Well, I didn't receive anything, but couldn't log in either. I had to google this to find out what the hell is going on - error messages on the login page are not helpful either, they just refuse login even after resetting the password.
HipChat security notice
111–119 of 119 posts
Re: HipChat security notice
#112Earlier quoted context omitted.
> Quite a lot of organizations use Spark which is a straight up XMPP client, they also license an enterprise XMPP server. The same open source community (IgniteRealtime.org[1]) that maintains the Spark[2] XMPP client, also maintains OpenFire[3], a very good and easy to setup XMPP server. [1] http://igniterealtime.org/ [2] http://igniterealtime.org/projects/spark/index.jsp [3] http://igniterealtime.org/projects/openfi…
Huh... I was confused when somebody told me they bought an Spark enterprise server license... now even moreso. I think they probably just bought a license for a commercial fork of OpenFire.
That's very possible. Cisco bundled/bundles OpenFire into several of their enterprise appliances, including the Cisco Finesse product. Other companies do similar things. OpenFire is licensed under the Apache license.
There's also the possibility that your friend bought an enterprise license to OpenFire back when it was a commercial product under the name WildFire (Spark was commercial back then too). That would have been many, many years ago, back before Jive Software open sourced WildFire/OpenFire, Spark, Smack (XMPP Java Library), and several other pieces of software for real time communications.
Re: HipChat security notice
#113Doubt this will be a popular view around here, but using a 3rd party service for internal business communications is just a bad idea. I've seen companies posting root passwords, ssh keys, salaries, internal financial details, etc in Slack and HipChat. Just waiting for a disaster to strike, adding value for every additional company to the target. Maybe this breach won't be the last straw, but it's a consistent risk. Y…
Re: HipChat security notice
#114Earlier quoted context omitted.
Serious question: Do you need the non-techy explanation?
no.. but I could be a non IT user using hipchat. This sentence is likely meaningless to me.
Security is hard. Describing security is even harder.
I'm for transparency in security for review, but you can achieve the same via a 3rd party audit.
Just my 2c.
Re: HipChat security notice
#115I miss IRC. All it needs is a few tweaks to bring it to 2017..
Re: HipChat security notice
#116I wonder which "popular third-party library" caused the problem
Re: HipChat security notice
#117Why are they force resetting everyone's password if they are bcrypt'ed?
Re: HipChat security notice
#118I wonder which "popular third-party library" caused the problem
Re: HipChat security notice
#119Earlier quoted context omitted.
In my experience, using irc or xmpp mostly results in people not using it unless a) the team is largely technical or b) there's a common, easy interface like gchat used to be.
That's why I suggested MatterMost - it can be self hosted and has a very nice interface. There's also quite good ones for XMPP like Conversations and Spark. Best bet for less technical people is to have suggested quality clients.