4 ms·
The password reset mail is yet another train wreck. I received this email. The reset password link in it is NOT https. If I manually change the http to https i
by eastern 4y ago
The password reset mail is yet another train wreck.
I received this email. The reset password link in it is NOT https. If I manually change the http to https it turns out that the server, click.msg.salesforce.com, is returning a certificate that is only valid for click.s10.exacttarget.com
- 0des 4y agoI assumed that was a phishing email and didn't proceed.
- sjhuang26 4y agoIf it isn't a phishing attempt it would be really surprising to me that they would use http. BTW, https://exacttarget.com https://exacttarget.com redirects to an official Salesforce product page, but that doesn't guarantee it to not be phishing.
- infamouscow 4y ago> If it isn't a phishing attempt it would be really surprising to me that they would use http. Why? Technical incompetence is a systematic problem that comes from the top down. This is what happens when mediocrity becomes acceptable and takes priority over correctness. I would suggest moving all of your business from Heroku ASAP. These kind of mistakes strongly suggest nobody capable of intelligent thought makes decisions at Heroku, nor has for awhile.
- memorable 4y agoThe website seems to be down at least for me.
- zeepzeep 4y ago> If it isn't a phishing attempt it would be really surprising to me that they would use http Spammers are the first to adopt https and all the mail and dns security stuff. It never was a sign of legitimacy
- nomilk 4y agoI think all this link does is redirects to the 'Reset password' page (i.e. https://id.heroku.com/account/password/reset https://id.heroku.com/account/password/reset), with email address pre-populated, then shows a button to email the user a separate reset password link. So I think the lack of 's' in http in the original link doesn't matter. If I'm wrong, could you please explain why (I am reasoning as best I can, and am not an expert, and keen to learn).
- Froogo 4y agoI guess a concern could be that since this URL is insecure, it could redirect you wherever assuming your network is compromised (either their malicious URL, or even HTTP for the legit Heroku site assuming you don't have HSTS on it). Obviously, you've checked the URL and seen that it's legit after, but realistically you should expect a legit email to not be feeding you a potentially insecure link.
- tialaramex 4y agoRight. If you're on top of things then using plain HTTP links here didn't make anything worse, but if you aren't it's yet another unnecessary gift to bad guys because it's yet another opportunity for customers to get phished.
- Froogo 4y agoSorry, meant if the end user's network was compromised, not the server's. Whether or not you're on top of your game, HTTP leaves you vulnerable to MITM attacks[0]. So this would leave the end user vulnerable to any of these attacks even assuming Heroku has everything else perfect. [0] https://en.wikipedia.org/wiki/Man-in-the-middle_attack https://en.wikipedia.org/wiki/Man-in-the-middle_attack
- eastern 4y agoYou are right, by itself it doesn't matter. All Heroku users should be smart enough to figure this out themselves. However, Heroku should also be smart enough to figure out that all links should be https and servers should have valid certificates. For a company to make such basic security-related mistakes while in the middle of a bad security incident doesn't look good, to put it politely. It sort of explains how they got where they are.
- kevincox 4y agoI use HTTPS-only mode in Firefox and this is incredibly common. I think a lot of services are sending all mail through a click-tracking services and a lot of these redirect via HTTP.
- zoomzoom 4y agoAlong with the vague status updates that provide no information, this has been the most shockingly bad part of the response from my POV, as well. This felt like a phishing email (I know it is not, but given that emails were likely compromised along with OAuth tokens, an attacker could totally be sending - even alongside a legit campaign running as announced on their status site). Would have expected a valid HTTPS cert on the links in an email as sensitive as this one! Salesforce isn't a small new startup where this can be understood as a cost of doing business, they are a tier-1 provider to the largest companies in the world. Unacceptable (but still sending #Hugops to the team dealing with this mess!)