Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Technically this was possible before this.

Since the email to each slack user is an @company.com address all you need to do is take control of the employees email address, reset the slack password and login as the target user.



> Since the email to each slack user is an @company.com address

Not necessarily


It turns out administrators could change the email address anyway. :)


Right?


for most companies slack channel, you would need the @company.com to get approved for slack access.

Very rare and unprofessional to allow someone's personal email access




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: