Wow. This is a very serious security flaw. You should never assume that usernames (especially email addresses) are unknown to attackers.
Wanna know what product your competitor is working on? Try Slack
71–80 of 145 posts
Re: Wanna know what product your competitor is working on? Try Slack
#72I think the "this is why not startups|cloud" posts are a bit heavy handed given the actual details of what we're talking about here.
Re: Wanna know what product your competitor is working on? Try Slack
#73Seriously, just the idea of keeping ALL your company internal conversations on a 3rd party server is quite crazy, but to get access without even hacking anything.. I wonder if situations like this will result in business customers more carefully evaluating SaaS solutions that deal with sensitive data, because "in-house" solutions may be old school, but at least a) no one will suddenly terminate the service and b) all…
Leaking of business conversations can have serious implications on many areas from financial to legal. If an employee leaves the company how that will be handled.
Re: Wanna know what product your competitor is working on? Try Slack
#74Re: Wanna know what product your competitor is working on? Try Slack
#75cache version as link broken.
Re: Wanna know what product your competitor is working on? Try Slack
#76Actually, is Microsoft really using Slack if they have Lync and Skype?
Re: Wanna know what product your competitor is working on? Try Slack
#77Re: Wanna know what product your competitor is working on? Try Slack
#78Re: Wanna know what product your competitor is working on? Try Slack
#79Therefore I prefer using encrypted platforms like https://telegram.org/ or https://stackfield.com - they really take care of privacy and data protection.
Re: Wanna know what product your competitor is working on? Try Slack
#80Earlier quoted context omitted.
The way companies handle security disclosures lately (i.e. laughing it off, or paying $6 reward), it seems like shaming them would work much better. Plus, this is truly a beginner-level failure, the kind you'd get insulted for by Linus.
Slack has a Reporting Security Vulnerabilities page on its site: http://slack.com/whitehat . Seems like something they would have taken seriously if it had been brought to them first.