6 ms·
Doubt this will be a popular view around here, but using a 3rd party service for internal business communications is just a bad idea. I've seen companies posti
by problems 9y ago
Doubt this will be a popular view around here, but using a 3rd party service for internal business communications is just a bad idea.
I've seen companies posting root passwords, ssh keys, salaries, internal financial details, etc in Slack and HipChat. Just waiting for a disaster to strike, adding value for every additional company to the target. Maybe this breach won't be the last straw, but it's a consistent risk.
You can run your own MatterMost or XMPP server quite easily and even lock it down to behind VPN only to minimize security risks almost completely.
- throwaway91111 9y agoIn my experience, using irc or xmpp mostly results in people not using it unless a) the team is largely technical or b) there's a common, easy interface like gchat used to be.
- deaddodo 9y agoWhy are you giving your employees a choice in the matter of something so important? Set up an XMPP server, tell them that's what is used for internal communication. Period. And if they're too lazy/dumb/entitled to download Adium/Pidgin and enter their email address+password; well, you should probably find better employees.
- wilg 9y agoOh for God's sake.
- detaro 9y agoYou probably should not let all your (non-technical) employees install random software they download.
- Xylakant 9y agoFriends don't let friends use libpurple based messengers. Sadly, Adium development is pretty stale and unresponsive to even major security issues such as https://threatpost.com/code-execution-vulnerability-found-in-libpurple-im-library/124448/ https://threatpost.com/code-execution-vulnerability-found-in...
- geofft 9y ago"Not using it" means "compared to using offline means for communication or just not communicating," not "compared to using an unauthorized online means for communication." Your job as IT is to deliver business value. It's certainly possible that people not communicating is better for the business than people communicating over a hackable service, but it's not the conclusion most people have come to.
- problems 9y agoThat's why I suggested MatterMost - it can be self hosted and has a very nice interface. There's also quite good ones for XMPP like Conversations and Spark. Best bet for less technical people is to have suggested quality clients.
- krick 9y agoIts Android client is so-so. I'd suggest Matrix/Riot.
- DKnoll 9y agoQuite a lot of organizations use Spark which is a straight up XMPP client, they also license an enterprise XMPP server.
- Alupis 9y ago> Quite a lot of organizations use Spark which is a straight up XMPP client, they also license an enterprise XMPP server. The same open source community (IgniteRealtime.org[1]) that maintains the Spark[2] XMPP client, also maintains OpenFire[3], a very good and easy to setup XMPP server. [1] http://igniterealtime.org/ http://igniterealtime.org/ [2] http://igniterealtime.org/projects/spark/index.jsp http://igniterealtime.org/projects/spark/index.jsp [3] http://igniterealtime.org/projects/openfire/index.jsp http://igniterealtime.org/projects/openfire/index.jsp
- DKnoll 9y agoHuh... I was confused when somebody told me they bought an Spark enterprise server license... now even moreso. I think they probably just bought a license for a commercial fork of OpenFire.
- Alupis 9y ago> I think they probably just bought a license for a commercial fork of OpenFire. That's very possible. Cisco bundled/bundles OpenFire into several of their enterprise appliances, including the Cisco Finesse product. Other companies do similar things. OpenFire is licensed under the Apache license. There's also the possibility that your friend bought an enterprise license to OpenFire back when it was a commercial product under the name WildFire (Spark was commercial back then too). That would have been many, many years ago, back before Jive Software open sourced WildFire/OpenFire, Spark, Smack (XMPP Java Library), and several other pieces of software for real time communications.
- yarper 9y agoI think that's a totally legitimate view
- Gaelan 9y agoWhat about private code on GitHub? Email/files on Google? Heck, customer data in AWS?
- CaptSpify 9y agoWhat about them? They are just as prone to the same problems
- fao_ 9y agoYou can host your own versions of them. For that extra layer of security, you can stick them behind a domain that's only accessable behind a company-wide VPN.
- mirashii 9y agoWhat about using one of those pesky popular operating systems that everyone else uses. They're such big targets, using them only increases the bounty someone would get if they exploited them. You can build your own internal operating system to minimize the risk that anyone can break into your company's machines.
- problems 9y agoThat's a bit different - no one here is suggesting recreating tools, merely using existing tools in a more secure manner and segmenting them off from the general public and sometimes the rest of your network too. Lowering your attack surface is often the cheapest way to stop attacks.
