Close Menu
New York Examiner News

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Marilyn Manson Halts Concert For ‘Confession’ About Sobriety

    April 24, 2026

    Businesses spending $4 million to cross the Panama Canal as ‘it’s safer’ than the Strait of Hormuz

    April 24, 2026

    Trump’s Nightmare Week Worsens As Democrats Prepare Day One Impeachment Plan

    April 24, 2026
    Facebook X (Twitter) Instagram
    New York Examiner News
    • Home
    • US News
    • Politics
    • Business
    • Science
    • Technology
    • Lifestyle
    • Music
    • Television
    • Film
    • Books
    • Contact
      • About
      • Amazon Disclaimer
      • DMCA / Copyrights Disclaimer
      • Terms and Conditions
      • Privacy Policy
    New York Examiner News
    Home»Technology»Slack and Teams’ Lax App Security Raises Alarms
    Technology

    Slack and Teams’ Lax App Security Raises Alarms

    By AdminSeptember 23, 2022
    Facebook Twitter Pinterest LinkedIn WhatsApp Email Reddit Telegram
    Slack and Teams’ Lax App Security Raises Alarms


    Collaboration apps like Slack and Microsoft Teams have become the connective tissue of the modern workplace, tying together users with everything from messaging to scheduling to video conference tools. But as Slack and Teams become full-blown, app-enabled operating systems of corporate productivity, one group of researchers has pointed to serious risks in what they expose to third-party programs—at the same time as they’re trusted with more organizations’ sensitive data than ever before.

    A new study by researchers at the University of Wisconsin-Madison points to troubling gaps in the third-party app security model of both Slack and Teams, which range from a lack of review of the apps’ code to default settings that allow any user to install an app for an entire workspace. And while Slack and Teams apps are at least limited by the permissions they seek approval for upon installation, the study’s survey of those safeguards found that hundreds of apps’ permissions would nonetheless allow them to potentially post messages as a user, hijack the functionality of other legitimate apps, or even, in a handful of cases, access content in private channels when no such permission was granted.

    “Slack and Teams are becoming clearinghouses of all of an organization’s sensitive resources,” says Earlence Fernandes, one of the researchers on the study who now works as a professor of computer science at the University of California at San Diego, and who presented the research last month at the USENIX Security conference. “And yet, the apps running on them, which provide a lot of collaboration functionality, can violate any expectation of security and privacy users would have in such a platform.”

    When WIRED reached out to Slack and Microsoft about the researchers’ findings, Microsoft declined to comment until it could speak to the researchers. (The researchers say they communicated with Microsoft about their findings prior to publication.) Slack, for its part, says that a collection of approved apps that is available in its Slack App Directory does receive security reviews before inclusion and are monitored for any suspicious behavior. It “strongly recommends” that users install only these approved apps and that administrators configure their workspaces to allow users to install apps only with an administrator’s permission. “We take privacy and security very seriously,” the company says in a statement, “and we work to ensure that the Slack platform is a trusted environment to build and distribute apps, and that those apps are enterprise-grade from day one.”

    But both Slack and Teams nonetheless have fundamental issues in their vetting of third-party apps, the researchers argue. They both allow integration of apps hosted on the app developer’s own servers with no review of the apps’ actual code by Slack or Microsoft engineers. Even the apps reviewed for inclusion in Slack’s App Directory undergo only a more superficial check of the apps’ functionality to see whether they work as described, check elements of their security configuration such as their use of encryption, and run automated app scans that check their interfaces for vulnerabilities.

    Despite Slack’s own recommendations, both collaboration platforms by default allow any user to add these independently hosted apps to a workspace. An organization’s administrators can switch on stricter security settings that require the administrators to approve apps before they’re installed. But even then, those administrators must approve or deny apps without themselves having any ability to vet their code, either—and crucially, the apps’ code can change at any time, allowing a seemingly legitimate app to become a malicious one. That means attacks could take the form of malicious apps disguised as innocent ones, or truly legitimate apps could be compromised by hackers in a supply chain attack, in which hackers sabotage an application at its source in an effort to target the networks of its users. And with no access to apps’ underlying code, those changes could be undetectable to both administrators and any monitoring system used by Slack or Microsoft.



    Original Source Link

    Share. Facebook Twitter Pinterest LinkedIn WhatsApp Email Reddit Telegram
    Previous ArticleRobot navigates indoors by tracking anomalies in magnetic fields
    Next Article Orioles hired investment bank to assess potential sale of team: report

    RELATED POSTS

    Give Mom Warm Coffee All Year Long With This Ember Smart Mug Deal

    April 24, 2026

    Porsche is adding an all-electric Cayenne coupe to its lineup

    April 24, 2026

    Newly Deciphered Sabotage Malware May Have Targeted Iran’s Nuclear Program—and Predates Stuxnet

    April 23, 2026

    India’s app market is booming — but global platforms are capturing most of the gains

    April 23, 2026

    Sam Altman’s Orb Company Promoted a Bruno Mars Partnership That Doesn’t Exist

    April 22, 2026

    Redwood Materials lays off 10% in restructuring to chase energy storage business

    April 22, 2026
    latest posts

    Marilyn Manson Halts Concert For ‘Confession’ About Sobriety

    Marilyn Manson needed to stop down during the first show of his current tour to…

    Businesses spending $4 million to cross the Panama Canal as ‘it’s safer’ than the Strait of Hormuz

    April 24, 2026

    Trump’s Nightmare Week Worsens As Democrats Prepare Day One Impeachment Plan

    April 24, 2026

    Federal judge sanctions law firm in Epstein-linked case against Leon Black

    April 24, 2026

    Give Mom Warm Coffee All Year Long With This Ember Smart Mug Deal

    April 24, 2026

    One scientist’s 10-year quest to calculate the strength of gravity

    April 24, 2026

    5 Best Horror Movies Turning 50 In 2026, Ranked

    April 24, 2026
    Categories
    • Books (1,203)
    • Business (6,106)
    • Events (48)
    • Film (6,043)
    • Lifestyle (4,145)
    • Music (6,157)
    • Politics (6,105)
    • Science (5,460)
    • Technology (6,037)
    • Television (5,725)
    • Uncategorized (7)
    • US News (6,095)
    popular posts

    This Is What It’s Like To Live With Your Ex-Spouse While Dating Other People

    Earlier this week, former New York City Mayor Bill de Blasio and his wife, Chirlane…

    Watch NCIS: Hawai’i Online: Season 1 Episode 22

    May 24, 2022

    Forecasting the Future of Weather – Margins of Error

    June 23, 2022

    The Climate Struggle Literally Hit Home in 2022

    December 30, 2022
    Archives
    Browse By Category
    • Books (1,203)
    • Business (6,106)
    • Events (48)
    • Film (6,043)
    • Lifestyle (4,145)
    • Music (6,157)
    • Politics (6,105)
    • Science (5,460)
    • Technology (6,037)
    • Television (5,725)
    • Uncategorized (7)
    • US News (6,095)
    About Us

    We are a creativity led international team with a digital soul. Our work is a custom built by the storytellers and strategists with a flair for exploiting the latest advancements in media and technology.

    Most of all, we stand behind our ideas and believe in creativity as the most powerful force in business.

    What makes us Different

    We care. We collaborate. We do great work. And we do it with a smile, because we’re pretty damn excited to do what we do. If you would like details on what else we can do visit out Contact page.

    Our Picks

    One scientist’s 10-year quest to calculate the strength of gravity

    April 24, 2026

    5 Best Horror Movies Turning 50 In 2026, Ranked

    April 24, 2026

    ‘Unexpected’ Hunter’s Dad Granted Custody, Texts With Falen

    April 24, 2026
    © 2026 New York Examiner News. All rights reserved. All articles, images, product names, logos, and brands are property of their respective owners. All company, product and service names used in this website are for identification purposes only. Use of these names, logos, and brands does not imply endorsement unless specified. By using this site, you agree to the Terms & Conditions and Privacy Policy.

    Type above and press Enter to search. Press Esc to cancel.

    We use cookies on our website to give you the most relevant experience by remembering your preferences and repeat visits. By clicking “Accept All”, you consent to the use of ALL the cookies. However, you may visit "Cookie Settings" to provide a controlled consent.
    Cookie SettingsAccept All
    Manage consent

    Privacy Overview

    This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
    Necessary
    Always Enabled
    Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
    CookieDurationDescription
    cookielawinfo-checkbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
    cookielawinfo-checkbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
    cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
    cookielawinfo-checkbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
    cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
    viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
    Functional
    Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
    Performance
    Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
    Analytics
    Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
    Advertisement
    Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
    Others
    Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
    SAVE & ACCEPT