Live data from Hacker News

A former Gizmodo writer changed name to 'Slackbot', stayed undetected for months

theverge.com

61–70 of 140 posts

Re: A former Gizmodo writer changed name to 'Slackbot', stayed undetected for months

#61

Earlier quoted context omitted.

That means they're not using SAML/SSO which sounds absolutely crazy to me, unless you only have like a dozen users. The implication is that your IT team doesn't take security seriously. Not because you can change names, but because they aren't implementing identity policies.

you can very much allow people to change display names while using saml/sso. My work setup allows this. We can change photo and description as well but nothing else.

Same here.

Re: A former Gizmodo writer changed name to 'Slackbot', stayed undetected for months

#62
post #21

Earlier quoted context omitted.

SCIM adoption isn't near where it needs to be. I guess yeah, this is the correct answer. We live in a world where SSO is considered an enterprise feature, I hope one day that it's considered default.

Shameless plug for my startup (hope that's ok!) If you're building an app and need to add SCIM, check out WorkOS. My email is in my profile to chat. More info -> https://workos.com/directory-sync

$125 per connection / month and then you wonder why companies don't offer SSO/SCIM by default in their free/cheap plans.

Re: A former Gizmodo writer changed name to 'Slackbot', stayed undetected for months

#63

Earlier quoted context omitted.

On the other hand, an over-zealous IT guy at my job just deleted our Jira automation account (because he didn't know what it was there for and got sketched out by the name $CompanySecretary). Cue (a few days later) a large pile of pain as we tried to find and fix every workflow and ticket that formerly referred to that user before something really important broke.

Aah, he took down Chesterton's fence and found the reason of its existance! ( https://en.wiktionary.org/wiki/Chesterton%27s_fence )

More than once I have taken down a Chesterton's fence that I myself had originally put up

Re: A former Gizmodo writer changed name to 'Slackbot', stayed undetected for months

#64
post #4

> Of course, not every company will fall for this trick The company can have the last laugh: https://en.wikipedia.org/wiki/Computer_Fraud_and_Abuse_Act

That’s why he waited two years to say he did it which just so happens to be the CFAA statute of limitations.

IANAL, but as far as I can tell that's only for civil actions (and it runs from the date that the damages are discovered, not necessarily the time of the offense).

For criminal charges, I believe you'd use the default 5 year statute of limitations for noncapitcal federal crimes (18 U.S.C. § 3282)

Re: A former Gizmodo writer changed name to 'Slackbot', stayed undetected for months

#65

Earlier quoted context omitted.

On the other hand, an over-zealous IT guy at my job just deleted our Jira automation account (because he didn't know what it was there for and got sketched out by the name $CompanySecretary). Cue (a few days later) a large pile of pain as we tried to find and fix every workflow and ticket that formerly referred to that user before something really important broke.

Aah, he took down Chesterton's fence and found the reason of its existance! ( https://en.wiktionary.org/wiki/Chesterton%27s_fence )

Chesterton's key more like.

Re: A former Gizmodo writer changed name to 'Slackbot', stayed undetected for months

#66
post #52

One place I worked was slow to deactivate slack accounts, so when I left I made a private channel #daves_cave and invited friends my friends to it. I would leave a short story or pithy saying now and then; it was fun until management got wise and deactivated me.

I’ve got a private, paid Slack team ($10 a month?) and you can invite people from other paid Slack teams to chat in rooms on it. Nice thing about this is it’s “by design”, so less likely to get shut down, and also unlikely to fall foul of computer misuse laws.

Re: A former Gizmodo writer changed name to 'Slackbot', stayed undetected for months

#67
post #51

Earlier quoted context omitted.

At the same time the ability to change name is sich a godsend. We're currently abusing it to have presence info straight in the display name (e.g. mike-2/12~16vac.) to let anyone contacting us what to expect for response times, or wether to ask for a task if it's a few days before a planned vacation. Nobody seemed to look at the actual status property and it beats going to the calendars to check.

> mike-2/12~16vac Looks like mike-2 is a robot powered by a doorbell transformer.

He'd probably be fine with that perception.

Re: A former Gizmodo writer changed name to 'Slackbot', stayed undetected for months

#68

The fact slack doesn't allow you to lock down name changes must be such a gaping security hole for big companies. Change your name to the CEO, and profile image to match. Odds of people noticing the difference are extremely small until it's too late. Changing to slackbot seems like small fry!

Name changes can be locked; I'm in an Enterprise Grid org and our display names/usernames are synced against our employee profile. We're also required to SSO every single time we launch the desktop app so once you're terminated you're definitely not getting back in (they deactivate accounts very quickly too, so mobile is likely not a major concern). Basically the only thing you can change without filing a ticket is y…

How does an enterprise chat tool not have the ability to invalidate all session tokens and all connected clients to disconnect?

Re: A former Gizmodo writer changed name to 'Slackbot', stayed undetected for months

#69

the screenshots of people replying to him who clearly know he's not slackbot, including calling him Tom, kind of contradict the headline here. he was clearly not "undetected". we've got some former staff in our slack still. they check in and say hi every now and then, it's nice. if one of them started pretending to be a snarky slackbot one day, we'd probably have a laugh about it too.

Same here, slack is not our main communications channel but it was used for some external consultants. And sure enough people who had quit were never kicked out so they just continued planning lunches together.

Re: A former Gizmodo writer changed name to 'Slackbot', stayed undetected for months

#70

Best place to hide is something that looks like a service account everyone is afraid to touch for fear of what will break if disabled. Well played!

On the other hand, an over-zealous IT guy at my job just deleted our Jira automation account (because he didn't know what it was there for and got sketched out by the name $CompanySecretary). Cue (a few days later) a large pile of pain as we tried to find and fix every workflow and ticket that formerly referred to that user before something really important broke.

At my previous job, we had an entire system aptly named Pandora whose entire role was keeping track of which ssh keys were permitted to be found on servers. It had a bot that would crawl through every server, and if it found a key not in it's database, it nuked it. Every new person or automation key had to first be registered fomarlly, with an end date. A bit of a hassle but definitely necessary for the space the company was in.
Post reply on HN