Close Menu
New York Examiner News

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Charli XCX Releases New Song “Wall of Sound”

    January 18, 2026

    Democrats think a war-powers resolution for Greenland would get more GOP votes than one on Venezuela

    January 18, 2026

    Trump accuses Tim Walz and Ilhan Omar of using ICE protests to distract from

    January 18, 2026
    Facebook X (Twitter) Instagram
    New York Examiner News
    • Home
    • US News
    • Politics
    • Business
    • Science
    • Technology
    • Lifestyle
    • Music
    • Television
    • Film
    • Books
    • Contact
      • About
      • Amazon Disclaimer
      • DMCA / Copyrights Disclaimer
      • Terms and Conditions
      • Privacy Policy
    New York Examiner News
    Home»Technology»A Slack Bug Exposed Some Users’ Hashed Passwords for 5 Years
    Technology

    A Slack Bug Exposed Some Users’ Hashed Passwords for 5 Years

    By AdminAugust 6, 2022
    Facebook Twitter Pinterest LinkedIn WhatsApp Email Reddit Telegram
    A Slack Bug Exposed Some Users’ Hashed Passwords for 5 Years


    The office communication platform Slack is known for being easy and intuitive to use. But the company said on Friday that one of its low-friction features contained a vulnerability, now fixed, that exposed cryptographically scrambled versions of some users’ passwords. 

    When users created or revoked a link—known as a “shared invite link”—that others could use to sign up for a given Slack workspace, the command also inadvertently transmitted the link creator’s hashed password to other members of that workspace. The flaw impacted the password of anyone who made or scrubbed a shared invite link over a five-year period, between April 17, 2017, and July 17, 2022.

    Slack, which is now owned by Salesforce, says a security researcher disclosed the bug to the company on July 17, 2022. The errant passwords weren’t visible anywhere in Slack, the company notes, and could have only been apprehended by someone actively monitoring relevant encrypted network traffic from Slack’s servers. Though the company says it’s unlikely that the actual content of any passwords were compromised as a result of the flaw, it notified impacted users on Thursday and forced password resets for all of them. 

    Slack said the situation impacted about 0.5 percent of its users. In 2019 the company said it had more than 10 million daily active users, which would mean roughly 50,000 notifications. By now, the company may have nearly doubled that number of users. Some users who had passwords exposed throughout the five years may not still be Slack users today.

    “We immediately took steps to implement a fix and released an update the same day the bug was discovered, on July 17th, 2022,” the company said in a statement. “Slack has informed all impacted customers and the passwords for impacted users have been reset.”

    The company did not respond to questions from WIRED by press time about which hashing algorithm it used on the passwords or whether the incident has prompted broader assessments of Slack’s password-management architecture.

    “It’s unfortunate that in 2022 we’re still seeing bugs that are clearly the result of failed threat modeling,” says Jake Williams, director of cyber-threat intelligence at the security firm Scythe. “While applications like Slack definitely perform security testing, bugs like this that only come up in edge case functionality still get missed. And obviously, the stakes are very high when it comes to sensitive data like passwords.”

    The situation underscores the challenge of designing flexible and usable web applications that also silo and limit access to high-value data like passwords. If you received a notification from Slack, change your password, and make sure you have two-factor authentication turned on. You can also view the access logs for your account.



    Original Source Link

    Share. Facebook Twitter Pinterest LinkedIn WhatsApp Email Reddit Telegram
    Previous ArticleLarry Brilliant Says Covid Rapid Tests Are Bad for Public Health
    Next Article The ‘radicals’ in the EPA are preventing real change: Sean Duffy

    RELATED POSTS

    Jones Hovercraft 2.0 Snowboard Review: For Big Powder Days

    January 18, 2026

    Why Silicon Valley is really talking about fleeing California (it’s not the 5%)

