Tell HN: Security notice from Slack regarding Shared Invitation links

  • I’m willing to bet someone `JSON.stringify`’d the entire user object without realizing the password hash is in there.

    The broader conversation I think here is facilitating a shift to passwordless. Magic links, OAuth, Yubikeys all make passwords redundant.

    If I put in a password I still need MFA and I can reset my password with just MFA, so why do I need the password at all? Let’s just switch to MFA-only signon.

    Slack kinda led the charge to magic links and passwordless so it’s strange to see they’re still stuck on this. Many enterprise orgs have moved SSO setups to enforce solely passwordless already.

  • I also received such messages. I think I could sleep more easily if there was a notice on the Slack website as well concerning this issue.

    I searched briefly but couldn't find one; does anyone else know more?

  • [flagged]