Live data from Hacker News

HipChat security notice

blog.hipchat.com

41–50 of 119 posts

Re: HipChat security notice

#41
post #40

The HipChat desktop client had a trivial MITM vulnerability which took them several months to fix after I reported it. They never made any kind of public notice about it, so I'm almost surprised to see them talking about security here.

Where does that vulnerability report fit in with the Atlassian acquisition? (circa spring 2012)

It was first reported around this time last year, so "after".

Re: HipChat security notice

#42
post #4

Needless to say their (login) servers crashed from the pressure of people resetting their credentials. "Hey, you know what might be a good idea? Let's email all of the accounts at the same time using an Appriver blast!" Atlassian. I hate to hate you.

While I can see your point in this case I think it was the appropriate action, their ops team should've just beefed up their resources in conjunction with the email blast. Only emailing a rolling amount of your customers becomes a shit show of support, who do you email first? Who do you email last? How long do you wait between groups? For who is security important, your biggest customers, highest paying, most securit…

The servers should have definitely been prepared for the increased load. Perhaps I'm overly optimistically using the plural form in this case.

Truth to be told I can only assume this was done in a short burst, given my limited sample of (hopefully ever narrowing) circle of people who use Atlassian products. But would distributing the bulk-mail over an hour (two, three) using a randomized sample of their customer base really made a significant impact to security or their support?

I wonder how I'd do it, really, if let's say, beefing up my infrastructure for some reason isn't an option.

Re: HipChat security notice

#43
post #36

Earlier quoted context omitted.

>Open source code now carries a moral maintenance obligation? Many have always argued that it has. >Do we say the same thing about any large company that uses openssl or any other open source libs that people use or depend on? Many do. >That doesn't seem fair or reasonable. Many argue that any company that failing to contribute to the OSS projects they depend upon isn't fair or reasonable.

> Many have always argued that it has. Alright, I'm arguing that it doesn't. > Many do. shrug I don't. > Many argue that any company that failing to contribute to the OSS projects they depend upon isn't fair or reasonable. This sort of attitude bothers me. At this point the software is not really free in my opinion. I am not a lawyer :P Just my $0.02

Nothing in life is free.

Quality software doesn't create itself out of thin air (yet, if ever). That means someone has to make an investment.

You don't have to invest in the upkeep of the foundation of your house, but if some bugs, say termites, were to sneak in you can't blame the original builders for the donated foundation.

Please downvote for the bad analogy.

Re: HipChat security notice

#46
post #33

Earlier quoted context omitted.

To use an analogy, do you blame everyone that has ever used the linux kernel whenever bugs/vulnerabilities are discovered in the kernel?

I would certainly blame Google if their Android phones were backdoored, especially if they tried to foist the blame off on the Linux kernel developers - a much more apt analogy since they sell Android phones.

I would be very surprised if something as complicated as Android phones didn't contain anything that can be back doored.

Obviously that is Google's problem, but I haven't seen Google (nor Atlassian in this case) claim anyone else is to blame.

Re: HipChat security notice

#47

Doubt this will be a popular view around here, but using a 3rd party service for internal business communications is just a bad idea. I've seen companies posting root passwords, ssh keys, salaries, internal financial details, etc in Slack and HipChat. Just waiting for a disaster to strike, adding value for every additional company to the target. Maybe this breach won't be the last straw, but it's a consistent risk. Y…

In my experience, using irc or xmpp mostly results in people not using it unless a) the team is largely technical or b) there's a common, easy interface like gchat used to be.

Re: HipChat security notice

#48
Do they really need a captcha on BOTH username AND password input? I get that they are different submit pages, so they are likely querying the database on each page, but is that really necessary? I don't see any benefit from it, as a user, while trying to log in to my account.

Re: HipChat security notice

#49
post #7
post #6

Earlier quoted context omitted.

More importantly, I wonder how much they were paying for this library, or to what extent they were supporting it internally. Because if the answer is zero and they weren't, I would put a lot of the blame on HipChat engineering.

I'm not sure I understand you - You would blame the users of a third-party library if the library was found to have a vulnerability and it was exploited against the people using the library?

This really depends on the use case of the library. It's entirely possible to find bugs that are outside your expertise to fix.

I can't speak to this case, obviously.

Post reply on HN