Slack was hacked
141–150 of 526 posts
Re: Slack was hacked
#142Host your own IRC if you care about the privacy and security of your communication. There is no reason why you can't take 10min to setup a IRC with SSL on your own. Yes, Slack is awesome, lots of features, but it's not yours!
For the VAST majority of people this would not take just 10 min. Not only would I first need to research the different IRC servers out there but I'd have to get a server to install it on (which is not the fastest processes where I work). Then I need to get an SSL cert (which is like pulling teeth here) unless I want to use self-signed and listen to everyone bitch about dealing with that (and some aren't tech people and I've have to walk them through that). Then I need to find clients for everyone (Windows/Mac/Linux) also now chat is only accessible from inside the company unless I want to expose it publicly then I need to worry about security.....
OR I could pay $X/mo and have it up and running in seconds... Slack is not the end-all-be-all but I quite like it and use it with friends as well as public slacks. IRC is great but let's not pretend it takes seconds to set up everything you need...
Re: Slack was hacked
#143Earlier quoted context omitted.
Incorrect. You can't login with a password hash, you need a password.
If you get the user table, you can crack the password hashes offline, at your leisure.
Of course, I barely know anything about computer security, but at least it should prevent attacks using rainbow tables I think?
Re: Slack was hacked
#144Why do I have to install Google Authenticator some sort of other app for 2factor here? Why can't you send me a text like everyone else does? EDIT: Slack responded that they do not support SMS yet .
Re: Slack was hacked
#145Why do I have to install Google Authenticator some sort of other app for 2factor here? Why can't you send me a text like everyone else does? EDIT: Slack responded that they do not support SMS yet .
Re: Slack was hacked
#146I hate to be the negative guy, and they were hashing passwords better than 90% of the sites, but it would be SO easy to completely neutralize password leakage when the attacker only has access to the database. https://blog.filippo.io/salt-and-pepper/ tl;dr: Hardcode a second salt in your application code or in an environment variable. Then a database dump is not enough anymore to do any kind of bruteforce. It's simpl…
Re: Slack was hacked
#147May be slack wants us to believe only a small part of the data is hacked , I dont know .
We have been using Slack for many projects over last year and it helps improve productivity
Re: Slack was hacked
#148Why do I have to install Google Authenticator some sort of other app for 2factor here? Why can't you send me a text like everyone else does? EDIT: Slack responded that they do not support SMS yet .
Ideally, you want as strong as practical proofs of each half within the constraints set by UX considerations.
Re: Slack was hacked
#149How does one discover that they were hacked? The post states that the breach occurred during February, and this is the end of March... did it just take them a long time to react and write a post about it, or did they likely discover after the fact? If so, how?
Re: Slack was hacked
#150This completely sucks.