Live data from Hacker News

Wanna know what product your competitor is working on? Try Slack

tanay.co.in

111–120 of 145 posts

Re: Wanna know what product your competitor is working on? Try Slack

#111

Earlier quoted context omitted.

Shaming Slack is one point. This guy just exposed the confidential information of who knows how many of Slack's customers. In my opinion that's douchery of epic proportions.

Maybe this kind of exposure is the only way we will teach people to stop trusting fly-by-night cloud startups with their confidential data?

How about responsibly disclosing to the victims/users before going public?

Re: Wanna know what product your competitor is working on? Try Slack

#112
post #111

Earlier quoted context omitted.

Maybe this kind of exposure is the only way we will teach people to stop trusting fly-by-night cloud startups with their confidential data?

How about responsibly disclosing to the victims/users before going public?

I don't see how that would be possible unless Slack has a full list of their customers available somewhere.

Note that elsewhere in this thread you can see that it was reported to Slack, but they responded saying it wasn't a bug.

Re: Wanna know what product your competitor is working on? Try Slack

#113
post #52
post #39

While I'm unable to comment on the content of the article, I really have to applaud HostGator's error page marketing strategy here. We've met with a horrible fate (status code 500) while generating what appears to be a static page. This site is hosted by HostGator! Get yours now!

If they're generating 500 errors while serving up static sites, someone is doing something very wrong.

Is there a HTTP code for when you've taken the piss with your cheap as dirt shared web host?

Re: Wanna know what product your competitor is working on? Try Slack

#114

Seriously, just the idea of keeping ALL your company internal conversations on a 3rd party server is quite crazy, but to get access without even hacking anything.. I wonder if situations like this will result in business customers more carefully evaluating SaaS solutions that deal with sensitive data, because "in-house" solutions may be old school, but at least a) no one will suddenly terminate the service and b) all…

Productivity trumps those concerns.

for startups yes. For big companies, in my experience, no.

Re: Wanna know what product your competitor is working on? Try Slack

#115
post #92

This is ugly, and probably much more of a disclosure than most of these companies were expecting. That being said, everyone railing about "unreleased product names" seem to have forgotten this is exactly the purpose of code names: they're pretty much expected to be leaked at some point, but it's okay since the stakes are intentionally low. Use code names!

Except it will forever be called that. A quick example is where I work we have a 'new product x billing' system and it is still called the 'new' one five years later when it is also the only one. There is some debate internally over whether 'new' refers to 'new as in old' or 'new' as in the opposite of 'renewal'. No one knows why it is called what it is called.

Except it will forever be called that.

Not as long as you replace it with a new name. Your "new" problem doesn't sound like a problem of stickiness, it's a problem of never giving it an actual name in the first place, or when it was rolled out.

Look at the Orbis and Durango for names widely used in when the press was rumor-mongering that went away as soon as the devices were revealed. We've even changed our internal code names on projects without much fanfare, as long as the name change represents a milestone in the project or a difference in audience it's easy to cut over.

Re: Wanna know what product your competitor is working on? Try Slack

#116

Earlier quoted context omitted.

What conversations are being leaked? It's a list of team names.

By using slack or any other external chat system, you're leaking metadata and comms content.

Leaking to where? By using the internet you're leaking [meta]data. It's a question of degrees and trust.

Re: Wanna know what product your competitor is working on? Try Slack

#117

Here are the ones for: - amazon - ebay - facebook - apple - google http://imgur.com/a/eWLEf

Bad thing is that every facebook user has email id `fbusername@facebook.com`. So you can easily get into any team you want.

Facebook employees use @fb.com

Re: Wanna know what product your competitor is working on? Try Slack

#118

My response to all the people who says it is nothing just the team names Check this screenshot of google teams http://m.imgur.com/a/eWLEf . There is a team name called viber and google doesn't own viber. Check this news that came 2 days back: http://www.jbgnews.com/2014/10/google-looking-to-rival-whats... Connect the dots. You can infer a lot. It is information disclosure at the finest. Smart thing is to accept it is…

How is this the fault of companies using Slack? That's nothing more than victim-blaming.

Re: Wanna know what product your competitor is working on? Try Slack

#119

My response to all the people who says it is nothing just the team names Check this screenshot of google teams http://m.imgur.com/a/eWLEf . There is a team name called viber and google doesn't own viber. Check this news that came 2 days back: http://www.jbgnews.com/2014/10/google-looking-to-rival-whats... Connect the dots. You can infer a lot. It is information disclosure at the finest. Smart thing is to accept it is…

I'm one of the people saying it is just the team names. I'm not doing that to defend Slack - I've always been unhappy with their sign-in process and this is one of the reasons. However, a lot of people are saying that you can list channels, and that's not correct and would be far more concerning.

Re: Wanna know what product your competitor is working on? Try Slack

#120
Sorry that the site was down for long. The site was on poorman's hosting (hostgator) that could not take HN traffic and bogged down.

Cloudflare, along with flatfile caching by Drupal's Boost module came to the rescue. Hope that stays alive for a while now.

Regarding not having disclosed this one discretely to Slack:

* I have considerable experience in a couple opensource projects including Drupal and have reported multiple vulnerabilities on various occasions for various modules discretely (though mostly of lesser significance and a very narrow/rare attack vector) to the right teams through various channels meant for this purpose. As such I am aware of the SOPs for the righteous to follow in case of discovering a vulnerability.

* I don't think this one is a security issue that would take a professional security expert to crack. Nor could this have been not noticed when Slack tested their product. This is an issue with 'common sense'. I am pretty sure that Slack designed it this way. It is just the customers that are surprised now. Not Slack.

Also, it looks like this was reported earlier to Slack by https://twitter.com/rootlabs/status/499723782244675584 a couple of months ago and it was rejected by Slack as "Not a bug". However I do acknowledge that I was not aware of this report when I first published the post and hence can not say that I disclosed it only after being rejected by Slack. I would say it was not a security vulnerability to report but just bad design that Slack had put in being totally aware of what it means.

Post reply on HN