Skip to content

Comment on Impact to DigitalOcean customers resulting from Mailchimp security incidentparent

Comments

That doesn’t make too much sense. An intercepted password reset email requires access to the email account. That’s a whole different scenario.

If both the email and DO account are behind strong, unique passwords, that won’t happen from a mere DO email leak.

Now, if the same, weak passwords are used for both accounts, sure. That’s terrible practice. But it’s also not what the GP was talking about.

The article is about a security breach at a company which sends emails. This scenario requires access to the email, the email account is irrelevant.

I am astonished by the amount of people commenting under an article they obviously didn’t read…

You must be new here.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.