Ask HN: Bugcrowd Forcing Password Reset

12 points by xyst 16 days ago

Anybody else getting a suspicious e-mail from Bugcrowd to reset your password? Seems their user data has been leaked or infiltrated?

No news reports. No official reports from bugcrowd.com.

(( hope it's not just _poor_ data secops ))

Update: Message itself _seems_ legit. DKIM signed. Originates from AmazonSES. SPF checks out. Link to reset points to bugcrowd.com

eclipticplane 16 days ago

Gotta love a security company using the phrase "for security reasons."

dualbus 16 days ago

Yes, I got a "Reset password instructions" email from support@bugcrowd.com at roughly 11:13 PM UTC. There is no information in the email nor the linked page about why it is necessary.

How am I supposed to trust this...

fallenby 16 days ago

Yeah. Really weird e-mail. "Security reasons" immediately made me assume they were compromised.