Live data from Hacker News

Wanna know what product your competitor is working on? Try Slack

tanay.co.in

81–90 of 145 posts

Re: Wanna know what product your competitor is working on? Try Slack

#81

I just realized that any facebook user can signup on https://facebook.slack.com/ with his fb username.

I'm too scared to try it - I have all my photos and stuff like that on my Facebook account. So tempting though!

You should backup those off facebook. However consider carefully if you wish to keep that backup in the cloud. (and which cloud).

Re: Wanna know what product your competitor is working on? Try Slack

#82
post #3

This is something that could definitely have been reported to Slack before disclosing it publicly. Maybe he did that, but it's not mentioned in the blog post so I assume he didn't. It's just a nice thing to do and they might reward you for it. You can still post it on your blog after they released a fix.

This is hardly an exploit. Since no authentication is required in order to see the chatroom listings for any domain, we must assume that they meant for their chatroom directory to be public information. This may not be what their customers are expecting, though...

It's information disclosure at its finest. Something you _really_ want to avoid in a sensitive environment - which company internal comms certainly is.

Re: Wanna know what product your competitor is working on? Try Slack

#84

Earlier quoted context omitted.

Shaming Slack is one point. This guy just exposed the confidential information of who knows how many of Slack's customers. In my opinion that's douchery of epic proportions.

Maybe this kind of exposure is the only way we will teach people to stop trusting fly-by-night cloud startups with their confidential data?

So hurting people in order to teach them a lesson about not getting hurt?

Re: Wanna know what product your competitor is working on? Try Slack

#85

Seriously, just the idea of keeping ALL your company internal conversations on a 3rd party server is quite crazy, but to get access without even hacking anything.. I wonder if situations like this will result in business customers more carefully evaluating SaaS solutions that deal with sensitive data, because "in-house" solutions may be old school, but at least a) no one will suddenly terminate the service and b) all…

Productivity trumps those concerns.

Re: Wanna know what product your competitor is working on? Try Slack

#86
This is ugly, and probably much more of a disclosure than most of these companies were expecting.

That being said, everyone railing about "unreleased product names" seem to have forgotten this is exactly the purpose of code names: they're pretty much expected to be leaked at some point, but it's okay since the stakes are intentionally low. Use code names!

Re: Wanna know what product your competitor is working on? Try Slack

#87
post #39

While I'm unable to comment on the content of the article, I really have to applaud HostGator's error page marketing strategy here. We've met with a horrible fate (status code 500) while generating what appears to be a static page. This site is hosted by HostGator! Get yours now!

This page is broken! That doesn't mean yours will be! HostGator.

Re: Wanna know what product your competitor is working on? Try Slack

#88

Fun to scan down this list: http://www.siliconvalley.com/SV150/ci_25548370/ Naturally the biggest companies have the most teams.

I wrote a node script[1] you could use for this. [1] http://pastebin.com/raw.php?i=NgTeseN1

Here's a streaming version that runs through the top 1m Alexa sites. It looks like it gets throttled after a while though, but you can fix it with some trial and error by dialing down the concurrency in concurrent-map-stream and by introducing pauses.

https://gist.github.com/anonymous/4e34a10f1552dd8ede96

Re: Wanna know what product your competitor is working on? Try Slack

#90

Earlier quoted context omitted.

Maybe this kind of exposure is the only way we will teach people to stop trusting fly-by-night cloud startups with their confidential data?

So hurting people in order to teach them a lesson about not getting hurt?

This was about the most minor kind of information leak you could imagine. I doubt anybody is going to feel any real 'hurt' from this.

In this case the information seems unlikely to contain anything sensitive pertaining to customers. If it had though then the companies that had negligently put sensitive information on untrusted servers would be held liable and could face significant fines (violating the Data Protection Act 1998 in the UK can lead to fines of up to £500,000 and similar legislation exists in other parts of the EU). That more serious kind of breach is the one we are trying to avoid by advising companies not to use cloud services.

Post reply on HN