Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
Important Security Notification from Mandrill (campaign-archive1.com)
8 points by nnx on March 18, 2015 | hide | past | favorite | 2 comments


"Parts of Mandrill's infrastructure are hosted with Amazon Web Services (AWS), and we use EC2 Security Groups to control access." then "As a result, a cluster of servers hosting Mandrill's internal application logs was made publicly accessible instead of allowing internal-only access."

Does this mean that security groups (ie. firewalls) are the only line of defense between _the internet_ and customer data?


Leaving aside the time from incident to post, this is an excellent example of incident disclosure. Technical detail, complete list of mitigation actions, specific info on what may have been compromised, and what they're doing to ensure it doesn't happen again. They don't need to use the old "we take your privacy seriously" cliché; their disclosure and actions prove it.




Consider applying for YC's Winter 2026 batch! Applications are open till Nov 10

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: