Live data from Hacker News

Slack Security Incident

keybase.io

31–40 of 110 posts

Re: Slack Security Incident

#31

Wow - for a sales pitch fantastic. Many of these security issues leave you little to actually do. This write up provides an alternative. What’s super bad here is slack misleading about the cause wasting all the users time. Quick question, anyone use key base - can u give a quick review? Team currently use slack

I use Keybase. I like it, the thing to keep in mind though is 99.9% of the time the biggest threat vector to your company is going to be preventing your employees from sexually harassing each other, not preventing the Russians or whoever from reading your internal messages.

99.9% of the time the biggest threat vector to your company is going to be preventing your employees from sexually harassing each other, not preventing the Russians or whoever from reading your internal messages.

Yes, but:

1. We always have to combine the likelihood and incidence rate of threats with the magnitude of damage. I do not personally subscribe to this thinking, but some bloodless financial types will suggest that you can compensate harassment victims, but a major security incident could cost you the entire company.

2. Insert animated gif of a little girl asking, "Why not both?" Companies can and must address threats like sexual harassment AND exfiltration of sensitive data.

Re: Slack Security Incident

#32
post #10

The author would have done well by refraining from using this as an opportunity to make a sales pitch for their startup, as it detracts from an otherwise important message. Let me see if I have this right: Slack had a major security breach in 2015. Apparently someone installed malicious code that could even read password inputs in plaintext. They waited 4 years, after growing large and going public, to inform affecte…

Would shareholders have a case to make for fraud here? Slack clearly didn't want this information getting out pre-IPO, as a security disclosure in this case would certainly impact public confidence in the company.

Every tech IPO filing has a generic statement saying something like "our software may contain bugs, including bugs that we cannot fix blah blah blah." So unless Slack has made fraudulent statements about this specific breach, I doubt they've done anything illegal WRT securities fraud.

Re: Slack Security Incident

#33
What makes this even more sad is the extreme difficulty you'll have if you attempt to remove your company data off of the Slack platform. (Disclaimer: I stopped using Slack 2 years ago)

Our company used Slack extensively for multiple years. A couple years ago, we decided to stop using Slack for official company communication. After switching to alternative communication tools, we tried to delete the data in our Slack account and found it to be nearly impossible.

I recall using 3rd party python scripts (opensource on Github) that took hours to run - the script used an API key to fetch and delete messages individually.

We also tried using Slack's Admin panel to delete messages. At the time, I believe it required clicking a checkbox next to every chat message we wanted to delete. Clearly not a realistic way to scrub an account.

The sad reality is that with many services like Slack, once a provider has your data, there's often no easy way to remove it. IMO, this is a major downfall of our reliance on modern SaaS services (companies have no incentive to prioritize features for deleting account data - the only users who would find those features useful are already churned customers).

Re: Slack Security Incident

#34
post #10

The author would have done well by refraining from using this as an opportunity to make a sales pitch for their startup, as it detracts from an otherwise important message. Let me see if I have this right: Slack had a major security breach in 2015. Apparently someone installed malicious code that could even read password inputs in plaintext. They waited 4 years, after growing large and going public, to inform affecte…

The issue looks to be that they thought they had informed all the affected users back in 2015, but underestimated the set of affected users. The breach certainly wasn’t secret until today, they posted it publicly at that time: https://slackhq.com/march-2015-security-incident-and-the-lau....

Re: Slack Security Incident

#35
post #10

The author would have done well by refraining from using this as an opportunity to make a sales pitch for their startup, as it detracts from an otherwise important message. Let me see if I have this right: Slack had a major security breach in 2015. Apparently someone installed malicious code that could even read password inputs in plaintext. They waited 4 years, after growing large and going public, to inform affecte…

Would shareholders have a case to make for fraud here? Slack clearly didn't want this information getting out pre-IPO, as a security disclosure in this case would certainly impact public confidence in the company.

This is large companies must notify the authorities within days of such a data breach in the EU now - no room for "guessing" whether or not the companies should be sued over this type of fraud.

Re: Slack Security Incident

#36
I wonder if this affected companies like IBM... I know for a fact IBM uses slack to talk internally about client billing, meaning if IBM was compromised the attacker knows what most of IBM clients bought from IBM.

Same applies to a bunch of other companies...

Re: Slack Security Incident

#37
post #22
post #10

The author would have done well by refraining from using this as an opportunity to make a sales pitch for their startup, as it detracts from an otherwise important message. Let me see if I have this right: Slack had a major security breach in 2015. Apparently someone installed malicious code that could even read password inputs in plaintext. They waited 4 years, after growing large and going public, to inform affecte…

I think the point was a sales pitch. The post worked well enough to get to the top of the Hacker News front page. I think the effort was rewarded.

I don't even dislike the pitch, tbh. Rarely do I view these posts as innocent / without-pitch. So seeing the pitch is almost appreciated by me, as at least he's trying not to hide it.

With that said, I wish he'd have gone into more of a pitch - specifically why Keybase might be unable to suffer from this specific problem. Or at least, why the attack surface area is smaller with Keybase, etc etc. He goes into a bit, but not a ton, I could have used more.

Re: Slack Security Incident

#38
post #4
post #3

Scary, and certainly doesn't reflect well on Slack. But, do keep in mind that the author runs a company that does compete with Slack in some ways.

I don't think that's relevant. Poor security practices are poor security practices despite conflicts of interests, and Slack's are certainly extremely poor.

It's relevant because as a security minded CEO...he did not even enable 2FA on his account.

Regardless of the issue, that still reflects very poorly on him.

Re: Slack Security Incident

#39
post #7

Not only does Keybase not automatically update its client, there is no way to even figure out if your client is out of date and in need of security updates. Even if you look up the exact version of your installed client, which you can find, there is nothing on the website that says what the most recent version is. The only way to even get a hint is to look on GitHub, and even that isn't accurate; version 4.2.1 is the…

You know what's better than installing slack? Not installing it and using it in the browser. If there's a website option for any tool, I recommend using that over native. It's usually more performant and is less of a security risk. And it's always up to date.

> It's usually more performant and is less of a security risk.

Source, particularly for the "less of a security risk"? (It might well be now, I'm not an expert, but a few years ago I'd have thought "no way").

Re: Slack Security Incident

#40
post #10

The author would have done well by refraining from using this as an opportunity to make a sales pitch for their startup, as it detracts from an otherwise important message. Let me see if I have this right: Slack had a major security breach in 2015. Apparently someone installed malicious code that could even read password inputs in plaintext. They waited 4 years, after growing large and going public, to inform affecte…

[deleted]
Post reply on HN