7 ms·
Again? This is the third incident in ~12 months IIRC. Is every other company hiding their incidents, or are MC developing a habit of actually not "taking the s
by fukawi2 4y ago
Again? This is the third incident in ~12 months IIRC.
Is every other company hiding their incidents, or are MC developing a habit of actually not "taking the security of our users' data seriously"?
- LewisVerstappen 4y agoWell, considering how absurdly expensive they are compared to other ESPs, the money has to be going somewhere?
- iamacyborg 4y agoThey’re expensive for their feature set but cheap compared to most good ESP’s.
- iinnPP 4y agoThe problem that people are overlooking is the profit motives of the people capable of penetrating systems. These motives are dictated by how companies treat security. By: - Feet dragging on free work or extremely low paid work - Not hiring any competent person or not paying enough to attract that person. - Refusing to fix internal problems that create the issues. The reality is, there are so many more people willing to use technology to scam you than there are people employed to stop those people. Probably because these currently bad people are, by design, hard to discover and thus go unaccounted for entirely. Nobody pays for the skillset and what people hire for clearly doesn't work. Until companies see consequences, nothing will change. So expect this not to change. Why on earth are you giving these companies your money and data anyway? It's truly not difficult to avoid breaches. Do a tiny bit of digging into the security model before you unload your list of customers into their servers. Take some bloody responsibility yourselves too.
- BrandoElFollito 4y agoThe third case is very common. I would not even use the word "refuse" Sometimes the legacy system is so legacy that fixing it is a many years project. Sometimes you have such a messy environment that rotating credentials means a general crash. Sometimes you have legacy software that must stay legacy and you cannot patch + that software is so ingrained into your system that you cannot isolate it. Sometimes ... This is all bad design and bad architecture from scratch. Or "good architecture 25 years ago".
- beardedwizard 4y agoWhat exactly does Mailchimp publish about their security model that would allow anyone to predict this breach?
- dividuum 4y agoAs purely an outsider and not OP: it seems their contractors and support people have direct access to critical customer data simply by typing password and/or totp into a form. Seems it’s not always the correct one. * Limiting access (maybe to email subject instead of all content?) might prevent some fallout as it might be more difficult to extract password reset emails sent by customers. * Limiting access from certain IP sources might make it more difficult to use captured login credentials. * Hardware key based authentication might prevent the type of phishing that seems to have happened here.
- iamacyborg 4y ago* Allowing customer to only allow MC staff access for fixed intervals when support tickets are raised.
- iinnPP 4y agoYou should never trust the marketing department to accurately convey any security model and should assume anything published regarding security has been approved by marketing. Avoid companies that require data which isn't required. Overlook companies with previous vulnerability disclosures that leave you facepalming. Ignore companies that pre check marketing anything. Blacklist the companies with GDPR ignorant cookie "consent." Black hole companies that kill the planet to bring you advertising while telling you you're killing the planet. I would make a joke about what remains. It wouldn't be funny. There are still lots of companies left however and those are the ones that gave at least a signal about caring about you. And for the love of all things. If your company is forcing employees to sign up for garbage data farm software, SAY SOMETHING. Your data is important.
- InCityDreams 4y ago>Blacklist the companies with GDPR ignorant cookie "consent." Could you explain further?
- kneebonian 4y agoWhat I've found is it isn't companies won't pay for good people, they very much will, as a sec engineer you can make 200k pretty easily with just a few years of experience in a lot of places. The problem is once these people are hired they come in and aren't given power to do anything, or the "drive for security" isn't actually present in the organization once people realize it might actually force people to focus on things other than pushing features as fast as you can. This issue is further exacerbated by the fact that there is not an insignificant portion of info sec guys that believe they have to come in and save the organization from themselves and that they are the heroic white knight valiantly protecting the company from the unwashed masses of wild wild west cowboy developers and incompetent sys admins.
- rprospero 4y agoI once worked with one of those heroic security guys before. He setup the firewall so that the public website was only accessible from a white list of known up addresses. New users would need to submit their IP address to him in person before they’d be allowed to browse the site. He insisted that this was industry best practice and it took two weeks before the site was online again.
- diarrhea 4y agoAt that point just take it offline entirely. For security of course.
- teknopaul 4y agoMight it be that Mailchimp has Internet facing customer service facilities? Our lot doesn't, if you got and admin user and password that, in itself, doesn't get you very far.