← Back to context

Comment by nodamage

4 months ago

The Slack takeover exploit is a problem on Slack's end (and sounds more like a configuration issue than a bug) so Zendesk would not be responsible for that anyway though.

I disagree, the problem is clearly on Zendesks end.

  • Don't get me wrong, Zendesk definitely has their own separate problem: you should not be able to CC yourself onto an existing support ticket by emailing a guessable ticket ID.

    But simultaneously you should not be able to get into a company Slack by simply having an account with a @company.com email address created by a third-party SSO provider.

    In other words, even in Zendesk fixed their problem, Slack would still have a problem on their end.