars, however, usually do not operate forwarding DNS resolvers. They typically only answer queries for zones that they are responsible for, and give you an NXDOMAIN response for anything else. For this reason, nobody would use a non-forwarding DNS as a resolver for their computer since it would make it near impossible to reach hosts on the Internet (unless you happen to query a record for one of the zones they provide service for).
They say they sell domains at cost, which is a red flag since it means people who only use them as a register are going to be the first to go when they start loading up the enshittification bandwagon.
I don't care about the price of domains. They're relatively cheap even with the mark up from your typical registrar. What I care about is peace of mind that I won't lose my domain due to an incompetent registrar, or will have to scramble to transfer everything again because of reasons outside of my control. Cloudflare doesn't offer that.
I've now decided to move to Namecheap. Idk how solid they are, but they seem to have been selling domains for a very long time.
I have emailed some former clients I knew to use Google Domains just as a heads up, with steps from the article.
It would be nice if Squarespace showed a modicum of ownership for their failings here.
When a registrar registers a domain, that costs the registrar money because the registrar has to pay a fee to the registry. So a registrar generally cannot give out domains for free.
Now, a registry could in decide to charge no fee. That's what .tk used to do. So you could get a .tk domain for free. Of course then .tk domains got the reputation of being cheap junk and spam.
Also keep in mind that domains are a “source of truth” unlike certs, which rely on the domains for verification.
Damn.
I think I'm going to switch from fintech to cybersecurity.
The defense side sucks. You have to deal with security vendors that are eager to sell you snake oil. You have to actively fight against management that wants to save money. You have to fight against users who don't care about security.
If everything goes smoothly and you have no security problems, the bosses wonder why they even pay you. If you have a security incident, the bosses wonder why they even pay you.
I remember reading the Domains announcement and thought to myself - “you have to be a fool to trust Google to host your domains long-term”. Feels good to be right, but I feel bad for everyone who jumped on the bandwagon. I cant imagine trusting Google products to last those days.
Schnikey.