4 ms·
> used to access several of our internal systems on three separate dates in February and March 2015. > On April 8, the SendGrid account of a Bitcoin-related cu
by compbio 11y ago
> used to access several of our internal systems on three separate dates in February and March 2015.
> On April 8, the SendGrid account of a Bitcoin-related customer was compromised
If I can gather this right: SendGrid was fully hacked for 3 months on end. At least that is what they were able to recover from forensics, it may have been longer.
This sounds illogical:
> We have not found any forensic evidence that customer lists or customer contact information was stolen. However, as a precautionary measure, we are implementing a system-wide password reset.
How would a password reset help combat information that was stolen before the reset? The password reset is because the systems accessed contained password hashes. Also it may be to upgrade the hashing mechanism to be more secure than "salted and iteratively hashed".
Sendgrid's privacy policy is cookie cutter, but it contains this:
> For example, our policy is that only those individuals who need your personally identifiable information to perform a specific job are granted access to that personally identifiable information.
Apparently the employee that was hacked needed access to the data of all his colleagues and all users.
> Upon discovery, we took immediate actions to block unauthorized access and deployed additional processes and controls to better protect our customers, our employees, and our platform.
Then the Privacy Policy again:
> We will use at least industry standard security measures on the Site to protect the loss, misuse and alteration of the information under our control. While there is no such thing as "perfect security" on the Internet, we will take all reasonable steps to insure the safety of your personal information.
So apparently there were still some reasonable steps left to take, which were forced by this hack, not by 'industry standard security measures'.
> Two-Factor Authentication: We encourage all of our customers to enable two-factor authentication, which can effectively prevent unauthorized logins.
I think you can better encourage (or force) your employees to enable this, so you can prevent unauthorized logins into superuser accounts.
From the Privacy Policy you'd expect they already did this:
> Likewise, all employees and contractors are kept up-to-date on our security and privacy practices.
Then the unspecified hashing mechanism. Should you worry about the chance of account compromise again?
> salts and iteratively hashes passwords
It would be a breath of fresh air if these companies would just say 'We use bcrypt' in their privacy policy.
> Our Ongoing Commitment to Security
Your 3 month struggle with hackers. Also, three reasonable steps follow that could have been taken before this hack, like your Privacy Policy promised us.
> NOTE: We require passwords to be a minimum of 8 alpha-numeric characters. Make sure any new passwords you set conform to this requirement.
Before or after this hack? Why should the customer make sure his password conforms to this requirement? Is it even possible to set a shorter password?
> Security update: Please reset your SendGrid account passwords today. Beginning today, and in line with standard practice, we are requesting that all of our customers reset their passwords to all of their SendGrid account access points.
Why not force this? Asking nicely? Standard practice would be to force this upon next log-in and temp disable accounts that have not changed their password yet.