Hacker News new | past | comments | ask | show | jobs | submit | migueltarga's comments login

Thank you Gabe, I sent you an email.


Received. I confirmed the team is working the issue. Stay tuned.


Thank you very much for helping on this, Much Appreciated!

I would love to see improvements on the "Social Authentication" process, making the third party ID as primary identifier, instead of the email.


I hear you. I’ll talk to the team about how we can do better.


I work in the public service sector. When we're architecting OAuth2/OIDC integrations we specify using a unique identifier like a guid or some otherwise immutable id as the federation id. This way other attributes that may be ephemeral can change at will. It's not always easy determining this but it's worth it.


Just had a different primary email on my Github account, when I signed up for DO. By changing my primary email account on Github, I lost access to DO.


They did everything to confirm my Identity and prevent social engineering tactics which is exactly what I expected from the company.

But I feel like they don't have an internal process to solve this issue, I haven't anything back for the last 8 hours..


To be fair - for a standard account, not hearing back for 8 hours wouldn’t concern me too much


For sure the SLO for standard account is 24hrs.


I love Digital Ocean, don't get me wrong. Im just sharing the Bad experience with the "Social Authentication" flow and how long it is taking to solve a simple problem.

This also a heads up for anyone using GitHub as the authentication method.


It's definitely not a simple problem though. Anyone can claim they own your account. And it would be bone-headed to make the re-verification process easy.


Sure, but I did not change my Authentication Method. Im still using GitHub login. With the same Github ID...


And now the company admin, or if the domain for sale again, can take over his account


Not possible to gain access with 2 factor authentication. I used as my primary email to receive email notifications


That's extremely weird you can't use the same address for notifications and 2FA

But if that's the case, you shouldn't tie personal accounts to work stuff like this in the first place. Just make a second email address.

Sure it's convenient but then you dig yourself holes like this.



RingCentral Meetings still vulnerable:

lsof -i :19424

https://www.ringcentral.com/whyringcentral/company/pressrele...


For those unaware, RingCentral white-labels the zoom.us product as their meeting solution.


Ironically, RingCentral's convention schwag includes a stick-on laptop lens shutter.


I just got an update! Good job Jonathan Leitschuh!

Release notes of 4.4.53932.0709:

Remove local web server

-We are discontinuing the use of a local web server on Mac devices. Following the update, the local web server will be completely removed from the Zoom installation Option to uninstall Zoom

-Zoom users can now uninstall the Zoom desktop application and all of its components through the settings menu


RingCentral Meetings uses zoom.us engine but the local server runs on port 19424 instead. I'm able to replicate the issue on it.

PoC: http://localhost:19424/launch?action=join&confno=3535353535


I can confirm that this vulnerability exists in RingCentral for macOS, version 7.0.136380.0312.

I was taken into Miguel's meeting, but since the host wasn't presented, it simply let me know it was waiting for him (It also had a friendly notice "Your video will turn ON automatically when the meeting starts".

I've changed my settings in Video > Meetings, just like in Zoom, to turn off my vid when joining. Also confirmed that the server is running on port 19424 (via terminal command 'lsof -i :19424').


In my case it's 19421 as written in the article.


For RingCentral or Zoom? Could be because I have both on my machine.


Zoom


Yes, my comment was about RingCentral Meetings


Sorry, never heard of that, and since the rest of the story was so similar, it didn't really register in my brain as something entirely different.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: