As people are discussing Keybase for teams and whatnot - could anyone comment on Keybase for individuals, families, etc? My family are debating moving to Matrix (and away from iMessage). I had briefly debates Keybase due to some interesting features. Anyone have experience with Keybase for families and individuals?
Slack Security Incident
41–50 of 110 posts
Re: Slack Security Incident
#42The author would have done well by refraining from using this as an opportunity to make a sales pitch for their startup, as it detracts from an otherwise important message. Let me see if I have this right: Slack had a major security breach in 2015. Apparently someone installed malicious code that could even read password inputs in plaintext. They waited 4 years, after growing large and going public, to inform affecte…
The issue looks to be that they thought they had informed all the affected users back in 2015, but underestimated the set of affected users. The breach certainly wasn’t secret until today, they posted it publicly at that time: https://slackhq.com/march-2015-security-incident-and-the-lau... .
Re: Slack Security Incident
#43Let's ignore the rather awkward self promotion, and the fact that 2FA would have prevented this specific incident. This is the important part, which everyone should think about: > What would have been way worse — immeasurably worse — is if our team had used Slack for anything other than what we did use it for, which was discussing outages of our own product. Had my cofounder and I discussed our company's cap table, o…
Is that so? The article states: "If the attackers inject server code, 2FA or U2F or any Web-based security practice does little."
Re: Slack Security Incident
#44Re: Slack Security Incident
#45So why was the Keybase CEO using Slack in the first place?
Re: Slack Security Incident
#46Not only does Keybase not automatically update its client, there is no way to even figure out if your client is out of date and in need of security updates. Even if you look up the exact version of your installed client, which you can find, there is nothing on the website that says what the most recent version is. The only way to even get a hint is to look on GitHub, and even that isn't accurate; version 4.2.1 is the…
4.2.1 was a bugfix release that only affected Linux and BSD, so we didn't push out Mac or Windows releases for it.
Re: Slack Security Incident
#47Earlier quoted context omitted.
You know what's better than installing slack? Not installing it and using it in the browser. If there's a website option for any tool, I recommend using that over native. It's usually more performant and is less of a security risk. And it's always up to date.
> It's usually more performant and is less of a security risk. Source, particularly for the "less of a security risk"? (It might well be now, I'm not an expert, but a few years ago I'd have thought "no way").
Re: Slack Security Incident
#48Wow - for a sales pitch fantastic. Many of these security issues leave you little to actually do. This write up provides an alternative. What’s super bad here is slack misleading about the cause wasting all the users time. Quick question, anyone use key base - can u give a quick review? Team currently use slack
I use Keybase. I like it, the thing to keep in mind though is 99.9% of the time the biggest threat vector to your company is going to be preventing your employees from sexually harassing each other, not preventing the Russians or whoever from reading your internal messages.
Re: Slack Security Incident
#49The author would have done well by refraining from using this as an opportunity to make a sales pitch for their startup, as it detracts from an otherwise important message. Let me see if I have this right: Slack had a major security breach in 2015. Apparently someone installed malicious code that could even read password inputs in plaintext. They waited 4 years, after growing large and going public, to inform affecte…
The issue looks to be that they thought they had informed all the affected users back in 2015, but underestimated the set of affected users. The breach certainly wasn’t secret until today, they posted it publicly at that time: https://slackhq.com/march-2015-security-incident-and-the-lau... .
Re: Slack Security Incident
#50Let's ignore the rather awkward self promotion, and the fact that 2FA would have prevented this specific incident. This is the important part, which everyone should think about: > What would have been way worse — immeasurably worse — is if our team had used Slack for anything other than what we did use it for, which was discussing outages of our own product. Had my cofounder and I discussed our company's cap table, o…
> the fact that 2FA would have prevented it. Is that so? The article states: "If the attackers inject server code, 2FA or U2F or any Web-based security practice does little."