Earlier quoted context omitted.
In my experience, using irc or xmpp mostly results in people not using it unless a) the team is largely technical or b) there's a common, easy interface like gchat used to be.
Why are you giving your employees a choice in the matter of something so important? Set up an XMPP server, tell them that's what is used for internal communication. Period. And if they're too lazy/dumb/entitled to download Adium/Pidgin and enter their email address+password; well, you should probably find better employees.
HipChat security notice
61–70 of 119 posts
Re: HipChat security notice
#62Earlier quoted context omitted.
I don't think anyone is trying to shift blame, just to explain what happened. I am not affiliated with Atlassian so I'm only guessing.
Sorry, i wasn't trying to imply they shifted blame. But atlassian does bare the legal&moral burden of securing their product here.
Re: HipChat security notice
#63Earlier quoted context omitted.
> Many have always argued that it has. Alright, I'm arguing that it doesn't. > Many do. shrug I don't. > Many argue that any company that failing to contribute to the OSS projects they depend upon isn't fair or reasonable. This sort of attitude bothers me. At this point the software is not really free in my opinion. I am not a lawyer :P Just my $0.02
Nothing in life is free. Quality software doesn't create itself out of thin air (yet, if ever). That means someone has to make an investment. You don't have to invest in the upkeep of the foundation of your house, but if some bugs, say termites, were to sneak in you can't blame the original builders for the donated foundation. Please downvote for the bad analogy.
Re: HipChat security notice
#64Doubt this will be a popular view around here, but using a 3rd party service for internal business communications is just a bad idea. I've seen companies posting root passwords, ssh keys, salaries, internal financial details, etc in Slack and HipChat. Just waiting for a disaster to strike, adding value for every additional company to the target. Maybe this breach won't be the last straw, but it's a consistent risk. Y…
Re: HipChat security notice
#65"This weekend our Security Intelligence Team detected" ... "Security Intelligence Team" ... yeah, because that team actually exists.
Re: HipChat security notice
#66WTF? I got the email from HipChat. It includes this sentence. Without additional non-techy context "HipChat hashes passwords using bcrypt with a random salt." This is a good example of how not to do mass e-mails targeting the general population.
If they'd explained both ways, somebody would accuse them of the notification being too long as part of a scheme to bury the details below the fold.
As a company reporting an issue, no matter what you do, the internet's gonna nit pick
Re: HipChat security notice
#67Doubt this will be a popular view around here, but using a 3rd party service for internal business communications is just a bad idea. I've seen companies posting root passwords, ssh keys, salaries, internal financial details, etc in Slack and HipChat. Just waiting for a disaster to strike, adding value for every additional company to the target. Maybe this breach won't be the last straw, but it's a consistent risk. Y…
In my experience, using irc or xmpp mostly results in people not using it unless a) the team is largely technical or b) there's a common, easy interface like gchat used to be.
Re: HipChat security notice
#68Earlier quoted context omitted.
I'm not sure I understand you - You would blame the users of a third-party library if the library was found to have a vulnerability and it was exploited against the people using the library?
If it's free software? Yes, absolutely. To do otherwise is a chilling effect against hobbyist free-software authors in favor of large companies that have the ability to take on that liability. I, as an individual, want to be able to write code in my free time, put it on GitHub, and let it get popular without worrying that maybe it has a bug in it. If people want to start holding me responsible for it, I'm just not go…
Re: HipChat security notice
#69Why are they force resetting everyone's password if they are bcrypt'ed?