Fwd: [Action Required] Authenticate with API Keys

30 views
Skip to first unread message

Attila-Mihaly Balazs

unread,
Oct 17, 2020, 8:02:03 AM10/17/20
to Java Advent Coordination
Hello all,

As per the below email, I added two factor authentication to this SendGrid account. I do believe this is being used by the javaadvent blog, so let me know if something breaks and if I can assist with updating the settings (I think the blog needs to be set to use "API key" instead of user/password).

Best,
Attila

---------- Forwarded message ---------
From: SendGrid Security <sendgr...@sendgrid.com>
Date: Sat, Oct 17, 2020 at 1:13 AM
Subject: [Action Required] Authenticate with API Keys
To: <x_at_...@yahoo.com>


 
SendGrid

Hello Attila-Mihaly,

We are emailing to inform you of an upcoming requirement to update your authentication method with Twilio SendGrid to API keys exclusively by November 18th, 2020 in order to ensure uninterrupted service and improve the security of your account. Our records show that you have used basic authentication with username and password for one or more of your API requests with one or more users of your SendGrid account in the last 180 days.

Why API keys?
This is an effort to enhance security for all of our users. Using your account username and password for authentication is less secure than using an API Key. Unlike your username and password, API Keys are uniquely generated and can be set to limit the access and specify permissions for a given request.

What action is required?
Follow these steps to identify and replace your authentication method to API Keys and then implement Two-Factor Authentication (2FA) for enhanced security.

What happens if no action is taken?
On November 18th, 2020 we will no longer accept basic authentication with username and password, and we will be requiring 2FA to login to your account. If you attempt to authenticate your API requests or SMTP configuration with username and password for any of your users after that date, your requests will be rejected.

We’d like to thank you in advance for your prompt attention to these requirements. If you’d like to learn more about how you can enhance the security of your account, view this post. If you have any questions or need assistance, please visit our documentation or reach out to our Support team.

Thank you,

The Twilio SendGrid Team

SendGrid

Send with Confidence

© SendGrid Inc. 1801 California St., Suite 500, Denver, CO 80202 USA

Blog GitHub Twitter Facebook LinkedIn

 
You received this message because you are a SendGrid customer. If you would prefer not to receive these emails in the future, you canupdate your preferencesorunsubscribeat any time.

 

Holger Steinhauer

unread,
Oct 26, 2020, 2:44:16 PM10/26/20
to Java Advent Coordination
Oh, we are using sendgrid? I think I reconfigured it to one of my mail servers, but might be a good idea to use sendgrid instead. We need to evolve anyways (yeah, I said the same last year and the year before and the one before...) Let's catch up on this later.
Not sure, but iirc sendgrid supports teams? If so, you could add me and maybe Mani and Olimpiu and well? Just thinking out loud ;)

Attila-Mihaly Balazs

unread,
Nov 10, 2020, 12:21:52 AM11/10/20
to Holger Steinhauer, Java Advent Coordination
I think it's for account confirmation / password reset, and based on the dashboard it seems to still be used:

image.png

Unfortunately it doesn't seem like I can add "teammates" without upgrading to a non-free tier. In fact it seems like the lowest paid tier which supports "subuser management" is $90/month! Let me know how you would like to proceed. Maybe it's the easiest to "give this account" (ie. change the login details) to either you or Olimpiu? (since I don't use it for anything else)

Best,
Attila


--
You received this message because you are subscribed to the Google Groups "Java Advent Coordination" group.
To unsubscribe from this group and stop receiving emails from it, send an email to java-advent-coordi...@googlegroups.com.
To view this discussion on the web, visit https://groups.google.com/d/msgid/java-advent-coordination/e184ee59-42a6-40dd-80d0-538e2a7a25c5n%40googlegroups.com.

Holger Steinhauer

unread,
Nov 17, 2020, 4:10:35 AM11/17/20
to Java Advent Coordination
VERY intersting. We should investigate this! Thanks for letting us know!

Holger Steinhauer

unread,
Nov 30, 2020, 7:11:54 AM11/30/20
to Java Advent Coordination
Hey ya.

So, by sheer coincidence, I found out that we actually do use SendGrid for emails. The challenge is now to get this from the spam lists. Just got approached by a new author and he never got the initial activation email :(
I assume this might be something we should accommodate with appropriate DNS settings. Any chance you could give me some access to that SendGrid account? Or send me instructions given from SendGrid?
Any details with credentials or similar might be worth sending to hol...@steinhauer.software. They shouldn't be in here as well. The rest of the discussion can be public ;)

Cheers,
Holger

Attila-Mihaly Balazs

unread,
Dec 1, 2020, 7:37:42 AM12/1/20
to Holger Steinhauer, Java Advent Coordination
Sent you an email with the username / password. See if you can use it or if further assistance is needed from my part. I deactivated the 2-factor authentication since it was tied to my phone number and tried to re-login to verify that it works. But now it insists on me providing a new phone number for two-factor auth. See if you manage to set it up with the provided username / password and a phonenumber of yours.

Best,
Attila

Holger Steinhauer

unread,
Dec 1, 2020, 12:31:05 PM12/1/20
to Java Advent Coordination
Awesome, will check and let you know. Will also try to get my user to access this one, so we can both work on it and you can re-enable the TOTP :)
Or is this a "just for Java Advent created account"?
Then I would totally own it soon :D

Attila-Mihaly Balazs

unread,
Dec 2, 2020, 11:37:23 AM12/2/20
to Holger Steinhauer, Java Advent Coordination
This is a "just for Java Advent created account" so feel free to take it over completely.

Best,
Attila

Reply all
Reply to author
Forward
0 new messages