Live data from Hacker News

Wanna know what product your competitor is working on? Try Slack

tanay.co.in

91–100 of 145 posts

Re: Wanna know what product your competitor is working on? Try Slack

#91
As previously stated, this isn't listing the rooms or groups inside a slack account, it's listing the slack accounts that you might potentially be trying to login to.

IMO, this seems like more a security issue of the individual creating slack accounts for, a) naming the accounts for a specific (potentially revealing) sub-set of their company, and b) turning on the feature that allows anyone to create an account if their e-mail matches the domain.

The company I work for uses Slack but has this second feature turned disabled and our company is not listed when you try and sign in with a bogus e-mail account.

Re: Wanna know what product your competitor is working on? Try Slack

#92

This is ugly, and probably much more of a disclosure than most of these companies were expecting. That being said, everyone railing about "unreleased product names" seem to have forgotten this is exactly the purpose of code names: they're pretty much expected to be leaked at some point, but it's okay since the stakes are intentionally low. Use code names!

Except it will forever be called that. A quick example is where I work we have a 'new product x billing' system and it is still called the 'new' one five years later when it is also the only one.

There is some debate internally over whether 'new' refers to 'new as in old' or 'new' as in the opposite of 'renewal'. No one knows why it is called what it is called.

Re: Wanna know what product your competitor is working on? Try Slack

#93
post #92

This is ugly, and probably much more of a disclosure than most of these companies were expecting. That being said, everyone railing about "unreleased product names" seem to have forgotten this is exactly the purpose of code names: they're pretty much expected to be leaked at some point, but it's okay since the stakes are intentionally low. Use code names!

Except it will forever be called that. A quick example is where I work we have a 'new product x billing' system and it is still called the 'new' one five years later when it is also the only one. There is some debate internally over whether 'new' refers to 'new as in old' or 'new' as in the opposite of 'renewal'. No one knows why it is called what it is called.

This reminds me of so many times doing ad-hoc manual ETL with co-workers, e-mailing back and forth files with names like "accounts-final.csv", "accounts-really-final.csv", "accounts-this-is-the-last-one-for-sure.csv", and inevitably descending into obscenity.

Re: Wanna know what product your competitor is working on? Try Slack

#95
post #92

This is ugly, and probably much more of a disclosure than most of these companies were expecting. That being said, everyone railing about "unreleased product names" seem to have forgotten this is exactly the purpose of code names: they're pretty much expected to be leaked at some point, but it's okay since the stakes are intentionally low. Use code names!

Except it will forever be called that. A quick example is where I work we have a 'new product x billing' system and it is still called the 'new' one five years later when it is also the only one. There is some debate internally over whether 'new' refers to 'new as in old' or 'new' as in the opposite of 'renewal'. No one knows why it is called what it is called.

The solution is to use a name that will never get pass legal, like a trademark of another company.

That's what Sun did with Swing, which was originally called Kentucky Fried Chicken[0] internally.

[0] https://blogs.oracle.com/thejavatutorials/entry/why_is_swing...

Re: Wanna know what product your competitor is working on? Try Slack

#96

Seriously, just the idea of keeping ALL your company internal conversations on a 3rd party server is quite crazy, but to get access without even hacking anything.. I wonder if situations like this will result in business customers more carefully evaluating SaaS solutions that deal with sensitive data, because "in-house" solutions may be old school, but at least a) no one will suddenly terminate the service and b) all…

It beats me to see so many Microsoft and google teams. Don't they have their own tools to do this securely. Leaking of business conversations can have serious implications on many areas from financial to legal. If an employee leaves the company how that will be handled.

What conversations are being leaked? It's a list of team names.

Re: Wanna know what product your competitor is working on? Try Slack

#97

Nice, they eat their own dogfood http://imgur.com/Xs2QRZa

Slack is super dogfood in the sense that it was built and used internally while building another product, and only productized when the original idea failed (like the founder's previous project Flickr).

Re: Wanna know what product your competitor is working on? Try Slack

#99
While I understand how disclosing group names of customers is a bad idea, everyone here jumping on how serious of a security vulnerability this is is missing the fact that it is a feature, not a bug. It's not disclosing anything that was ever intended by the Slack UX designers to be undisclosed, they clearly thought about it and decided to make this tradeoff. This is arguably bad judgement, but it's far from the gross incompetence and negligence that most comments here seem to be frothing at the mouth to proclaim. These are group names, not any internal communication or private data. In a world of Shellshocks and 8-figure credit card thefts direct from PoS systems, there is simply no way this qualifies as a "serious security vulnerability".

Re: Wanna know what product your competitor is working on? Try Slack

#100
post #92

This is ugly, and probably much more of a disclosure than most of these companies were expecting. That being said, everyone railing about "unreleased product names" seem to have forgotten this is exactly the purpose of code names: they're pretty much expected to be leaked at some point, but it's okay since the stakes are intentionally low. Use code names!

Except it will forever be called that. A quick example is where I work we have a 'new product x billing' system and it is still called the 'new' one five years later when it is also the only one. There is some debate internally over whether 'new' refers to 'new as in old' or 'new' as in the opposite of 'renewal'. No one knows why it is called what it is called.

That's why you give it a nonsense name. Windows XP was codenamed 'Whistler'. Nobody calls it Whistler (except when reminiscing about the warez scene). https://en.wikipedia.org/wiki/List_of_Microsoft_codenames https://en.wikipedia.org/wiki/Code_name
Post reply on HN