Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

tldr-

November 2017: added TURN abuse to our stunner toolset

December 2017: discovered and reported TURN vulnerability in private customer of Enable Security

February 2018: briefly tested Slack and discovered the vulnerability

April 2018: submitted our report to Slack, helped them reproduce and address the issue through various rounds of testing

May 2018: Slack pushed patch to live servers which was retested by Enable Security

January 2020: asked to publish report

February 2020: disclosure delayed by HackerOne/Slack

March 2020: report published



Don't use indentation for formatting linebreaks. It beaks HN layout.

Just add extra linebreaks


I've fixed the formatting now.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: