WeWEAT
  • Home
  • Tech News
  • Ideas
  • Innovation
  • Science
  • Perspective
WeWEAT
  • Home
  • Tech News
  • Ideas
  • Innovation
  • Science
  • Perspective
  • Tech News

A Slack Bug Uncovered Some Customers’ Hashed Passwords for five Years

  • August 5, 2022
  • admin
A Slack Bug Exposed Some Users’ Hashed Passwords for 5 Years
Total
0
Shares
0
0
0

The workplace communication platform Slack is thought for being simple and intuitive to make use of. However the firm mentioned on Friday that one in all its low-friction options contained a vulnerability, now fastened, that uncovered cryptographically scrambled variations of some customers’ passwords. 

When customers created or revoked a hyperlink—often known as a “shared invite hyperlink”—that others may use to join a given Slack workspace, the command additionally inadvertently transmitted the hyperlink creator’s hashed password to different members of that workspace. The flaw impacted the password of anybody who made or scrubbed a shared invite hyperlink over a five-year interval, between April 17, 2017, and July 17, 2022.

Slack, which is now owned by Salesforce, says a safety researcher disclosed the bug to the corporate on July 17, 2022. The errant passwords weren’t seen anyplace in Slack, the corporate notes, and will have solely been apprehended by somebody actively monitoring related encrypted community visitors from Slack’s servers. Although the corporate says it is unlikely that the precise content material of any passwords had been compromised because of the flaw, it notified impacted customers on Thursday and compelled password resets for all of them. 

Slack mentioned the state of affairs impacted about 0.5 % of its customers. In 2019 the corporate mentioned it had greater than 10 million every day lively customers, which might imply roughly 50,000 notifications. By now, the corporate could have almost doubled that variety of customers. Some customers who had passwords uncovered all through the 5 years could not nonetheless be Slack customers right this moment.

“We instantly took steps to implement a repair and launched an replace the identical day the bug was found, on July seventeenth, 2022,” the corporate mentioned in an announcement. “Slack has knowledgeable all impacted prospects and the passwords for impacted customers have been reset.”

The corporate didn’t reply to questions from WIRED by press time about which hashing algorithm it used on the passwords or whether or not the incident has prompted broader assessments of Slack’s password-management structure.

“It is unlucky that in 2022 we’re nonetheless seeing bugs which are clearly the results of failed menace modeling,” says Jake Williams, director of cyber-threat intelligence on the safety agency Scythe. “Whereas purposes like Slack positively carry out safety testing, bugs like this that solely come up in edge case performance nonetheless get missed. And clearly, the stakes are very excessive on the subject of delicate knowledge like passwords.”

The state of affairs underscores the problem of designing versatile and usable internet purposes that additionally silo and restrict entry to high-value knowledge like passwords. When you acquired a notification from Slack, change your password, and be sure to have two-factor authentication turned on. You too can view the entry logs in your account.

Total
0
Shares
Share 0
Tweet 0
Pin it 0
admin

Previous Article
Amazon's iRobot Deal Would Give It Maps Inside Millions of Homes
  • Tech News

Amazon’s iRobot Deal Would Give It Maps Inside Hundreds of thousands of Properties

  • August 5, 2022
  • admin
View Post
Next Article
Alex Jones faces $45.2 million defamation verdict — but could pay less
  • Tech News

Alex Jones faces $45.2 million defamation verdict — however may pay much less

  • August 5, 2022
  • admin
View Post
You May Also Like
A Single Flaw Broke Every Layer of Security in MacOS
View Post
  • Tech News

A Single Flaw Broke Each Layer of Safety in MacOS

  • admin
  • August 12, 2022
With the Inflation Reduction Act, the US brings climate goals within reach
View Post
  • Tech News

With the Inflation Discount Act, the US brings local weather targets inside attain

  • admin
  • August 12, 2022
South Korean president pardons Samsung heir Lee for bribing predecessor
View Post
  • Tech News

South Korean president pardons Samsung inheritor Lee for bribing predecessor

  • admin
  • August 12, 2022
Brazilian court orders Apple and Google to block Telegram
View Post
  • Tech News

Apple held up Telegram’s newest replace over emoji

  • admin
  • August 12, 2022
Twitch changes course, will now require masks at TwitchCon
View Post
  • Tech News

Twitch adjustments course, will now require masks at TwitchCon

  • admin
  • August 12, 2022
Zoom’s Auto-Update Feature Came With Hidden Risks on Mac
View Post
  • Tech News

Zoom’s Auto-Replace Function Got here With Hidden Dangers on Mac

  • admin
  • August 12, 2022
PSA: Update Zoom on Mac to fix a bug that keeps your mic on after meetings
View Post
  • Tech News

The Zoom installer let a researcher hack his solution to root entry on macOS

  • admin
  • August 12, 2022
Peloton gears up to hike prices, lay off employees, and shutter stores
View Post
  • Tech News

Peloton gears as much as hike costs, lay off workers, and shutter shops

  • admin
  • August 12, 2022

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

WeWEAT
  • Home
  • Contact us

Input your search keywords and press Enter.