4 ms·
> ADP should be figuring out a way to give Zenefits (and any other similar companies) more secure access to their platform, not cutting them off. From the PDF:
by 7Figures2Commas 11y ago
> ADP should be figuring out a way to give Zenefits (and any other similar companies) more secure access to their platform, not cutting them off.
From the PDF:
Despite having many legitimate ways to integrate with ADP properly, Zenefits chose an unsecure and indirect approach.
> If someone wants to manage their account through a 3rd party that allegedly uses some non-standard way of accessing ADP then that's a risk they decided to take.
From the PDF:
Despite Zenefits serving less than 0.25% of the clients on our system, they had been responsible for up to 25.0% of the total user traffic (in other words, a hundred-fold times ordinary user traffic).
The Zenefits approach was not only putting excessive and unnecessary demand on ADP’s servers, but it was pulling sensitive information, including unmasked Social Security numbers and employee banking information, in a manner that did not comply with ADP’s standards for data security.
It sounds like ADP did what any company, large or small, would do when faced with a third party accessing its systems in an unauthorized and inefficient manner.
- slang800 11y ago> Despite having many legitimate ways to integrate with ADP properly, Zenefits chose an unsecure and indirect approach. Do you really think Zenefits just chose this "lesser" method on a whim? I've never met the team from Zenefits, so I can't say for certain, but if they're not idiots then I think there's a reason why they decided not to use the regular API. Whether that's a requirement of getting their app approved by the ADP Marketplace, or some restriction on the data that they are able to get through the official API - I think that there's something that ADP isn't mentioning. > It sounds like ADP did what any company, large or small, would do when faced with a third party accessing its systems in an unauthorized and inefficient manner. As far as unauthorized methods go - you'd patch the hole in your security to prevent them from getting through. Unauthorized methods of accessing your systems shouldn't exist, and blacklisting the domain name of the third-party isn't how you fix a security flaw. For the excessive load, they should just implement rate limiting across their system & return a 429 when someone goes over. Of course, I really doubt that they were accessing ADP via a real security flaw - they were probably just making the same requests as users are able to, but in an automated fashion. And if that's the case then the term "unauthorized" doesn't apply, because users are clearly authorized to make those requests.
- 7Figures2Commas 11y ago> I've never met the team from Zenefits, so I can't say for certain, but if they're not idiots... The founder of Zenefits posted here on HN that "APIs == zero errors"[1]. Anybody who has worked with APIs knows this is not the case so you may be overestimating Zenefits' competence. > Unauthorized methods of accessing your systems shouldn't exist... Yes, scrapers should not exist.
- smackfu 11y ago> For the excessive load, they should just implement rate limiting across their system & return a 429 when someone goes over. Practically, I'm not sure that would be much better for Zenefits.
- slang800 11y agoI think that rate limiting might just force Zenefits to stop using whatever contributed to the high load, and ensure that their API calls are efficient enough. Otherwise, if they really can't do without that volume of calls, then at least they would be locked out in the same way that everyone else is & they couldn't really call it unfair.
- gvb 11y ago> As far as unauthorized methods go - you'd patch the hole in your security to prevent them from getting through. "They gained access to our systems by convincing clients to give them administrative access to our platform." When ADP's clients giving out administration access[1] is the security hole, that is a reasonable way to patch it. The alternative is for ADP to fire their clients. [1] I have not seen ADP's TOS, but I would expect giving out the administration login to third party outfits is a violation of it.