Usually I don’t bother with the Email notifications and I check the forum directly.
Today I just clicked on “Visit topic” in the Email to see my threat protection kicking in badly.
https://mandrillapp.com is the culprit in question and seems to be well known for stealing private data from users.
From their website we get this:
What is Mandrill?
Mandrill is a paid Mailchimp add-on, and allows clients to send one-to-one transactional emails triggered by user actions, like requesting a password or placing an order. They’re powerful touchpoints between you and your customers, so we’ve made it easier to make the most of them.
Unlike a normal re-director Mandrill is ‘flexible’ and can be configured in full by the paying user, in this case Bambu.
What makes using this service so concerning is how it works…
For starters Bambu uses exactly what any scammer would use - crypted links following a link to some unknown website.
While the crypted part works fine without the Mandrill part and lands you on the correct forum page there is no way of knowing HOW you landed there.
With the crypted part also containing user log in details any ‘man in the middle’ can take an advantage here…
Checking Mandrill reveals it is a legit service but also a ton of really bad feedback, especially in terms of user data being stolen and abused.
Can Bambu please explain why such a dubious service is used instead of something users can TRUST ?