    January 18, 2026

    Reddit Has Thoughts on Paris Hilton Cookware. So Do We

    January 17, 2026

    AI cloud startup Runpod hits $120M in ARR — and it started with a Reddit post  

    January 17, 2026

    Ads Are Coming to ChatGPT. Here’s How They’ll Work

    January 16, 2026

    Silicon Valley’s messiest breakup is definitely headed to court

    January 16, 2026
    latest posts

    Charli XCX Releases New Song “Wall of Sound”

    Charli XCX has shared a new song from Wuthering Heights, her soundtrack and accompaniment to…

    Democrats think a war-powers resolution for Greenland would get more GOP votes than one on Venezuela

    January 18, 2026

    Trump accuses Tim Walz and Ilhan Omar of using ICE protests to distract from

    January 18, 2026

    Ukrainian drone strikes hit Russian energy infrastructure, Zelenskyy says

    January 18, 2026

    Jones Hovercraft 2.0 Snowboard Review: For Big Powder Days

    January 18, 2026

    NASA’s Artemis II mission to the moon is inching toward the launch pad

    January 18, 2026

    Chihiro Amano: ‘It was like I hit a wall in all…

    January 18, 2026
    Categories
    • Books (1,009)
    • Business (5,914)
    • Events (29)
    • Film (5,850)
    • Lifestyle (3,960)
    • Music (5,951)
    • Politics (5,915)
    • Science (5,265)
    • Technology (5,844)
    • Television (5,528)
    • Uncategorized (6)
    • US News (5,902)
    popular posts

    If you’re not happy with your Medicare Advantage plan, experts offer these tips to find better benefits

    © 2025 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance…

    1923 Season 1 Episode 3 Review: The War Has Come Home

    January 1, 2023

    ICE nabs illegal immigrant convicted for child sex offense, who escaped after parole release in Illinois

    June 17, 2023

    Trump’s Michigan Speech Is A Humiliating Disaster

    September 28, 2023
    Archives
    Browse By Category
    • Books (1,009)
    • Business (5,914)
    • Events (29)
    • Film (5,850)
    • Lifestyle (3,960)
    • Music (5,951)
    • Politics (5,915)
    • Science (5,265)
    • Technology (5,844)
    • Television (5,528)
    • Uncategorized (6)
    • US News (5,902)
    About Us

    We are a creativity led international team with a digital soul. Our work is a custom built by the storytellers and strategists with a flair for exploiting the latest advancements in media and technology.

    Most of all, we stand behind our ideas and believe in creativity as the most powerful force in business.

    What makes us Different

    We care. We collaborate. We do great work. And we do it with a smile, because we’re pretty damn excited to do what we do. If you would like details on what else we can do visit out Contact page.

    Our Picks

    NASA’s Artemis II mission to the moon is inching toward the launch pad

    January 18, 2026

    Chihiro Amano: ‘It was like I hit a wall in all…

    January 18, 2026

    Where We Left Off & What’s Ahead in Season 15

    January 18, 2026
    © 2026 New York Examiner News. All rights reserved. All articles, images, product names, logos, and brands are property of their respective owners. All company, product and service names used in this website are for identification purposes only. Use of these names, logos, and brands does not imply endorsement unless specified. By using this site, you agree to the Terms & Conditions and Privacy Policy.

    Type above and press Enter to search. Press Esc to cancel.

    We use cookies on our website to give you the most relevant experience by remembering your preferences and repeat visits. By clicking “Accept All”, you consent to the use of ALL the cookies. However, you may visit "Cookie Settings" to provide a controlled consent.
    Cookie SettingsAccept All
    Manage consent

    Privacy Overview

    This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
    Necessary
    Always Enabled
    Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
    CookieDurationDescription
    cookielawinfo-checkbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
    cookielawinfo-checkbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
    cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
    cookielawinfo-checkbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
    cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
    viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
    Functional
    Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
    Performance
    Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
    Analytics
    Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
    Advertisement
    Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
    Others
    Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
    SAVE & ACCEPT