Live data from Hacker News

A former Gizmodo writer changed name to 'Slackbot', stayed undetected for months

theverge.com

71–80 of 140 posts

Re: A former Gizmodo writer changed name to 'Slackbot', stayed undetected for months

#71
post #40

This reminds me of a glorious day at my consulting company ca. 2016 when we discovered that we could change each other's names on Slack. At one point everyone was just named dad.

This sounds a lot like when my kids realized anyone can edit Netflix/Disney+ profile names and pictures.

All the accounts are filled with the maximum number of ‘djehebdxineEbsuan’ profiles. And my son is asking why there’s a limit ;)

Re: A former Gizmodo writer changed name to 'Slackbot', stayed undetected for months

#72

Earlier quoted context omitted.

That’s why he waited two years to say he did it which just so happens to be the CFAA statute of limitations.

IANAL, but as far as I can tell that's only for civil actions (and it runs from the date that the damages are discovered, not necessarily the time of the offense). For criminal charges, I believe you'd use the default 5 year statute of limitations for noncapitcal federal crimes (18 U.S.C. § 3282)

But the company can't force the state to pursue criminal action whereas it can sue in a civil court any time it wants.

Re: A former Gizmodo writer changed name to 'Slackbot', stayed undetected for months

#73
post #32

Earlier quoted context omitted.

You got a reference on the CFAA? On the contrary, I found that it was probably not a problem to change a URL parameter "We also note that in order to be guilty of accessing “without authorization, or in excess of authorization” under New Jersey law, the Government needed to prove that Auernheimer or Spitler circumvented a code-or password-based barrier to access. See State v. Riley, 988 A.2d 1252, 1267 (N.J. Super. C…

Exactly correct. Nonetheless, a prosecution was indeed brought, and the opinion you're citing is an appeal. Without the EFF's financial support, weev would not be a free man.

That's one way to go. Yolo on a prank.

Re: A former Gizmodo writer changed name to 'Slackbot', stayed undetected for months

#74

Earlier quoted context omitted.

Name changes can be locked; I'm in an Enterprise Grid org and our display names/usernames are synced against our employee profile. We're also required to SSO every single time we launch the desktop app so once you're terminated you're definitely not getting back in (they deactivate accounts very quickly too, so mobile is likely not a major concern). Basically the only thing you can change without filing a ticket is y…

How does an enterprise chat tool not have the ability to invalidate all session tokens and all connected clients to disconnect?

Perverse incentives. People are paying them already without that feature, so why bother? They are incentivized to do and provide as little as possible.

Re: A former Gizmodo writer changed name to 'Slackbot', stayed undetected for months

#75
post #32

I knew an ex-employee back in the day (not me I swear) who created a dialup/ISDN provisioning profile called 'Ringing' in the modem rack controller module (not the Radius server, that would be too obvious), such that a glance at the modem rack status page showed everyone who was connected, and one that was 'Ringing', just like any other incoming call that hadn't been picked up yet. It went completely undetected, yiel…

You got a reference on the CFAA? On the contrary, I found that it was probably not a problem to change a URL parameter "We also note that in order to be guilty of accessing “without authorization, or in excess of authorization” under New Jersey law, the Government needed to prove that Auernheimer or Spitler circumvented a code-or password-based barrier to access. See State v. Riley, 988 A.2d 1252, 1267 (N.J. Super. C…

There is a massive difference between scraping unintentionally published information on a public website and cloaking your account to subvert your employer revoking access to its systems and continuing to access them when you know you're not allowed to be.

Re: A former Gizmodo writer changed name to 'Slackbot', stayed undetected for months

#77

Earlier quoted context omitted.

My company allows name changes. It’s fun.

That means they're not using SAML/SSO which sounds absolutely crazy to me, unless you only have like a dozen users. The implication is that your IT team doesn't take security seriously. Not because you can change names, but because they aren't implementing identity policies.

Or it’s just a more relaxed atmosphere? Not everything needs to be corporate no-fun serious business 24/7.

We’re on an enterprise Slack instance with >1000 members and SSO/SAML. Changing names and photos allows us to be fun and everyone trusts everyone else to not spoil the party.

Re: A former Gizmodo writer changed name to 'Slackbot', stayed undetected for months

#78

Earlier quoted context omitted.

On the other hand, an over-zealous IT guy at my job just deleted our Jira automation account (because he didn't know what it was there for and got sketched out by the name $CompanySecretary). Cue (a few days later) a large pile of pain as we tried to find and fix every workflow and ticket that formerly referred to that user before something really important broke.

At my previous job, we had an entire system aptly named Pandora whose entire role was keeping track of which ssh keys were permitted to be found on servers. It had a bot that would crawl through every server, and if it found a key not in it's database, it nuked it. Every new person or automation key had to first be registered fomarlly, with an end date. A bit of a hassle but definitely necessary for the space the com…

That’s a good idea although I’d probably be paranoid enough to have a human do the deletions, out of fear of the failure mode where it deletes all the keys everywhere and nobody can log into anything.

Re: A former Gizmodo writer changed name to 'Slackbot', stayed undetected for months

#79

Earlier quoted context omitted.

On the other hand, an over-zealous IT guy at my job just deleted our Jira automation account (because he didn't know what it was there for and got sketched out by the name $CompanySecretary). Cue (a few days later) a large pile of pain as we tried to find and fix every workflow and ticket that formerly referred to that user before something really important broke.

At my previous job, we had an entire system aptly named Pandora whose entire role was keeping track of which ssh keys were permitted to be found on servers. It had a bot that would crawl through every server, and if it found a key not in it's database, it nuked it. Every new person or automation key had to first be registered fomarlly, with an end date. A bit of a hassle but definitely necessary for the space the com…

Why not use ssh certificates at that point?

Re: A former Gizmodo writer changed name to 'Slackbot', stayed undetected for months

#80

Earlier quoted context omitted.

I spent months passively waiting for a former employer to evict me from Slack. It was genuinely bizarre, almost a year later I still had full access to a ton of internal channels. They are friends, but this was not them being friendly, it was just because slack account management integration with Google Office is a dumpster fire.

I've got one up on this. I kept my insurance from a past company for nearly 2 years after I got laid off. Would have rather they cancelled it, as it caused a massive headache around the time my son was born

Did you notify them and ask to have it cancelled?
Post reply on HN