8 ms·
How realistic is it really that Sendgrid's official Facebook, Twitter, blog, and status site were all compromised simultaneously?
by dkulchenko 14y ago
How realistic is it really that Sendgrid's official Facebook, Twitter, blog, and status site were all compromised simultaneously?
- untog 14y agoIf you compromise the Gmail account of the person that controls all of them- quite realistic.
- uptown 14y agoWhich makes me wonder why everybody races to sign-up for ancillary services like Mailbox which just open up additional vectors of attack on people's most-sensitive account.
- MortenK 14y agoMaybe because they like the app more than they fear identity theft.
- rdl 14y agoHonestly, if an email service provider gets hacked on all public channels due to an email password being hacked, you should probably factor that into decisions about what email service provider to use.
- k3n 14y agoThe weakest link is always the user. In the event that an account was compromised, I'd put money on it being 100% due to a naive user.
- nilkn 14y agoBut how realistic is it that there would be no statement at all from the company about the accounts being compromised?
- goodwink 14y agoPretty realistic. Compromises tend to be pretty far-reaching because often the weakest points are single points of failure for many system (email accounts especially).
- hkmurakami 14y agoThey most likely share the same password so that multiple sendgrid employees can post to each of the pages.
- tikhonj 14y agoHmm, given that one of those is compromised, I'd say it's more likely that the rest are as well--Bayesian reasoning and all that. (Yeah, I don't actually know much about probability :P.) People share passwords all the time. Also, if somebody's computer or email account was compromised, chances are that would also give up the credentials for all of the sites.
- Millennium 14y agoIt's quite realistic. Or rather, the possibility that SendGrid's official Facebook, Twitter, blog, and status site all use the same password is quite realistic, and if that's the case then you only have to compromise one site to get them all.
- simcop2387 14y agoTheir blog at least is running wordpress, from wordpress.com. It's possible that they did get compromised somewhere since all of the things seem to be external to them that they did get compromised and they weren't entirely aware of it right away because of the DDoSing. I can't imagine though that they can't have heard of this by now and aren't trying to do something about it if it's fake.