Live data from Hacker News

Slack Security Incident

keybase.io

1–10 of 110 posts

Re: Slack Security Incident

#2
That's a nice sales pitch! A little on the nose, but I think that's ok.

I think one issue keybase still had is it's minimal web presence that sounds to focus too little on what keybase can do for regular users. People need more explaining of the day to day benefits.

Re: Slack Security Incident

#4
post #3

Scary, and certainly doesn't reflect well on Slack. But, do keep in mind that the author runs a company that does compete with Slack in some ways.

I don't think that's relevant.

Poor security practices are poor security practices despite conflicts of interests, and Slack's are certainly extremely poor.

Re: Slack Security Incident

#6
Wow - for a sales pitch fantastic. Many of these security issues leave you little to actually do. This write up provides an alternative.

What’s super bad here is slack misleading about the cause wasting all the users time.

Quick question, anyone use key base - can u give a quick review? Team currently use slack

Re: Slack Security Incident

#7
Not only does Keybase not automatically update its client, there is no way to even figure out if your client is out of date and in need of security updates. Even if you look up the exact version of your installed client, which you can find, there is nothing on the website that says what the most recent version is. The only way to even get a hint is to look on GitHub, and even that isn't accurate; version 4.2.1 is the latest release, but when I download the mac app it's still version 4.2.0.

For whatever problems Slack has, at least I know if there is a new version that I need to install.

Re: Slack Security Incident

#8
Encryption for a business chat app limits the potential users rather significantly, as I understand it. A number of sectors (like banking) have strict rules which require keeping a record of company communications. How does Keybase deal with this, or do they choose not to play in that market?

Re: Slack Security Incident

#9
post #4
post #3

Scary, and certainly doesn't reflect well on Slack. But, do keep in mind that the author runs a company that does compete with Slack in some ways.

I don't think that's relevant. Poor security practices are poor security practices despite conflicts of interests, and Slack's are certainly extremely poor.

From the blog posts slack has released we know nothing about their security practices.

They have a lot of high quality security features and you can see they actually work because they alerted Max that his account was compromised.

Saying their security practices are extremely poor based on an incident they had in 2015 when their company was 1/20th the size it is today is ridiculous

Re: Slack Security Incident

#10
The author would have done well by refraining from using this as an opportunity to make a sales pitch for their startup, as it detracts from an otherwise important message.

Let me see if I have this right:

Slack had a major security breach in 2015. Apparently someone installed malicious code that could even read password inputs in plaintext. They waited 4 years, after growing large and going public, to inform affected users. And in the interim they blamed their users for any related security problems.

Do I have this correct? If so, how is anyone going to defend this situation? And how can anyone put any sensitive data on Slack, or tell their company to do so, and feel good about it now?

I expected some stupid apology note from the CEO on their website if this turns into a bigger issue, which is sort of an anti-pattern at this point...

Post reply on HN