Live data from Hacker News

HipChat security notice

blog.hipchat.com

31–40 of 119 posts

Re: HipChat security notice

#31
Doubt this will be a popular view around here, but using a 3rd party service for internal business communications is just a bad idea.

I've seen companies posting root passwords, ssh keys, salaries, internal financial details, etc in Slack and HipChat. Just waiting for a disaster to strike, adding value for every additional company to the target. Maybe this breach won't be the last straw, but it's a consistent risk.

You can run your own MatterMost or XMPP server quite easily and even lock it down to behind VPN only to minimize security risks almost completely.

Re: HipChat security notice

#32
post #7
post #6

Earlier quoted context omitted.

More importantly, I wonder how much they were paying for this library, or to what extent they were supporting it internally. Because if the answer is zero and they weren't, I would put a lot of the blame on HipChat engineering.

I'm not sure I understand you - You would blame the users of a third-party library if the library was found to have a vulnerability and it was exploited against the people using the library?

When you use any third party library, you're responsible for its behaviors (or misbehaviors) on your customer's machine. How is it possible to view this in any other way?

Re: HipChat security notice

#33
post #7

Earlier quoted context omitted.

I'm not sure I understand you - You would blame the users of a third-party library if the library was found to have a vulnerability and it was exploited against the people using the library?

IMO, frankly, yes. If you use someone else's code, especially if you're not paying anything for it, you get what you put into it: nothing. The liability for this breach is ultimately owned by Atlassian, not the third party library writer. To quote the most permissive license out there: "THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NO…

To use an analogy, do you blame everyone that has ever used the linux kernel whenever bugs/vulnerabilities are discovered in the kernel?

Re: HipChat security notice

#34
post #7

Earlier quoted context omitted.

I'm not sure I understand you - You would blame the users of a third-party library if the library was found to have a vulnerability and it was exploited against the people using the library?

When you use any third party library, you're responsible for its behaviors (or misbehaviors) on your customer's machine. How is it possible to view this in any other way?

I 100% agree with you. Atlassian is 100% responsible. I'm not sure I would not say they are at 'fault' though. Maybe I'm just quibbling over semantics.

I don't know the details of the vulnerability - I would say they were at fault if they did not update/patch a fixed vulnerability.

Re: HipChat security notice

#35
My recent password update policy: Wait for a service to be hacked and then change the password to a long hash generated by Keepass. I was thinking of spending a whole day updating all the passwords for all the services I have accounts on but at the rate sites are getting hacked, it won't be long before I have created unique hash passwords for all the sites.

Re: HipChat security notice

#36
post #9

Earlier quoted context omitted.

Open source code now carries a moral maintenance obligation? Do we say the same thing about any large company that uses openssl or any other open source libs that people use or depend on? That doesn't seem fair or reasonable.

>Open source code now carries a moral maintenance obligation? Many have always argued that it has. >Do we say the same thing about any large company that uses openssl or any other open source libs that people use or depend on? Many do. >That doesn't seem fair or reasonable. Many argue that any company that failing to contribute to the OSS projects they depend upon isn't fair or reasonable.

> Many have always argued that it has.

Alright, I'm arguing that it doesn't.

> Many do.

shrug I don't.

> Many argue that any company that failing to contribute to the OSS projects they depend upon isn't fair or reasonable.

This sort of attitude bothers me. At this point the software is not really free in my opinion. I am not a lawyer :P Just my $0.02

Re: HipChat security notice

#37
post #33

Earlier quoted context omitted.

IMO, frankly, yes. If you use someone else's code, especially if you're not paying anything for it, you get what you put into it: nothing. The liability for this breach is ultimately owned by Atlassian, not the third party library writer. To quote the most permissive license out there: "THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NO…

To use an analogy, do you blame everyone that has ever used the linux kernel whenever bugs/vulnerabilities are discovered in the kernel?

I would certainly blame Google if their Android phones were backdoored, especially if they tried to foist the blame off on the Linux kernel developers - a much more apt analogy since they sell Android phones.

Re: HipChat security notice

#38
post #7

Earlier quoted context omitted.

I'm not sure I understand you - You would blame the users of a third-party library if the library was found to have a vulnerability and it was exploited against the people using the library?

IMO, frankly, yes. If you use someone else's code, especially if you're not paying anything for it, you get what you put into it: nothing. The liability for this breach is ultimately owned by Atlassian, not the third party library writer. To quote the most permissive license out there: "THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NO…

Surely that's completely unreasonable. Who can claim that any piece of software is without bugs/security holes?

The problem is absolutely owned by Atlassian, but they actually did do something to fix it.

I don't believe anyone (apart from maybe Daniel J Bernstein) can claim any piece of software is bug/hole free, and neither does anyone need to!

Re: HipChat security notice

#40

The HipChat desktop client had a trivial MITM vulnerability which took them several months to fix after I reported it. They never made any kind of public notice about it, so I'm almost surprised to see them talking about security here.

Where does that vulnerability report fit in with the Atlassian acquisition? (circa spring 2012)
Post reply on HN