Article may be outdated

This article is 68 days old. Some details may have changed since publication.

Hacker News·5 min read·hard

Show HN: Exploiting Slack's video embeds to achieve E2EE communication

V
victorio
AI Summary

A security researcher demonstrates a method to achieve end-to-end encrypted communication within Slack by exploiting the platform's video embed feature. The technique uses browser crypto APIs and the openpgpjs library to bypass standard server-side message visibility.

Why it matters

This highlights potential security vulnerabilities in enterprise communication platforms that allow arbitrary iframe embedding.

Dive DeeperCreate a free account to unlock

Some time ago, while exploring Slack’s Block Kit reference, I noticed something peculiar: the video block . When I saw that it accepted a video_url , the first thing I thought was: how does it distinguish between any content and an actual video? Would there be any particular requirement or limitation in the embed? Foreign sources?

Continue reading on Headlinne

Create a free account to read the full article.

Read full article →
technologycrypto
Political Bias
Center
LeftLean LCenterLean RRight
Confidence: 85%

Technical security analysis without political or social bias.

Get smarter about the news

Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.

Create free account

Already have an account? Sign in