Your Web News in One Place

Help Webnuz

Referal links:

Sign up for GreenGeeks web hosting
April 29, 2016 03:13 pm GMT

Ouch: Some Slack developers have been exposing corporate data

Screen_shot_2016-04-29_at_4.13.13_pm

If you perform a very specific query in the search field of online code repository Github, where many Slack bot projects are stored, you can get info that potentially lets you access a trove of corporate data, including companies' internal chats and files. 

This is because a lot of Slack bot developers — and there are a lot of them, since building a Slack bot is quite easy — included their Slack tokens (personal Slack account credentials) directly in the code, which they share publicly on Github. 

The issue was discovered by security company Detectify, which notified Slack about it on March 26. Detectify managed to find "thousands" of such tokens with a simple GitHub search. The story was first reported by Quartz. Read more...

More about Corporate Data Leak, Github, Tokens, Slack, and Tech

Original Link: http://feeds.mashable.com/~r/mashable/tech/~3/V5nS03TrFj8/

Share this article:    Share on Facebook
View Full Article

Mashable

Mashable is the top source for news in social and digital media, technology and web culture.

More About this Source Visit Mashable