Live data from Hacker News

Show HN: Shadow IT Scan – Uncover SaaS Apps, Users and Risky OAuth Scopes

accessowl.io

31–38 of 38 posts

Re: Show HN: Shadow IT Scan – Uncover SaaS Apps, Users and Risky OAuth Scopes

#31
post #11

What do people think about companies (even small startups) having a rule against random employees signing up for SaaSes? On the one hand, such a rule sounds like stodgy company friction to "getting it done". On the other hand, I see employees putting crucial information across seemingly every SaaS they'd heard of, except for the official place it's actually supposed to go. Making it inaccessible to the people who nee…

Jesus I've seen "newer developers" do dumb shit like need a damn website to pretty-print JSON or change something all to lower case or something instead of just learning to use their tools. In the absence of real mentorship and supervision, guardrails are necessary.

It's not like you have to have a lot of red tape around signing up for SaaSes. "Any employee can sign up for one, you just have to notify us" or "Approval is practically a rubber stamp" is waaaay better than "who knows what they're doing" -- at least you know what's happening and can deal with it later

Every company bigger than 100 people I've been at covers this in the corporate training on the first week. You can't just put the company's data into random textboxes on the internet. And you can't pretend you weren't told. This is how to get fired immediately anywhere with a clue.

Even at a startup, the process could be reaching out to the "CTO" on Slack for 30 seconds. Nobody should just be doing stuff like this with zero oversight, ever, anywhere, unless just none of it really matters, like some sort of complete joke app like something to rate the attractiveness of your college classmates or something

Re: Show HN: Shadow IT Scan – Uncover SaaS Apps, Users and Risky OAuth Scopes

#32

Earlier quoted context omitted.

Nobody without the power to sign contracts in company name can legally register and use a SaaS at work. They can make a personal account and using it amounts to extracting data out of the company.

From a legal point of view that might be true, but I believe people are not aware that this is a problem. They just register, check the "Agree terms of service" box and do whatever they want to do. I saw that often, especially with Marketing.

Then either the mandatory corporate training they signed off on their first day of employment was deficient, or they need to be fired for cause.

Re: Show HN: Shadow IT Scan – Uncover SaaS Apps, Users and Risky OAuth Scopes

#33
post #11

What do people think about companies (even small startups) having a rule against random employees signing up for SaaSes? On the one hand, such a rule sounds like stodgy company friction to "getting it done". On the other hand, I see employees putting crucial information across seemingly every SaaS they'd heard of, except for the official place it's actually supposed to go. Making it inaccessible to the people who nee…

To a lot of computer users, any window on the screen is as good as any other and they just don't have the concept of "I am uploading a file to an external computer that I do not control."

Any company that is reigning in SaaSes is doing so because they have had a bad experience. If you have this privilege, that's cool, but be smart about it. Make a unique account for your business use rather than comingling your personal data, and choose SaaS companies who you would actually be okay having a relationship with, because the relationship WILL get escalated and wouldn't it be nice if it were a cool HN person making the pitch instead of Oracle mailing you an extortion letter?

One of my clients, we had been trying to sell them on corporate groupware instead of personal dropboxes and gmails. The hammer dropped when they got sued and guess what got specified in the evidence search? Not only was executing that search deeply unpleasant for everyone involved, but it also cost a lot more consulting hours than searching a proper groupware would.

Re: Show HN: Shadow IT Scan – Uncover SaaS Apps, Users and Risky OAuth Scopes

#34
post #29

Earlier quoted context omitted.

This severely limits the usefulness of a product like this. Core aspects of the product like workflows and task management should not be tied to a chat vendor in my opinion, and would make me extremely nervous as a potential buyer due to your complete dependence on what SF does with Slack. I’ve also worked places that strongly dislike Slack and won’t touch it since it was acquired by Salesforce. Ironically, your prod…

Depending on the point of view it can also be a strength. Actually many of our customers like that we're in Slack because their people are already there: - no login required to request an access - they don't need to "learn a new application" So for end users that's great. There is still a web app for admins with more details. But I can see where you're coming from. We plan to offer an alternative to Slack to be indep…

It sounds like you may have found your niche with existing Slack customers and if that works for you that’s great.

I don’t agree that this is a “strength”, because it limits the growth potential of the product while coupling critical functions to the whims of a 3rd party vendor. I absolutely do see how it’s beneficial for you in this early stage because it allows you to deliver a straight-forward experience for this particular user base (Slack customers) without building your own UIs. But that position of strength is fundamentally limited to that specific group. Move beyond it, and not only would using the product now require the adoption of a non-standard chat tool, but the core function of your product is completely orthogonal to chat making the Slack requirement also appear really odd. That group won’t have muscle memory for Slack or know all of its key features. That group will not benefit from any of the familiarity your current customers find compelling.

And back when I was a Slack customer (I actually like Slack and prefer it to the alternatives) I’d still be raising concerns because of the tight coupling with Slack features.

Not trying to just criticize your decisions here, but trying to elaborate on an outsider’s perspective as someone who has been in the position to bring this kind of product on board at large companies, and as someone who has dealt with the pitfalls of building products that have 3rd party integrations.

Best of luck to you on all of this and it’s good to hear there’s an alternative on the roadmap.

Re: Show HN: Shadow IT Scan – Uncover SaaS Apps, Users and Risky OAuth Scopes

#35

Earlier quoted context omitted.

If you block marketing from using the tools they want, they will do it anyway but using personal email addresses like Gmail or something like that especially with the generous free tiers.

Which makes it even worse because you cannot detect that then :/ Shouldn't people just be able to try out new things? How can a company be innovative otherwise? And at a specific point (e.g. putting customer data into it), they need to start a proper vendor assessment process.

People can absolutely try new things, but time and time again you cannot trust people to not put sensitive data into those platforms and they continually do.

It's always a balance of information security awareness, culture and technological solutions within an organisation.

Re: Show HN: Shadow IT Scan – Uncover SaaS Apps, Users and Risky OAuth Scopes

#36
post #29

Earlier quoted context omitted.

Slack is required for AccessOwl. It's used for things like approval workflows, task management and notifications in general. What do you use instead?

This severely limits the usefulness of a product like this. Core aspects of the product like workflows and task management should not be tied to a chat vendor in my opinion, and would make me extremely nervous as a potential buyer due to your complete dependence on what SF does with Slack. I’ve also worked places that strongly dislike Slack and won’t touch it since it was acquired by Salesforce. Ironically, your prod…

A lot of companies are MS O365/Teams shops.

Re: Show HN: Shadow IT Scan – Uncover SaaS Apps, Users and Risky OAuth Scopes

#37

Earlier quoted context omitted.

From a legal point of view that might be true, but I believe people are not aware that this is a problem. They just register, check the "Agree terms of service" box and do whatever they want to do. I saw that often, especially with Marketing.

It's not just legal but also the practical point of view. They committed fraud when they clicked that checkbox. It's exactly the same as signing a contract with someone else's name.

Also when you do npm i. That's fraud.

Did you just agree to opt the company into that smorgasbord of licenses?

Re: Show HN: Shadow IT Scan – Uncover SaaS Apps, Users and Risky OAuth Scopes

#38
post #37

Earlier quoted context omitted.

It's not just legal but also the practical point of view. They committed fraud when they clicked that checkbox. It's exactly the same as signing a contract with someone else's name.

Also when you do npm i. That's fraud. Did you just agree to opt the company into that smorgasbord of licenses?

Not really, most (larger) companies have internal policies about that, listing the acceptable licenses. Which is exactly what I said - the employees are given the power to accept the terms. Some employees can sign SaaS contracts, though that's usually much less people.
Post reply on HN