3 ms·
I'm surprised how under reported this has been. There were basically three scenarios: 1. They knew about the malicious code in 2015 and chose to misrepresent t
by polemic 7y ago
I'm surprised how under reported this has been. There were basically three scenarios:
1. They knew about the malicious code in 2015 and chose to misrepresent the breach, effectively lie to customers. (note that they didn’t reset passwords in 2015, take that how you will)
2. They didn’t know about the malicious code until somewhat later, and they chose not to inform anyone.
3. They only discovered it recently and they were muddying the water as much as possible to make it look like it was part of the 2015 breach
It turns out it was somewhere between (1) and (2). They've since revealed the did know about the issue soon after that notification, but chose only to disclose it to small number of users who they believed to be effected.
https://twitter.com/SlackHQ/status/1152005165802614786 https://twitter.com/SlackHQ/status/1152005165802614786
> We initially believed those credentials to be the result of malware or password re-use between services and took immediate action to protect accounts. However, we later concluded the majority of credentials were from accounts that logged in to Slack during the 2015 incident.
But it turns out it effected a much wider pool of people, and they continue to misrepresent the nature of the breach and it's impact. Their communications are very carefully crafted to downplay the situation or muddy the timelines. Even the title of this piece "New Information...". The information is 4 years old, they're only coming clean now!
Slack had an adversary capturing plain text passwords in 2015 and didn't disclose this to potentially effected users. This is a massive trust issue.
- deleted 7y ago[deleted]