Live data from Hacker News

HipChat security notice

blog.hipchat.com

21–30 of 119 posts

Re: HipChat security notice

#21

Earlier quoted context omitted.

Serious question: Do you need the non-techy explanation?

no.. but I could be a non IT user using hipchat. This sentence is likely meaningless to me.

Sure. I get your point. Just asking if YOU specifically needed the explanation, which I'm sure a number of folks would be happy to provide.

Re: HipChat security notice

#22

Earlier quoted context omitted.

Serious question: Do you need the non-techy explanation?

no.. but I could be a non IT user using hipchat. This sentence is likely meaningless to me.

Then you would be fine with the standard boilerplate "your data is secure with us"?

I'm happy they say this.. now i'd like some sort of proof :-)

Re: HipChat security notice

#23

Earlier quoted context omitted.

Serious question: Do you need the non-techy explanation?

no.. but I could be a non IT user using hipchat. This sentence is likely meaningless to me.

Googling bcrypt should do the trick and most people know how to do that.

Re: HipChat security notice

#24
post #7
post #6

Earlier quoted context omitted.

More importantly, I wonder how much they were paying for this library, or to what extent they were supporting it internally. Because if the answer is zero and they weren't, I would put a lot of the blame on HipChat engineering.

I'm not sure I understand you - You would blame the users of a third-party library if the library was found to have a vulnerability and it was exploited against the people using the library?

IMO, frankly, yes.

If you use someone else's code, especially if you're not paying anything for it, you get what you put into it: nothing.

The liability for this breach is ultimately owned by Atlassian, not the third party library writer. To quote the most permissive license out there:

"THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED."

Re: HipChat security notice

#25
post #4

Needless to say their (login) servers crashed from the pressure of people resetting their credentials. "Hey, you know what might be a good idea? Let's email all of the accounts at the same time using an Appriver blast!" Atlassian. I hate to hate you.

While I can see your point in this case I think it was the appropriate action, their ops team should've just beefed up their resources in conjunction with the email blast.

Only emailing a rolling amount of your customers becomes a shit show of support, who do you email first? Who do you email last? How long do you wait between groups? For who is security important, your biggest customers, highest paying, most security conscious? It's a real shit show to know, and one you'd absolutely get wrong, letting everyone know as fast as possible is the only acceptable solution to a security breach.

Re: HipChat security notice

#26
post #18
post #10

Earlier quoted context omitted.

Not only moral, but mostly legal. Warranties are not included. So it's a bit lame to blame "a popular third party library". The OP was trying to say a company of Atlassians size should dedicate the resources to vet (and fix) those libraries if they use them for these purposes.

I don't think anyone is trying to shift blame, just to explain what happened. I am not affiliated with Atlassian so I'm only guessing.

Sorry, i wasn't trying to imply they shifted blame. But atlassian does bare the legal&moral burden of securing their product here.

Re: HipChat security notice

#27
post #23

Earlier quoted context omitted.

no.. but I could be a non IT user using hipchat. This sentence is likely meaningless to me.

Googling bcrypt should do the trick and most people know how to do that.

you're joking I assume. If not, don't be in the UX field

Re: HipChat security notice

#30
post #13
post #9

Earlier quoted context omitted.

Open source code now carries a moral maintenance obligation? Do we say the same thing about any large company that uses openssl or any other open source libs that people use or depend on? That doesn't seem fair or reasonable.

> Open source code now carries a moral maintenance obligation? Yes, and it always has and it can't be discharged. Pay-it-forward is the right thing to do. > Do we say the same thing about any large company that uses openssl or any other open source libs that people use or depend on? I certainly do. A red line, I-will-quit condition is and always has been "I won't participate in the development of private forks of ope…

> Yes, and it always has and it can't be discharged. Pay-it-forward is the right thing to do.

Interesting - it may be a nice thing to do, but I don't agree that there is any sort of obligation to the project just for using the project.

> I certainly do. A red line, I-will-quit condition is and always has been "I won't participate in the development of private forks of open-source software" and I have at multiple employers gotten checks straight-up cut to open-source software maintainers. I have also entreated (and in two cases succeeded in convincing) maintainers to start up maintenance programs so we could pay them a yearly fee--because donations are way harder to push than support plans.

I have also worked at companies that funded open source projects through donations or maintenance, but there was never a moral obligation there. It was more a method of risk management than altruism.

> I consider not paying forward kindnesses paid to you way, way more unfair and unreasonable.

Paying forward kindness and being morally obligated to maintain an open source library just because you use it are different things in my mind. It seems like being paid a kindness creates an obligation, which is not that nice.

---

Interesting perspective even though I strongly disagree. I'll continue to use open source projects 'AS IS'[0] and I still wont feel morally obligated to maintain them. Similar to how I use linux/BSD and don't feel obligated to maintain the kernel. I'm certainly grateful of course, but I don't feel like there was any sort of contract/exchange between myself and the maintainers that creates an obligation on my part.

[0] https://github.com/eropple/auster/blob/master/LICENSE.txt

Post reply on HN