• Login
No Result
View All Result
My Blog
  • Home
  • World
  • Politics
  • Business
  • Science
  • Tech
    What One Entrepreneur And Investor Is Saying On the Unique Growth Opportunity In the Life Science Industry

    What One Entrepreneur And Investor Is Saying On the Unique Growth Opportunity In the Life Science Industry

    Dubai Chamber Of Digital Economy And Entrepreneur Middle East Publish A Report On The Prospects Of The Dubai’s Digital Economy

    Dubai Chamber Of Digital Economy And Entrepreneur Middle East Publish A Report On The Prospects Of The Dubai’s Digital Economy

    Never Worry About a Low Battery with This Wireless Charger, Now $80 Off

    Never Worry About a Low Battery with This Wireless Charger, Now $80 Off

    5 Cybersecurity Predictions Home Users Need to Know for 2023

    5 Cybersecurity Predictions Home Users Need to Know for 2023

    Listen to Music Without Blocking Out the World with These Headphones

    Listen to Music Without Blocking Out the World with These Headphones

    Air India To Use ‘Coruson’ Software For Safety Management

    Air India To Use ‘Coruson’ Software For Safety Management

    Trending Tags

    • Sillicon Valley
    • Climate Change
    • Election Results
    • Flat Earth
    • Golden Globes
    • MotoGP 2017
    • Mr. Robot
  • Entertainment
    • All
    • Movie
    • Music
    • Sports
    The ‘Dune’ Miniseries Is a Fascinating Piece of History

    The ‘Dune’ Miniseries Is a Fascinating Piece of History

    Coinbase Offered Them Dream Jobs—and Then Took Them Away

    Coinbase Offered Them Dream Jobs—and Then Took Them Away

    The January 6 Hearings Are Fighting for Your Attention

    The January 6 Hearings Are Fighting for Your Attention

    12 Best Messenger Bags (2022): Crossbody, Slings, Shoulder Bags

    12 Best Messenger Bags (2022): Crossbody, Slings, Shoulder Bags

    Big Tech Has Become a Creature of the Swamp

    Big Tech Has Become a Creature of the Swamp

    Sea to Summit Alto TR1 Review: A Fantastic Ultralight Tent

    Sea to Summit Alto TR1 Review: A Fantastic Ultralight Tent

    Prediction Engines Are Like Karma: You Get What You Stream

    Prediction Engines Are Like Karma: You Get What You Stream

    ‘The Quarry’ Lets You Experience What’s Great About Slasher Films

    ‘The Quarry’ Lets You Experience What’s Great About Slasher Films

    Summer Game Fest’s Biggest Announcement? A ‘Last of Us’ Remake

    Summer Game Fest’s Biggest Announcement? A ‘Last of Us’ Remake

  • Lifestyle
    • All
    • Fashion
    • Health
    • Travel
    nurse

    Everything You Need To Know About Nurse Residency

    Drug detox

    Are you the right candidate for medical detox?

    The Benefit of Using Sunscreen Protection

    Gift Ideas for Celebrating a Loved One’s College Acceptance

    What are the major reasons to form gall bladder stones?

    The ‘Dune’ Miniseries Is a Fascinating Piece of History

    The ‘Dune’ Miniseries Is a Fascinating Piece of History

    Coinbase Offered Them Dream Jobs—and Then Took Them Away

    Coinbase Offered Them Dream Jobs—and Then Took Them Away

    The January 6 Hearings Are Fighting for Your Attention

    The January 6 Hearings Are Fighting for Your Attention

    12 Best Messenger Bags (2022): Crossbody, Slings, Shoulder Bags

    12 Best Messenger Bags (2022): Crossbody, Slings, Shoulder Bags

    Big Tech Has Become a Creature of the Swamp

    Big Tech Has Become a Creature of the Swamp

    Trending Tags

    • Golden Globes
    • Mr. Robot
    • MotoGP 2017
    • Climate Change
    • Flat Earth
  • More
    • Directions
  • Home
  • World
  • Politics
  • Business
  • Science
  • Tech
    What One Entrepreneur And Investor Is Saying On the Unique Growth Opportunity In the Life Science Industry

    What One Entrepreneur And Investor Is Saying On the Unique Growth Opportunity In the Life Science Industry

    Dubai Chamber Of Digital Economy And Entrepreneur Middle East Publish A Report On The Prospects Of The Dubai’s Digital Economy

    Dubai Chamber Of Digital Economy And Entrepreneur Middle East Publish A Report On The Prospects Of The Dubai’s Digital Economy

    Never Worry About a Low Battery with This Wireless Charger, Now $80 Off

    Never Worry About a Low Battery with This Wireless Charger, Now $80 Off

    5 Cybersecurity Predictions Home Users Need to Know for 2023

    5 Cybersecurity Predictions Home Users Need to Know for 2023

    Listen to Music Without Blocking Out the World with These Headphones

    Listen to Music Without Blocking Out the World with These Headphones

    Air India To Use ‘Coruson’ Software For Safety Management

    Air India To Use ‘Coruson’ Software For Safety Management

    Trending Tags

    • Sillicon Valley
    • Climate Change
    • Election Results
    • Flat Earth
    • Golden Globes
    • MotoGP 2017
    • Mr. Robot
  • Entertainment
    • All
    • Movie
    • Music
    • Sports
    The ‘Dune’ Miniseries Is a Fascinating Piece of History

    The ‘Dune’ Miniseries Is a Fascinating Piece of History

    Coinbase Offered Them Dream Jobs—and Then Took Them Away

    Coinbase Offered Them Dream Jobs—and Then Took Them Away

    The January 6 Hearings Are Fighting for Your Attention

    The January 6 Hearings Are Fighting for Your Attention

    12 Best Messenger Bags (2022): Crossbody, Slings, Shoulder Bags

    12 Best Messenger Bags (2022): Crossbody, Slings, Shoulder Bags

    Big Tech Has Become a Creature of the Swamp

    Big Tech Has Become a Creature of the Swamp

    Sea to Summit Alto TR1 Review: A Fantastic Ultralight Tent

    Sea to Summit Alto TR1 Review: A Fantastic Ultralight Tent

    Prediction Engines Are Like Karma: You Get What You Stream

    Prediction Engines Are Like Karma: You Get What You Stream

    ‘The Quarry’ Lets You Experience What’s Great About Slasher Films

    ‘The Quarry’ Lets You Experience What’s Great About Slasher Films

    Summer Game Fest’s Biggest Announcement? A ‘Last of Us’ Remake

    Summer Game Fest’s Biggest Announcement? A ‘Last of Us’ Remake

  • Lifestyle
    • All
    • Fashion
    • Health
    • Travel
    nurse

    Everything You Need To Know About Nurse Residency

    Drug detox

    Are you the right candidate for medical detox?

    The Benefit of Using Sunscreen Protection

    Gift Ideas for Celebrating a Loved One’s College Acceptance

    What are the major reasons to form gall bladder stones?

    The ‘Dune’ Miniseries Is a Fascinating Piece of History

    The ‘Dune’ Miniseries Is a Fascinating Piece of History

    Coinbase Offered Them Dream Jobs—and Then Took Them Away

    Coinbase Offered Them Dream Jobs—and Then Took Them Away

    The January 6 Hearings Are Fighting for Your Attention

    The January 6 Hearings Are Fighting for Your Attention

    12 Best Messenger Bags (2022): Crossbody, Slings, Shoulder Bags

    12 Best Messenger Bags (2022): Crossbody, Slings, Shoulder Bags

    Big Tech Has Become a Creature of the Swamp

    Big Tech Has Become a Creature of the Swamp

    Trending Tags

    • Golden Globes
    • Mr. Robot
    • MotoGP 2017
    • Climate Change
    • Flat Earth
  • More
    • Directions
No Result
View All Result
My Blog
No Result
View All Result
Home National

A Slack Bug Exposed Some Users’ Hashed Passwords for 5 Years

by lacygibson
August 5, 2022
in National, World
0
A Slack Bug Exposed Some Users’ Hashed Passwords for 5 Years
0
SHARES
1
VIEWS
Share on FacebookShare on Twitter


office communication The platform Slack is known for being easy to use and intuitive. But the company said Friday that one of its low-friction features contained a bug, now fixed, that exposed encrypted versions of some users’ passwords.

When a user creates or revokes a link (called a “shared invite link”) that others can use to register for a given Slack workspace, the command also inadvertently transmits the link creator’s hashed password to that workspace other members of . The vulnerability affects the password of anyone who creates or clears a shared invite link within a five-year period between April 17, 2017 and July 17, 2022.

Slack, now owned by Salesforce, said a security researcher disclosed the vulnerability to the company on July 17, 2022. The company noted that wrong passwords are not seen anywhere on Slack and can only be apprehended by those who are actively monitoring them. Associated encrypted web traffic from Slack servers. While the company said the actual content of any passwords was unlikely to be compromised by the breach, it notified affected users on Thursday and forced password resets for all users.

Slack said the situation affected about 0.5 percent of its users. The company said it had more than 10 million daily active users in 2019, which translates to around 50,000 notifications. The company may have nearly doubled its number of users so far. Some users who exposed their passwords over the past five years may no longer be Slack users today.

“We took immediate steps to implement a fix and released an update on July 17, 2022, the same day the vulnerability was discovered,” the company said in a statement. “Slack has notified all affected customers, and affected users ‘s password has been reset.”

As of press time, the company did not answer WIRED’s questions about which hashing algorithm it uses on passwords and whether the incident prompted a broader review of Slack’s password management architecture.

“Unfortunately, in 2022, we will still see errors that are clearly the result of failures in threat modeling,” said Jake Williams, director of cyber threat intelligence at security firm Scythe. “While apps like Slack certainly perform security testing, bugs like this that only appear in edge-case functionality can still be missed. Obviously, the stakes are very high when sensitive data like passwords are involved.”

This situation highlights the challenges of designing flexible and usable web applications that are also designed to be silos and restrict access to high-value data such as passwords. If you get a notification from Slack, change your password and make sure you have two-factor authentication turned on. You can also view access logs for your account.

Tags: BugExposedHashedpasswordPasswordsrelaxationSafetySlackUsersYears
lacygibson

lacygibson

Next Post
A Slack Bug Exposed Some Users’ Hashed Passwords for 5 Years

A Slack Bug Exposed Some Users' Hashed Passwords for 5 Years

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recommended

Kristina Aabel — OfficialUSA.com Records

7 months ago
Celebrities, TikTok, and a Cat Bot Are Crashing Chess.com

Celebrities, TikTok, and a Cat Bot Are Crashing Chess.com

1 week ago

Popular News

    Connect with us

    • Contact
    • Read Latest News Around The World – Frapios
    Write Us at: [email protected]

    Copyright Reserved © 2022

    No Result
    View All Result
    • Home
    • Politics
    • World
    • Business
    • Science
    • National
    • Entertainment
    • Gaming
    • Movie
    • Music
    • Sports
    • Fashion
    • Lifestyle
    • Travel
    • Tech
    • Health
    • Food

    Copyright Reserved © 2022

    Welcome Back!

    Login to your account below

    Forgotten Password?

    Retrieve your password

    Please enter your username or email address to reset your password.

    Log In