Keybase CEO here. Let me tell a quick story. January 2019. I was loading the car to leave for a short family ski vacation when I got a truly horrifying email: that my slack account had been accessed from a distant land (that I hadn't been to). There goes my weekend! When we first started Keybase, we used Slack as other teams did, but were gradually moving all Slack-based workflows over to Keybase. As such, we didn't…
I think if this happened to me I would just assume the company was hacked due to poor security practices. It seems much more likely than my password being stolen from a device of mine considering that a very significant percentage of companies I have account with seem to have had breaches at some point. But maybe I am just naive.
New information about Slack’s 2015 security incident
31–36 of 36 posts
Re: New information about Slack’s 2015 security incident
#321. They knew about the malicious code in 2015 and chose to misrepresent the breach, effectively lie to customers. (note that they didn’t reset passwords in 2015, take that how you will)
2. They didn’t know about the malicious code until somewhat later, and they chose not to inform anyone.
3. They only discovered it recently and they were muddying the water as much as possible to make it look like it was part of the 2015 breach
It turns out it was somewhere between (1) and (2). They've since revealed the did know about the issue soon after that notification, but chose only to disclose it to small number of users who they believed to be effected.
https://twitter.com/SlackHQ/status/1152005165802614786
> We initially believed those credentials to be the result of malware or password re-use between services and took immediate action to protect accounts. However, we later concluded the majority of credentials were from accounts that logged in to Slack during the 2015 incident.
But it turns out it effected a much wider pool of people, and they continue to misrepresent the nature of the breach and it's impact. Their communications are very carefully crafted to downplay the situation or muddy the timelines. Even the title of this piece "New Information...". The information is 4 years old, they're only coming clean now!
Slack had an adversary capturing plain text passwords in 2015 and didn't disclose this to potentially effected users. This is a massive trust issue.
Re: New information about Slack’s 2015 security incident
#33Strange, the 2015 report says nothing about inserted code. Did they not know about it until 2019?
Re: New information about Slack’s 2015 security incident
#34Earlier quoted context omitted.
I think if this happened to me I would just assume the company was hacked due to poor security practices. It seems much more likely than my password being stolen from a device of mine considering that a very significant percentage of companies I have account with seem to have had breaches at some point. But maybe I am just naive.
I think it’s different depending on who you are and what systems you have access to. The Keybase CEO is much more vulnerable to targeted attacks where 0-days would be potentially worth the cost.
Re: New information about Slack’s 2015 security incident
#35I'm surprised how under reported this has been. There were basically three scenarios: 1. They knew about the malicious code in 2015 and chose to misrepresent the breach, effectively lie to customers. (note that they didn’t reset passwords in 2015, take that how you will) 2. They didn’t know about the malicious code until somewhat later, and they chose not to inform anyone. 3. They only discovered it recently and they…
Re: New information about Slack’s 2015 security incident
#36Keybase CEO here. Let me tell a quick story. January 2019. I was loading the car to leave for a short family ski vacation when I got a truly horrifying email: that my slack account had been accessed from a distant land (that I hadn't been to). There goes my weekend! When we first started Keybase, we used Slack as other teams did, but were gradually moving all Slack-based workflows over to Keybase. As such, we didn't…
>Additional security features: As of January 2018, we began sending an email every time your account is accessed from a new device; this is a simpler and more immediate way for you to be aware of new logins to your account than periodically reviewing your access logs.
(Quote from the "Slack password reset" email they recently sent out to affected users.)