Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Sorry that the site was down for long. The site was on poorman's hosting (hostgator) that could not take HN traffic and bogged down.

Cloudflare, along with flatfile caching by Drupal's Boost module came to the rescue. Hope that stays alive for a while now.

Regarding not having disclosed this one discretely to Slack:

* I have considerable experience in a couple opensource projects including Drupal and have reported multiple vulnerabilities on various occasions for various modules discretely (though mostly of lesser significance and a very narrow/rare attack vector) to the right teams through various channels meant for this purpose. As such I am aware of the SOPs for the righteous to follow in case of discovering a vulnerability.

* I don't think this one is a security issue that would take a professional security expert to crack. Nor could this have been not noticed when Slack tested their product. This is an issue with 'common sense'. I am pretty sure that Slack designed it this way. It is just the customers that are surprised now. Not Slack.

Also, it looks like this was reported earlier to Slack by https://twitter.com/rootlabs/status/499723782244675584 a couple of months ago and it was rejected by Slack as "Not a bug". However I do acknowledge that I was not aware of this report when I first published the post and hence can not say that I disclosed it only after being rejected by Slack. I would say it was not a security vulnerability to report but just bad design that Slack had put in being totally aware of what it means.



I also want to add on that I do not view this as a security issue. There are a myriad of things that should be done:

1) Your company should not be using SaaS services for sensitive projects w/o codenames. (Codename FishSauce = Viber M&A) -- obviously just obscurity, but still solid opsec.

2) I'd love to see your write-up on HipChat uploading all files directly to an S3 bucket accessible to the world.

3) Every user w/ that companies domain sees this each time they sign-in.

4)I just think it's overhyped and not a big deal.

5) It only impacts companies who have multiple slack TEAMS (not the same thing as channels, no channel names are disclosed)

Also, this is a decision Slack admins make: http://imgur.com/FCUE1mY


> I also want to add on that I do not view this as a security issue

This is absolutely a security issue. What companies I do business with is protected under NDA.


[deleted]


As far as I know, the teams the user has already joined will also show in that listing, not just the ones they are authorized to join. Even with the auto-auth setting turned off, then, anyone can get a listing of the teams to which a known email address already belongs.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: