Slack Shared Channel Metadata Exposure

Share this post

Slack sent us a notice on Thursday, March 18, 2021 that due to a software vulnerability it “unintentionally shared Slack Connect metadata” with partners that we share a Slack channel with. The result was a Slack shared channel metadata exposure.

Slack is a messaging platform that we use to communicate internally and externally with some of our clients. For those that we communicate with externally, we have a shared Slack channel.

Some of the data that we associate with the channel such as descriptions of channel were inadvertently shared with the other party on their analytics dashboard.

Is this a big deal? No.

Are we proud of Slack for the way that they handled it? Yes.

Slack Shared Channel Metadata Exposure

Some details, first, from Slack:

“This software bug impacted workspaces using Slack Connect channels between September 12, 2017 and February 24, 2021. Slack identified this problem through an internal review on February 19th, 2021 and immediately took steps to fix the problem, standardizing behavior between the client and the channel analytics dashboard so that changes to the channel names and the channel topic and purpose were no longer visible to the external organization.”

Through Slack’s internal processes, it identified the issue. They corrected the problem. They emailed us to let us know with clear language. Our email detailed which shared channels had their metadata exposed.

It would be great if all future exposures were so minimal and were handled so cleanly by the vendor. The way that this was handled is a sign of Slack’s security maturity for handling the Slack shared channel metadata exposure.

Tales From The Click

Sign up for our monthly newsletter for business leaders on minimizing cybersecurity risk.

Suceed at SOC 2

Free eBook:
5 Things to Know for your First SOC 2

  • How to scope your SOC 2
  • Estimate the cost and length of your SOC 2
  • Prepare for your SOC 2
  • Manage the SOC 2 audit period
  • Leverage your SOC 2 for growth

Related Posts

Is your Cyber Insurance really going to cover you?

Only 1/3 of cyber insurance policies actually pay out in incidents. Most companies have cyber insurance policies that insure too little, or too much, and have absurdly low caps and silly exclusions.

To learn more about cyber insurance and determine if you have the right coverage for you, join us for a free vCISO Office Hours session on Tuesday, April 18 at 1 p.m. eastern time. Bring your questions!

New Release: Free SOC 2 eBook!

Getting ready for your first SOC 2? This eBook is full of actionable advice to help you prepare for and succeed in your first SOC 2 audit.

Learn:

  • How to scope your SOC 2 project
  • How to estimate the cost and length of your SOC 2 project
  • How to prepare for your SOC 2
  • How to succeed in your SOC 2 audit period
  • How to leverage your SOC 2 report to enable your business and sales
Is your Cyber Insurance really going to cover you?

Only 1/3 of cyber insurance policies actually pay out in incidents. Most companies have cyber insurance policies that insure too little, or too much, and have absurdly low caps and silly exclusions.

To learn more about cyber insurance and determine if you have the right coverage for you, join us for a free vCISO Office Hours session on Tuesday, April 18 at 1 p.m. eastern time. Bring your questions!

New Release: Free SOC 2 eBook!

Getting ready for your first SOC 2? This eBook is full of actionable advice to help you prepare for and succeed in your first SOC 2 audit.

Learn:

  • How to scope your SOC 2 project
  • How to estimate the cost and length of your SOC 2 project
  • How to prepare for your SOC 2
  • How to succeed in your SOC 2 audit period
  • How to leverage your SOC 2 report to enable your business and sales