7 ms·
Tell HN: Stytch Login SaaS Unicorn has common auth vulnerabilities
_TL;DR_: Stytch, a Login SaaS Unicorn, has no CRSF-protection in their authentication API and other questionable security practices, coupled with a nonexistent security policy.
First of all: Why am I posting this on Hacker News instead of disclosing directly?
From experience, a lack of security policies and of communication on existing vulnerabilities implies retaliatory practices when submitting vulnerabilities responsibly. Since MITRE CVE does not accept vulnerabilities for SaaS services, I figured that Hacker News would be the way to get Stytch aware of their issues without getting me in the crosshairs.
The setting:
A few weeks ago (in June 2022 to be exact) I was looking at different authentication services and Stytch was one of the services that got my attention. Stytch.com was founded in 2020 with over $125M [1] raised at a $1bn+ valuation [2].
Checking out what the fuzz was about I decided to look into their security practices. The lack of a bug bounty program (e.g. HackerOne), ethical disclosure policy, and security policy already left a bad feeling. But I was keeping an open mind and wanted to see what their API has to offer.
The scoop:
The most critical issue I came across was a complete lack of Cross-Site Request Forgery defenses. All of the provided authentication APIs (e.g. [4]) except for Social Sign-In are vulnerable to the most basic of login attack vectors: Login CSRF [3]. This can be used to steal credit card information, for example. CSRF is completely missing in all of the Stytchs API concepts, a major oversight in the API design.
Further I found that the OTP tokens sent via their "passwordless" email authentication were valid for up to 7 days and did not invalidate on use. Attackers may find old magic link tokens in the browser, chat, or email histories and use them to get a valid session. While this issue has been fixed since June 2022, the vulnerability was not disclosed to customers.
Recently, Stytch has introduced a concept from OAuth2 called PKCE - a spec that is difficult to master for everyday developers - into their non-standardized Magic Link API which does not use a three-legged delegation authorization mechanism. This is not a direct vulnerability per se, but at least a questionable choice in terms of security.
A full report can be found here for anyone interested: https://www.klgrth.io/paste/kmxof
[1] https://www.crunchbase.com/organization/stytch-auth
[2] https://stytch.com/blog/announcing-series-b/
[3] https://cheatsheetseries.owasp.org/cheatsheets/Cross-Site_Request_Forgery_Prevention_Cheat_Sheet.html#login-csrf
[4] https://stytch.com/docs/passcodes#sms_auth
- mooreds 4y agoDisclosure: I work for a competitor of Stytch, FusionAuth. First, I'm sorry you felt you had to post this on HN to both alert users and not be retaliated against. I wish you'd had an avenue to disclose the issues less publicly. This would allow the company to fix them and not put their customers at risk. I think every company, and certainly every auth company, should welcome security issue reporting, as well as take other steps like regularly paying for pen testing. We do ( https://fusionauth.io/security https://fusionauth.io/security ). However, I haven't looked at how Stytch implemented PKCE, but it can provide CSRF protection in some scenarios. The bigger picture is that this is just another reason to not invent your own standards. Use options like OIDC and benefit from the hard won wisdom of others. Other reading: * https://datatracker.ietf.org/doc/html/draft-ietf-oauth-security-topics https://datatracker.ietf.org/doc/html/draft-ietf-oauth-secur... the OAuth Security BCP * https://owasp.org/www-community/attacks/csrf https://owasp.org/www-community/attacks/csrf CSRF attack description
- lvh 4y agoThey did have such an avenue, they elected not to use it.
- likmithril 4y ago[dead]
- EToS 4y agoCould be an interesting marketing approach for a Security/Pen Test SaaS.. Heres a vulnerability, pay for our service and we'll provide a full report.
- senko 4y agoI get spam for that all the time - both for "pen test" and for "seo test". Basically someone fires up a tool that checks a few things mentioned in a best practices document somewhere, scans as much domains as possible, and then sends out emails with the (subset of) the results. Invariably, the results are false positives but hey, if you don't know that, they might get a new client. They'll file the (automatically generated) report and presto, easy money and a chance to upsell a retainer.