Information Security - Slack Initiates Mass Password Reset
https://threatpost.com/slack-password-reset/146545/

Information Security - Slack Initiates Mass Password Reset

The popular workspace collaboration platform Slack is in the middle of asking tens of thousands of users to reset their passwords after a security breach.

The move is actually in response to new information that has come to light regarding a 2015 compromise, when hackers infiltrated Slack’s networks to gain access to databases containing user credentials including hashed passwords. They also planted password-scraping malware to capture login information in plaintext when users signed in.

While Slack implemented two-factor authentication and a password reset for those affected at the time, a new crop of people that were impacted by the event has come to light after a new batch of stolen credentials was reported via the company’s bug-bounty program.

However, the company thought the issue stemmed from the rampant practice of password reuse, until closer inspection showed the trove to be a previously unknown group of accounts that were compromised in the 2015 incident.

“These types of reports are fairly routine and usually the result of malware or password re-use between services,” according to a website notice. “However, as more information became available and our investigation continued, we determined that the majority of compromised credentials were from accounts that logged in to Slack during the 2015 security incident.”

Slack said that it has decided to reset passwords for all users who were active at the time of the 2015 breach; those who have changed their password since then and those who log in via single-sign-on (SSO) platforms are excepted. In total, about 100,000 users are affected.

要查看或添加评论,请登录

Mark Coley的更多文章

  • How browsers resolve competing CSS styles

    How browsers resolve competing CSS styles

    We style our websites using CSS, which stands for Cascading Style Sheets. But what does Cascading really mean? The CSS…

  • Must have tools to improve the quality of your PHP Code

    Must have tools to improve the quality of your PHP Code

    In this article, I want to showcase you a number of essential proper testing tools that will aid to improve the quality…

  • OWASP- Top 10 Vulnerabilities in web applications

    OWASP- Top 10 Vulnerabilities in web applications

    Introduction OWASP (Open web application security project) community helps organizations develop secure applications…

  • A Guide to Improving DevOps Performance

    A Guide to Improving DevOps Performance

    There are two aspects of the DevOps services - ensuring continuous software development, implementation and delivery…

  • MySQL Optimization Tips

    MySQL Optimization Tips

    Benefits The primary advantage of identifying performance driving factor for database allows you to avoid…

    1 条评论

社区洞察

其他会员也浏览了