Skip to content

Comment on Security Hole in Sendgrid

Comments

BCC every message is evil, as it can be misused as in this case. SendGrid should never allow that, or at least should flag such behavior. At the minimum, they should notified account owners of this change.

The attacker got SG to change the email on file, so the notification would just be sent to him.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.