Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> People connecting through our VPN have access to an internal-only SMTP gateway machine that doesn't require SMTP authentication.

This part sounds... not great. Even bad actor within org could send messages as someone else: president to payroll etc.



not great indeed. is this organization not under any compliance requirements? unauthenticated SMTP is not going to pass even the laziest of security scans. although neither is VPN access without MFA




Consider applying for YC's Winter 2027 batch! Applications are open till November 2.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: