TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Slack's private GitHub code repositories stolen over holidays

347 pointsby mindracerover 2 years ago

23 comments

openplatypusover 2 years ago
What&#x27;s the most interesting in this whole write-up is this: &gt; Security update hidden from search engines<p>Slack is selectively and deliberately limiting public access (discoverability) to the security breach announcements.
评论 #34258847 未加载
评论 #34258443 未加载
评论 #34258031 未加载
captn3m0over 2 years ago
Timeline matches with the Travis breach. So far likely impacted:<p>1. Slack<p>2. Okta (<a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=34081154" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=34081154</a>)<p>3. Coa (<a href="https:&#x2F;&#x2F;github.com&#x2F;veged&#x2F;coa&#x2F;issues&#x2F;99#issuecomment-961696885">https:&#x2F;&#x2F;github.com&#x2F;veged&#x2F;coa&#x2F;issues&#x2F;99#issuecomment-96169688...</a>)
评论 #34258276 未加载
评论 #34260555 未加载
评论 #34258679 未加载
muglugover 2 years ago
I work for Slack, opinions my own.<p>IMO the headline should be updated — much less than 1% of Slack’s private code can be accessed via github.com.
评论 #34258757 未加载
评论 #34258753 未加载
photoGrantover 2 years ago
This is how LastPass started the efficient downward spiral, no? This isn&#x27;t shocking, but also is.<p>Is it wise to simply keep private repositories away from GitHub at this point? It seems the best way to avoid being drawn in with the rest as a target.<p>Internal bad actors? So location wouldn&#x27;t matter?
评论 #34258526 未加载
评论 #34257769 未加载
评论 #34260013 未加载
shanebelloneover 2 years ago
Does it actually matter? I might be overlooking something but...<p>Slack is more than its code. The product is really the aggregate of their engineer&#x27;s knowledge and internal processes. It&#x27;s not practical to steal code and build a business or spinoff product around it.<p>The only legitimate threat seems to be the potential for exploitation. I suppose this might also threaten any backend improvements (economic leverage) they made with proprietary algorithms.
评论 #34259095 未加载
BoardsOfCanadaover 2 years ago
I hope microsoft can have a look and improve teams.
评论 #34258197 未加载
评论 #34258237 未加载
评论 #34258226 未加载
评论 #34260549 未加载
bjd2385over 2 years ago
This is exactly why secrets should not be stashed in any Git repository. Granted, I&#x27;m not sure they&#x27;re much safer in other managed services dedicated to protecting our secrets, with the news of several breaches as of late :&#x2F;
janosdebugsover 2 years ago
It would be so nice if GitHub deprecated their one key takes all and would let us create per-org personal access tokens. Also, organizations having power over these access tokens.
评论 #34258787 未加载
j45over 2 years ago
It remains surprising to see such private and valuable codebases hosted in the cloud in an external parties service.<p>The cloud remains someone else’s shared computer.
rvzover 2 years ago
Like I said before [0][1], a reminder that private repositories are not private on GitHub.<p>A great time to self-host.<p>[0] <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=34232347" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=34232347</a><p>[1] <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=23102942" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=23102942</a>
ianpurtonover 2 years ago
Slack could open source their code anyway. Slacks competitive advantage is their network of users which is difficult to copy.
评论 #34259712 未加载
评论 #34259370 未加载
danweeover 2 years ago
We&#x27;ve migrated from Slack to Mattermost some time ago. Best decision ever. Not sure why companies keep using Slack nowadays. It&#x27;s like those companies many years ago using HipChat instead of Slack. Slack&#x27;s is the HipChat of today.
评论 #34260963 未加载
评论 #34259607 未加载
评论 #34259804 未加载
评论 #34259323 未加载
halukakinover 2 years ago
I hope github would start allowing all users to use ip whitelisting features. I understand it is a sell point for enterprise accounts, but tokens&#x2F;passwords are not secure enough in today&#x27;s environment.
blkhp19over 2 years ago
So, where can these be found? I’d like to dig through the code.
nickjjover 2 years ago
They say no customer data was compromised and are investigating &quot;potential impact&quot; to customers.<p>The potential impact here is an attacker now has access to some of their code which could let them find and take advantage of vulnerabilities resulting in customer data being accessed.<p>Technically &quot;potential impact&quot; is correct but I think companies often underplay how severe a source code leak is. It&#x27;s the exact blueprint of how their app is built.
评论 #34258156 未加载
Suvitrufover 2 years ago
&gt; No downloaded repositories contained customer data, means to access customer data, or Slack’s primary codebase.
umanwizardover 2 years ago
Oh good, maybe someone will finally fix their many annoying bugs
marbanover 2 years ago
Streisand effect anyone?
tedk-42over 2 years ago
Doesn&#x27;t sound too bad to be honest
hosejaover 2 years ago
Do they not have them anymore?
mytailorisrichover 2 years ago
I don&#x27;t understand why some companies host their code externally on Github.<p>For a software company the code repo is the #1 asset.
评论 #34258611 未加载
评论 #34260595 未加载
评论 #34259354 未加载
IgorPartolaover 2 years ago
Stolen means Slack no longer has something that the thief has, right?
评论 #34259871 未加载
ergonaughtover 2 years ago
Offtopic, but, I made the mistake of trying to read this on my mobile phone this morning, where I don&#x27;t use adblockers per se. Served at least 6 ads, even ignoring the nonsense at the bottom of the page. So annoying and disruptive that I didn&#x27;t manage to read the story, and will find the details somewhere else.<p>We really needed a reaction against this nonsense which wasn&#x27;t just adblockers.<p>Bummer.
评论 #34262699 未加载