Hacked on Stripe–$41K Gone, No Real Help from Support. What Now?
old.reddit.com
old.reddit.com
It's far more likely that the team behind the said product leaked their Stripe prod key, by mistake, or through another leak (internal IT flaw, "secure" chat), than Stripe leaking random keys.
I also imagine that they'd have had multiple audits making sure someone can't simply get added to their account without proper rights.
The author mentions that this has happened a second time "this morning", but does not talk about ditching the key and using a new key? Does stripe not let you manage prod keys?
... [they ignored the fact that] "our API key was never leaked"
Writing it in bold doesn't make it true, nor factual.I hate to say it, but without any proof and precedent, this reads like user error.
I hope Stripe meets them half-way with some funds recovery options, but it's probably covered by the terms and conditions...
It would be truly extraordinary if Stripe had an internal leak of keys. It’s doubtful that an internal Stripe problem would manifest as an apparently isolated sequence of attacks on a single user for a trivial sum of money (at Stripe scale). Of course, if other reports start appearing of similar issues then it’s a different story.
As written, I agree: This is a sad report, but the person writing it needs to be looking internally into their systems very aggressively because the root problem is very unlikely to be coming from inside Stripe.
Even if they have the ability to issue "do everything" tokens/keys, that should be something they hide on a corner of their UI with lots of warnings about why it's a bad idea and how scoped tokens are what you mean to use unless you really really know what you want. It shouldn't be something you accidentally walk into.
If someone changes the bank account of a business for funds to be sent to - why not have a short (?48 hours) delay in allowing funds to be sent there. Especially if the business has been running a while (not sure in this specific case) with no bank account changes - then its not unreasonable for a built in delay for new accounts to be used.
Coupled with some basic stuff of "new bank account, new express accounts, spike in charges, sudden request(s) for withdraws" seems like something that a smart team in Stripe with their development experience could easily implement as an automated security trigger, and hold the funds pending additional security checks?
I doubt someone who had the ability to access stripe would waste it on a 40k payday. Also I wouldn’t rule out someone internally, however the attack makes it seem it was done by someone who is familiar with draining stripe accounts
There are so many Stripe horror stories it's a wonder they still have a business. The support is borderline hostile to anyone unfortunate enough to have to interact with them.
1. Happy users don’t talk about their experience on the internet, while unhappy users do.
2. You only hear one side of the story, and it’s always negative towards the other party (Stripe).
Would venture to guess the attackers are able to just read the files on the server due to a vulnerability or poor programming.
This sounds like way too many permissions being granted for something used in a storefront.
However what if Stripe could allow their customers (vendors) to limit what IP address(es) their API call could originate from? That would at least add an extra layer of security in the case an API key was leaked.