Live data from Hacker News

HipChat security notice

blog.hipchat.com

61–70 of 119 posts

Re: HipChat security notice

#61

Earlier quoted context omitted.

In my experience, using irc or xmpp mostly results in people not using it unless a) the team is largely technical or b) there's a common, easy interface like gchat used to be.

Why are you giving your employees a choice in the matter of something so important? Set up an XMPP server, tell them that's what is used for internal communication. Period. And if they're too lazy/dumb/entitled to download Adium/Pidgin and enter their email address+password; well, you should probably find better employees.

You probably should not let all your (non-technical) employees install random software they download.

Re: HipChat security notice

#62
post #26
post #18

Earlier quoted context omitted.

I don't think anyone is trying to shift blame, just to explain what happened. I am not affiliated with Atlassian so I'm only guessing.

Sorry, i wasn't trying to imply they shifted blame. But atlassian does bare the legal&moral burden of securing their product here.

I agree with you. I don't agree that they have a moral obligation to make pull requests to the open source library that had the issue. Hopefully they will, but there is no obligation there in my mind.

Re: HipChat security notice

#63
post #43
post #36

Earlier quoted context omitted.

> Many have always argued that it has. Alright, I'm arguing that it doesn't. > Many do. shrug I don't. > Many argue that any company that failing to contribute to the OSS projects they depend upon isn't fair or reasonable. This sort of attitude bothers me. At this point the software is not really free in my opinion. I am not a lawyer :P Just my $0.02

Nothing in life is free. Quality software doesn't create itself out of thin air (yet, if ever). That means someone has to make an investment. You don't have to invest in the upkeep of the foundation of your house, but if some bugs, say termites, were to sneak in you can't blame the original builders for the donated foundation. Please downvote for the bad analogy.

I think of it like the Heartbleed vulnerability - was everyone affected to blame for the vulnerability? Was everyone simultaneously morally obligated to be contributing patches back to openssl? I don't think so.

Re: HipChat security notice

#64

Doubt this will be a popular view around here, but using a 3rd party service for internal business communications is just a bad idea. I've seen companies posting root passwords, ssh keys, salaries, internal financial details, etc in Slack and HipChat. Just waiting for a disaster to strike, adding value for every additional company to the target. Maybe this breach won't be the last straw, but it's a consistent risk. Y…

The best is when people accidentally type their passwords into the hipchat window, which if you have a whole company spread across a few rooms, happens every fucking day without fail. The cloud is not secure, sorry.

Re: HipChat security notice

#66

WTF? I got the email from HipChat. It includes this sentence. Without additional non-techy context "HipChat hashes passwords using bcrypt with a random salt." This is a good example of how not to do mass e-mails targeting the general population.

If they'd just said "We securely store your passwords", they would have tech people with pitchforks and torches about how they need to name their password hashing algorithm.

If they'd explained both ways, somebody would accuse them of the notification being too long as part of a scheme to bury the details below the fold.

As a company reporting an issue, no matter what you do, the internet's gonna nit pick

Re: HipChat security notice

#67

Doubt this will be a popular view around here, but using a 3rd party service for internal business communications is just a bad idea. I've seen companies posting root passwords, ssh keys, salaries, internal financial details, etc in Slack and HipChat. Just waiting for a disaster to strike, adding value for every additional company to the target. Maybe this breach won't be the last straw, but it's a consistent risk. Y…

In my experience, using irc or xmpp mostly results in people not using it unless a) the team is largely technical or b) there's a common, easy interface like gchat used to be.

That's why I suggested MatterMost - it can be self hosted and has a very nice interface. There's also quite good ones for XMPP like Conversations and Spark. Best bet for less technical people is to have suggested quality clients.

Re: HipChat security notice

#68
post #60
post #7

Earlier quoted context omitted.

I'm not sure I understand you - You would blame the users of a third-party library if the library was found to have a vulnerability and it was exploited against the people using the library?

If it's free software? Yes, absolutely. To do otherwise is a chilling effect against hobbyist free-software authors in favor of large companies that have the ability to take on that liability. I, as an individual, want to be able to write code in my free time, put it on GitHub, and let it get popular without worrying that maybe it has a bug in it. If people want to start holding me responsible for it, I'm just not go…

I am absolutely not advocating that the library author be held liable.
Post reply on HN