Live data from Hacker News

HipChat security notice

blog.hipchat.com

1–10 of 119 posts

Re: HipChat security notice

#4
Needless to say their (login) servers crashed from the pressure of people resetting their credentials.

"Hey, you know what might be a good idea? Let's email all of the accounts at the same time using an Appriver blast!"

Atlassian. I hate to hate you.

Re: HipChat security notice

#6
post #2

I wonder which "popular third-party library" caused the problem

More importantly, I wonder how much they were paying for this library, or to what extent they were supporting it internally. Because if the answer is zero and they weren't, I would put a lot of the blame on HipChat engineering.

Re: HipChat security notice

#7
post #6
post #2

I wonder which "popular third-party library" caused the problem

More importantly, I wonder how much they were paying for this library, or to what extent they were supporting it internally. Because if the answer is zero and they weren't, I would put a lot of the blame on HipChat engineering.

I'm not sure I understand you - You would blame the users of a third-party library if the library was found to have a vulnerability and it was exploited against the people using the library?

Re: HipChat security notice

#8
post #7
post #6

Earlier quoted context omitted.

More importantly, I wonder how much they were paying for this library, or to what extent they were supporting it internally. Because if the answer is zero and they weren't, I would put a lot of the blame on HipChat engineering.

I'm not sure I understand you - You would blame the users of a third-party library if the library was found to have a vulnerability and it was exploited against the people using the library?

I read it as "if it's open-source, a company of Atlassian's size should be being good stewards and taking care of things that are helping them make money."

Re: HipChat security notice

#9
post #8
post #7

Earlier quoted context omitted.

I'm not sure I understand you - You would blame the users of a third-party library if the library was found to have a vulnerability and it was exploited against the people using the library?

I read it as "if it's open-source, a company of Atlassian's size should be being good stewards and taking care of things that are helping them make money."

Open source code now carries a moral maintenance obligation? Do we say the same thing about any large company that uses openssl or any other open source libs that people use or depend on? That doesn't seem fair or reasonable.

Re: HipChat security notice

#10
post #9
post #8

Earlier quoted context omitted.

I read it as "if it's open-source, a company of Atlassian's size should be being good stewards and taking care of things that are helping them make money."

Open source code now carries a moral maintenance obligation? Do we say the same thing about any large company that uses openssl or any other open source libs that people use or depend on? That doesn't seem fair or reasonable.

Not only moral, but mostly legal.

Warranties are not included. So it's a bit lame to blame "a popular third party library".

The OP was trying to say a company of Atlassians size should dedicate the resources to vet (and fix) those libraries if they use them for these purposes.

Post reply on HN