Slack Security Incident
keybase.io
Slack Security Incident
1–10 of 110 posts
Re: Slack Security Incident
#2I think one issue keybase still had is it's minimal web presence that sounds to focus too little on what keybase can do for regular users. People need more explaining of the day to day benefits.
Re: Slack Security Incident
#3Re: Slack Security Incident
#4Scary, and certainly doesn't reflect well on Slack. But, do keep in mind that the author runs a company that does compete with Slack in some ways.
Poor security practices are poor security practices despite conflicts of interests, and Slack's are certainly extremely poor.
Re: Slack Security Incident
#5Re: Slack Security Incident
#6What’s super bad here is slack misleading about the cause wasting all the users time.
Quick question, anyone use key base - can u give a quick review? Team currently use slack
Re: Slack Security Incident
#7For whatever problems Slack has, at least I know if there is a new version that I need to install.
Re: Slack Security Incident
#8Re: Slack Security Incident
#9Scary, and certainly doesn't reflect well on Slack. But, do keep in mind that the author runs a company that does compete with Slack in some ways.
I don't think that's relevant. Poor security practices are poor security practices despite conflicts of interests, and Slack's are certainly extremely poor.
They have a lot of high quality security features and you can see they actually work because they alerted Max that his account was compromised.
Saying their security practices are extremely poor based on an incident they had in 2015 when their company was 1/20th the size it is today is ridiculous
Re: Slack Security Incident
#10Let me see if I have this right:
Slack had a major security breach in 2015. Apparently someone installed malicious code that could even read password inputs in plaintext. They waited 4 years, after growing large and going public, to inform affected users. And in the interim they blamed their users for any related security problems.
Do I have this correct? If so, how is anyone going to defend this situation? And how can anyone put any sensitive data on Slack, or tell their company to do so, and feel good about it now?
I expected some stupid apology note from the CEO on their website if this turns into a bigger issue, which is sort of an anti-pattern at this point...