3 ms·
So what kind of integration did Twitter, Tumblr and Pinterest have with Zendesk? How much of risk are the users are with their passwords?
by creativityland 14y ago
So what kind of integration did Twitter, Tumblr and Pinterest have with Zendesk? How much of risk are the users are with their passwords?
- unreal37 14y agoNo password data was stored there - so zero. No passwords, password hashes or encrypted passwords were lost.
- viscanti 14y agoBut there's a greater than 0% chance that zendesk had an API token for at least one of those services. That could easily allow a hacker to make authenticated requests to those services to gain user info. The fact that usernames and passwords weren't stored on zendesk doesn't mean much, if a hacker can gain full admin access to those other services through an admin token that might have been stored on zendesk.
- kelnos 14y agoI seriously doubt any company (especially the three listed) would give Zendesk admin access to their service. Why would such a thing be necessary, anyway?
- jorts 14y agoI think he meant it the other way around. Having their API token would allow the attacker to have access to all of Twitter/Tumblr/Pinterest's information that's accessible via the Zendesk API.