4 ms·
This is something that could definitely have been reported to Slack before disclosing it publicly. Maybe he did that, but it's not mentioned in the blog post so
by johannh 12y ago
This is something that could definitely have been reported to Slack before disclosing it publicly. Maybe he did that, but it's not mentioned in the blog post so I assume he didn't.
It's just a nice thing to do and they might reward you for it. You can still post it on your blog after they released a fix.
- tomp 12y agoThe way companies handle security disclosures lately (i.e. laughing it off, or paying $6 reward), it seems like shaming them would work much better. Plus, this is truly a beginner-level failure, the kind you'd get insulted for by Linus.
- johannh 12y agoTrue, but it still feels like the right thing to do. I'd like people do be responsible when they discover a serious flaw in my programs, so I'll try to be responsible when discovering one in theirs. Also Linus basically insults anyone for being alive.
- smt88 12y agoWhy assume the worst about Slack just because some other companies have handled disclosures badly? Real people work at Slack, and very few of them were likely responsible for this oversight. OP could still pat him/herself on the back after disclosing and waiting for a fix.
- deleted 12y ago[deleted]
- ankey1 12y agoSlack has a Reporting Security Vulnerabilities page on its site: http://slack.com/whitehat http://slack.com/whitehat. Seems like something they would have taken seriously if it had been brought to them first.
- nailer 12y agoApparently it was, see: https://twitter.com/rootlabs/status/499723782244675584 https://twitter.com/rootlabs/status/499723782244675584
- richmarr 12y agoShaming Slack is one point. This guy just exposed the confidential information of who knows how many of Slack's customers. In my opinion that's douchery of epic proportions.
- anon1385 12y agoMaybe this kind of exposure is the only way we will teach people to stop trusting fly-by-night cloud startups with their confidential data?
- TeMPOraL 12y agoThis. That was exactly a kind of vulnerability that is meant to be publicly disclosed. Nothing of matter will happen to anyone because of that vulnerability, but people might remember it and next time they'll think twice about how they handle authentication.
- richmarr 12y agoSo hurting people in order to teach them a lesson about not getting hurt?
- anon1385 12y agoThis was about the most minor kind of information leak you could imagine. I doubt anybody is going to feel any real 'hurt' from this. In this case the information seems unlikely to contain anything sensitive pertaining to customers. If it had though then the companies that had negligently put sensitive information on untrusted servers would be held liable and could face significant fines (violating the Data Protection Act 1998 in the UK can lead to fines of up to £500,000 and similar legislation exists in other parts of the EU). That more serious kind of breach is the one we are trying to avoid by advising companies not to use cloud services.
- kordless 12y agoThe lesson can be had independently of the intent of douchery. Shit happens, and learning from your mistakes (by admitting them) is a fine way to get better at what you do.
- ayrx 12y agoCompletely untrue about the people at Slack. I disclosed a pretty trivial vulnerability to them and got a $100 reward. How about next time you stop generalising?
- tomp 12y agoI'm not generalizing, and I don't really care about Slack. I'm just putting forward a hypothesis about what might be going on in a security researcher's brain when they stumble upon a vulnerability.
- crazypyro 12y agoWell considering other people posted a tweet about someone trying to report it as a vuln on August 13th and getting told it's a feature, I'd say he's not exactly generalizing in this specific instance.
- tomjen3 12y agoPretty sure the going rate for a pen-tester is much, much higher than 100 usd an hour - and they would get paid even if they didn't find anything.
- tiglionabbit 12y agoThis is hardly an exploit. Since no authentication is required in order to see the chatroom listings for any domain, we must assume that they meant for their chatroom directory to be public information. This may not be what their customers are expecting, though...
- ZoFreX 12y agoIt's not listing chatrooms, it's listing teams. Very different. For example, at the company I work we have two teams on Slack: Engineering and Marketing. Not really a problem if people find out that! The channel listing would potentially be more interesting, and this exploit does not allow you to see that (spoilers: it's "general", "random", and "cats").
- spacefight 12y agoIt's information disclosure at its finest. Something you _really_ want to avoid in a sensitive environment - which company internal comms certainly is.
- thecus 12y agoIt's a minor degree of information disclosure -- hardly at it's finest.
- dchest 12y agoIt was reported to them before, they said it's not a bug: @rootlabs: Got the expected "not a bug" from @SlackHQ so feel free to see names of MSFT, Google chats via login info leak. http://t.co/kldKXN7NTf https://twitter.com/rootlabs/status/499723782244675584 https://twitter.com/rootlabs/status/499723782244675584
- 4ndr3vv 12y ago13th August? man, someone messed up.
- tomjen3 12y agoResponsible disclosure serves is nothing more than a cover for bad software venders. You are under absolutely no obligation to do work for free that these companies should have been doing in the first place.