Skip to content

Comment on Security Hole in Sendgridparent

Comments

The solution is to do what everyone who actually needs authentication from a company does; require a posted signed letter from a director, possibly along with an outbound (from SendGrid to the director) phone call to confirm. There's plenty of low-tech ways to confirm that a company really wants to do something.

Please, no.

Consider a determined attacker. A posted signed letter has zero cost and is easily forged and a phone call is free via Skype. There's plenty of low-tech ways to circumvent security.

How exactly does Skype let me take over a business's phone number? I am saying that SendGrid should call the company to verify, not the other way round.

Ahh sorry, my mistake. I missed the word "outbound".

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.