A former Gizmodo writer changed name to 'Slackbot', stayed undetected for months
1–10 of 140 posts
Re: A former Gizmodo writer changed name to 'Slackbot', stayed undetected for months
#2Best place to hide is something that looks like a service account everyone is afraid to touch for fear of what will break if disabled. Well played!
Re: A former Gizmodo writer changed name to 'Slackbot', stayed undetected for months
#3[deleted]
Re: A former Gizmodo writer changed name to 'Slackbot', stayed undetected for months
#4> Of course, not every company will fall for this trick
The company can have the last laugh: https://en.wikipedia.org/wiki/Computer_Fraud_and_Abuse_Act
Re: A former Gizmodo writer changed name to 'Slackbot', stayed undetected for months
#5> Of course, not every company will fall for this trick The company can have the last laugh: https://en.wikipedia.org/wiki/Computer_Fraud_and_Abuse_Act
This was my first thought on the "silly prank" line.
Re: A former Gizmodo writer changed name to 'Slackbot', stayed undetected for months
#6Best place to hide is something that looks like a service account everyone is afraid to touch for fear of what will break if disabled. Well played!
[deleted]
Re: A former Gizmodo writer changed name to 'Slackbot', stayed undetected for months
#7Normally an organization would have this protected via SSO & thus the deactivation of the employee's account on Gizmodo's systems would have kicked them off of the company's slack. Just another reason why it's valuable to avoid non-SSO 3p cloud apps so that "who's an active user" has a single source of truth.
Re: A former Gizmodo writer changed name to 'Slackbot', stayed undetected for months
#8it was a joke Verge
Re: A former Gizmodo writer changed name to 'Slackbot', stayed undetected for months
#9This reminds me of a glorious day at my consulting company ca. 2016 when we discovered that we could change each other's names on Slack. At one point everyone was just named dad.
Re: A former Gizmodo writer changed name to 'Slackbot', stayed undetected for months
#10I knew an ex-employee back in the day (not me I swear) who created a dialup/ISDN provisioning profile called 'Ringing' in the modem rack controller module (not the Radius server, that would be too obvious), such that a glance at the modem rack status page showed everyone who was connected, and one that was 'Ringing', just like any other incoming call that hadn't been picked up yet. It went completely undetected, yielding 128Kbit ISDN service for well over a year.
Obviously I do not advise this, especially now that the CFAA has been interpreted to include things like changing URL parameters and flicking boogers on the carpet.