Live data from Hacker News

Slack Security Incident

keybase.io

71–80 of 110 posts

Re: Slack Security Incident

#73
post #50

Earlier quoted context omitted.

It won’t prevent an attacker from logging in as you at the moment, but it will prevent them from using stolen credentials later on.

If they can inject server code, they can bypass 2FA entirely. They don't need your 2FA code they'll just skip that part of the authentication. The same goes for passwords, but with passwords there is the potential of additional value on other sites that haven't been compromised so those are always worth collecting.

[deleted]

Re: Slack Security Incident

#74
post #64
post #54

Earlier quoted context omitted.

Slack has some options to delete all messages over N days old. Unless there is a really good reason not to, turning on this feature generally sounds like a good idea. At least you can drastically limit the length of the archive available to any attacker.

That's a terrible feature in an instant messenger client for work use? I cannot recall the precise details of my conversations with smart people who know things I do not. I can recall that I had the conversation and remind myself what I learned before.

As with many things in life, it's a tradeoff. Do you want to accept a higher risk of security incidents or make it easier to recall information from a long ago IM conversation?

There are rational reasons for an organization to do either.

Re: Slack Security Incident

#75
post #64
post #54

Earlier quoted context omitted.

Slack has some options to delete all messages over N days old. Unless there is a really good reason not to, turning on this feature generally sounds like a good idea. At least you can drastically limit the length of the archive available to any attacker.

That's a terrible feature in an instant messenger client for work use? I cannot recall the precise details of my conversations with smart people who know things I do not. I can recall that I had the conversation and remind myself what I learned before.

I don't think anyone would argue with the value side of the question. The tricky part is calculating the cost side. (The cost of not deleting old messages.)

Surely we can agree that the cost side is > 0.

I'd argue that the benefit side is generally at least a little lower than what we think it's going to be. And if the expiration limit is set to say, 1 year, the cost of deleting old messages goes down considerably.

Re: Slack Security Incident

#76
From the slack post:

> In other words, if you’re one of the approximately 99% who joined Slack after March 2015 or changed your password since then, this announcement does not apply to you.

Hackers compromising plaintext password would seem to apply to everyone using Slack, whether their account was compromised or not??

Re: Slack Security Incident

#78
post #62

> Were our Dutch friends sifting through our messages for four years before Slack notified us of a suspicious login? The author might know this already but the hackers aren't Dutch. They simply bought a cheap NL server from LeaseWeb to mask their real IP.

> bought a cheap NL server

.. or exploited/hacked a random cheap server to use to proxy their requests and have access to high speed 100Mbit/1Gbit downloads/uploads of Slack data.

Re: Slack Security Incident

#79

As people are discussing Keybase for teams and whatnot - could anyone comment on Keybase for individuals, families, etc? My family are debating moving to Matrix (and away from iMessage). I had briefly debates Keybase due to some interesting features. Anyone have experience with Keybase for families and individuals?

Why move away from iMessage? It's end-to-end encrypted.

Because I'm planning on moving to Linux, and I dislike typing a lot on my iPhone. So I need a desktop client to talk with my family/etc.

I'd prefer to keep iMessage, but you know, walled garden. Lol.

Re: Slack Security Incident

#80

Wow - for a sales pitch fantastic. Many of these security issues leave you little to actually do. This write up provides an alternative. What’s super bad here is slack misleading about the cause wasting all the users time. Quick question, anyone use key base - can u give a quick review? Team currently use slack

I use keybase and promote it around the office, but I've had trouble getting people to join me. Maybe if it had an edgy dark mode...
Post reply on HN