Live data from Hacker News

Zendesk was hacked

zendesk.com

61–64 of 64 posts

Re: Zendesk was hacked

#61
post #37

Anybody knows a good alternative? Leaking my personal info is one thing, loosing customers personal info is simply far too boneheaded to begin with.

Nobody is unhackable. They've dealt with this honestly . What makes you think any other service could make further guarantees?

Seconded. The sheer fact of the matter is that the state-of-the-art on offense is outpacing the state-of-the-art on defense. These guys didn't expose any password data, and evidently, not even the contents of the support cases (just the subject lines). That's small potatoes.

Re: Zendesk was hacked

#62
post #46

Earlier quoted context omitted.

But there's a greater than 0% chance that zendesk had an API token for at least one of those services. That could easily allow a hacker to make authenticated requests to those services to gain user info. The fact that usernames and passwords weren't stored on zendesk doesn't mean much, if a hacker can gain full admin access to those other services through an admin token that might have been stored on zendesk.

I seriously doubt any company (especially the three listed) would give Zendesk admin access to their service. Why would such a thing be necessary, anyway?

I think he meant it the other way around. Having their API token would allow the attacker to have access to all of Twitter/Tumblr/Pinterest's information that's accessible via the Zendesk API.

Re: Zendesk was hacked

#63

Earlier quoted context omitted.

There's also Detectify : http://detectify.com They are in beta.

Actually, I've had really bad experiences with Detectify. Their results didn't provide anything useful that I couldn't have gotten from something like Nessus. They have a pretty nice design, but not much in the way of actual useful security.

Dear throaway132, I am one of the founders of Detectify and, like inkel above, I am very curious to hear your feedback regarding your experience using Detectify. Please respond publicly here or DM me at piotr#detectify.com. Looking forward to hearing from you soon!

Re: Zendesk was hacked

#64

Earlier quoted context omitted.

Are you suggesting most popular rails (if not all) apps are upgraded by now?

No, he's suggesting the ones that aren't are run by incompetent people.

If thats the case, there are so many incompetent people.
Post reply on HN