- mirashii 9y agoWhat's being suggested is still a significant increase in spend for infrastructure. Self-hosting is not free. You lose economies of scale on the services. You need to hire an inhouse IT and/or infrastructure/ops team to support them. Your probability of downtime increases significantly, which comes with a cost. It's the same tradeoff you're talking about, with the only difference being the scale of cost.
- Gaelan 9y agoWhat about private code on GitHub? Email/files on Google? Heck, customer data in AWS?
- Gaelan 9y agoWhat about private code on GitHub? Email/files on Google? Heck, customer data in AWS?
- 65827 9y agoThe best is when people accidentally type their passwords into the hipchat window, which if you have a whole company spread across a few rooms, happens every fucking day without fail. The cloud is not secure, sorry.
- MichaelGlass 9y agoMy assumption has always been that companies large enough to have a security team also have better security practices than my small company. E.g. I'd guess Atlassian infrastructure folks don't share ssh keys over chat. Maybe they do.
- bjoernw 9y agoWhen a zero day drops the size of the security team is irrelevant.
- Godel_unicode 9y agoWho do you think is responsible for detecting a breach with that 0day? How about containing (and ensuring your believed containment is effective) and eradicating it? Would you rather have a dedicated security team do this, or would you prefer to have your devs wipe and rebuild naively, hoping they got everything? Even if you go MSSP, do they know your network? Security is just as much (if not more) responding to a breach effectively and quickly as it is preventing one.
- briandear 9y agoIs there a single case of a company suffering a loss because of a Github or Slack data breach? Is there a single case of a company suffering a loss because of their own systems being breaches? It happens all the time. Look at Sony -- their data would have been safer stored on DropBox than their own internal servers. You claim "risk," of using 3rd party services but can you quantify it with actual data? Slack's entire business is secure business communication. Are we to think that our teams are better than Slack's when Slack's core competency is secure communication? Should companies install their own phone lines because the 3rd party phone companies can't be trusted? Is there not risk when your internal teams who aren't necessarily domain experts, are building and maintaining systems that are outside of the company's core competency? The security value of doing it yourself is nothing but anecdotal and not based on any actual data.
- problems 9y ago> Look at Sony -- their data would have been safer stored on DropBox than their own internal servers. Not really, if I recall correctly Sony's whole Windows network was compromised via trojans in a PDF attachment exploit. Nothing to do with local vs cloud storage. They certainly couldn't have replaced their desktops with Dropbox. > Are we to think that our teams are better than Slack's when Slack's core competency is secure communication? Not necessarily - but they are much better able to restrict things to only your employees by applying VPNs and HTTPS+LDAP auth only proxies. Preventing you from being affected by public breaches like these. The value there is well documented - look what happened when the world moved from exposed to behind NAT routers. Big public breaches happen all the time - you mentioned dropbox, I've gotten several reset emails from dropbox due to compromise, I'm guessing the attackers didn't walk away empty handed in such cases. A quick search reveals that just last year 68 million dropbox accounts were compromised. On the other hand, when was the last time an even moderately well maintained SMB file server behind a LAN was compromised directly? Unique zero-day attacks are much more likely to be used on public services too due to the nature of their value.
- Consultant32452 9y agoI had a gig at a company that used Hipchat once. I generally like the app, but I was shocked/appalled that posting files to the chat got uploaded to the AWS cloud with a URL that is retrievable anywhere. Do you know how often things like logs, config files, etc. got posted to chats? That place wrote insurance software too, so plenty of juicy financial information in their systems.
- briandear 9y agoHipChat has been a pile of crap for a long time. Why people willingly use that over Slack remains a mystery.
- X-Istence 9y agoSlack does the same thing... files are uploaded to S3 as well. Slack isn't a panacea when it comes to security.
- briandear 9y agoBeing uploaded to S3 isn't the problem; it's public access to the S3 URL that's the issue. You can't publicly access an uploaded Slack S3 file.
- pavel_lishin 9y agoHipchat offers a self-hosted option, which is a requirement for many companies that very specifically don't want their chat logs and files living in some s3 bucket.
- Consultant32452 9y agoAs far as usability and all that I really like Hipchat. I haven't gotten the chance to use Slack, but I've got no complaints on the Hipchat application itself. My current megacorp employer uses it as part of a big contract with Atlassian, but ours is hosted internally. I don't know the intimate details of self-hosting, but I assume that mitigates most of the security concerns.
- deleted 9y ago
- outworlder 9y ago>You can run your own MatterMost or XMPP server quite easily and even lock it down to behind VPN only to minimize security risks almost completely. What about Matrix?
- chowyuncat 9y agoYou can run your own HipChat server as well.