Live data from Hacker News

HipChat security notice

blog.hipchat.com

11–20 of 119 posts

Re: HipChat security notice

#12
post #9
post #8

Earlier quoted context omitted.

I read it as "if it's open-source, a company of Atlassian's size should be being good stewards and taking care of things that are helping them make money."

Open source code now carries a moral maintenance obligation? Do we say the same thing about any large company that uses openssl or any other open source libs that people use or depend on? That doesn't seem fair or reasonable.

>Open source code now carries a moral maintenance obligation?

Many have always argued that it has.

>Do we say the same thing about any large company that uses openssl or any other open source libs that people use or depend on?

Many do.

>That doesn't seem fair or reasonable.

Many argue that any company that failing to contribute to the OSS projects they depend upon isn't fair or reasonable.

Re: HipChat security notice

#13
post #9
post #8

Earlier quoted context omitted.

I read it as "if it's open-source, a company of Atlassian's size should be being good stewards and taking care of things that are helping them make money."

Open source code now carries a moral maintenance obligation? Do we say the same thing about any large company that uses openssl or any other open source libs that people use or depend on? That doesn't seem fair or reasonable.

> Open source code now carries a moral maintenance obligation?

Yes, and it always has and it can't be discharged. Pay-it-forward is the right thing to do.

> Do we say the same thing about any large company that uses openssl or any other open source libs that people use or depend on?

I certainly do. A red line, I-will-quit condition is and always has been "I won't participate in the development of private forks of open-source software" and I have at multiple employers gotten checks straight-up cut to open-source software maintainers. I have also entreated (and in two cases succeeded in convincing) maintainers to start up maintenance programs so we could pay them a yearly fee--because donations are way harder to push than support plans.

And, in turn, I open-source useful tools[1][2][3], including major parts of my consulting business, because it, too, is the right thing to do.

You should do likewise, because it is the decent and human thing to do.

> That doesn't seem fair or reasonable.

I consider not paying forward kindnesses paid to you way, way more unfair and unreasonable.

[1] - https://github.com/bossmodecg

[2] - https://github.com/eropple/auster

[3] - https://github.com/eropple/cfer-provisioning

Re: HipChat security notice

#15
WTF? I got the email from HipChat. It includes this sentence. Without additional non-techy context

"HipChat hashes passwords using bcrypt with a random salt."

This is a good example of how not to do mass e-mails targeting the general population.

Re: HipChat security notice

#16

WTF? I got the email from HipChat. It includes this sentence. Without additional non-techy context "HipChat hashes passwords using bcrypt with a random salt." This is a good example of how not to do mass e-mails targeting the general population.

Serious question: Do you need the non-techy explanation?

Re: HipChat security notice

#17
post #7
post #6

Earlier quoted context omitted.

More importantly, I wonder how much they were paying for this library, or to what extent they were supporting it internally. Because if the answer is zero and they weren't, I would put a lot of the blame on HipChat engineering.

I'm not sure I understand you - You would blame the users of a third-party library if the library was found to have a vulnerability and it was exploited against the people using the library?

I think this is a part of the general meme that big companies are making money by taking open source without giving back, and that big for-profit companies could do more for the open-source community.

Re: HipChat security notice

#18
post #10
post #9

Earlier quoted context omitted.

Open source code now carries a moral maintenance obligation? Do we say the same thing about any large company that uses openssl or any other open source libs that people use or depend on? That doesn't seem fair or reasonable.

Not only moral, but mostly legal. Warranties are not included. So it's a bit lame to blame "a popular third party library". The OP was trying to say a company of Atlassians size should dedicate the resources to vet (and fix) those libraries if they use them for these purposes.

I don't think anyone is trying to shift blame, just to explain what happened. I am not affiliated with Atlassian so I'm only guessing.

Re: HipChat security notice

#19

WTF? I got the email from HipChat. It includes this sentence. Without additional non-techy context "HipChat hashes passwords using bcrypt with a random salt." This is a good example of how not to do mass e-mails targeting the general population.

Serious question: Do you need the non-techy explanation?

no.. but I could be a non IT user using hipchat. This sentence is likely meaningless to me.

Re: HipChat security notice

#20
The HipChat desktop client had a trivial MITM vulnerability which took them several months to fix after I reported it. They never made any kind of public notice about it, so I'm almost surprised to see them talking about security here.
Post reply on HN