Live data from Hacker News

Wanna know what product your competitor is working on? Try Slack

tanay.co.in

71–80 of 145 posts

Re: Wanna know what product your competitor is working on? Try Slack

#71
post #2

Wow. This is a very serious security flaw. You should never assume that usernames (especially email addresses) are unknown to attackers.

It doesn't even require a valid email address. It's an obvious side-effect of Slack's completely weird account system.

Re: Wanna know what product your competitor is working on? Try Slack

#72
This seems like one of those things that was intentionally a 'feature' and not an oversight. The oversight was probably not making it clear to users that the team names were effectively public.

I think the "this is why not startups|cloud" posts are a bit heavy handed given the actual details of what we're talking about here.

Re: Wanna know what product your competitor is working on? Try Slack

#73

Seriously, just the idea of keeping ALL your company internal conversations on a 3rd party server is quite crazy, but to get access without even hacking anything.. I wonder if situations like this will result in business customers more carefully evaluating SaaS solutions that deal with sensitive data, because "in-house" solutions may be old school, but at least a) no one will suddenly terminate the service and b) all…

It beats me to see so many Microsoft and google teams. Don't they have their own tools to do this securely.

Leaking of business conversations can have serious implications on many areas from financial to legal. If an employee leaves the company how that will be handled.

Re: Wanna know what product your competitor is working on? Try Slack

#80
post #31
post #11

Earlier quoted context omitted.

The way companies handle security disclosures lately (i.e. laughing it off, or paying $6 reward), it seems like shaming them would work much better. Plus, this is truly a beginner-level failure, the kind you'd get insulted for by Linus.

Slack has a Reporting Security Vulnerabilities page on its site: http://slack.com/whitehat . Seems like something they would have taken seriously if it had been brought to them first.

Apparently it was, see: https://twitter.com/rootlabs/status/499723782244675584
Post reply on HN