Skip to main content
gunjanm
Expert ⭐️
June 14, 2023
Released

Sally Security Concerns - PSA

Related products:CS Other Features
  • June 14, 2023
  • 37 replies
  • 1023 views

Although I don’t agree that this should be an “Idea”, I was told to come over here by Support. I expect to hear from Gainsight security team about this. 

Given Gainsight Sally can be added to any Slack channel, we did some testing with our Slack Connect channel with Myranda, our Enterprise Support Analyst at Gainsight. We added Gainsight Sally to our channel, triggered a simple C360 Summary query, and asked whether Myranda can see the information - she can.

All of it.

In fact, she can see the other prompts but upon attempting to interact with it, she is thrown with an error as she is not a provisioned user. It even cleared out the original output when she interacted with a query with no threaded further information.

It seems that no matter what I query, Myranda as an external user to Slack, can see the information.

We need to be able to secure who can add Sally to which channel, as we have plenty of customer channels that users (CSMs) could easily provide extremely sensitive information to.

Should this be a reason for us to back out on Sally altogether, when we are planning to launch this to all employees in a month? The hype that we have created for Gainsight with Sally could easily kill our ability to use Gainsight altogether because of this massive security issue.

37 replies

gunjanm
gunjanmAuthor
Expert ⭐️
June 15, 2023

@arunabhat @Ajay Agrawal so it is working as designed. I understand there can be other priorities. Noting @bradley’s comment about this being a potential liability for Gainsight exposing the data, I am very surprised this is not being picked up faster. 

Is there not anything you can do to change the functionality to fundamentally NOT show the data at all, or restrict app responses to DMs only, no channels? Can we crowdsource ideas from the admin community to help rectify this sooner than later? We all want to work with you to figure out a solution because any companies using Sally effectively are getting value out of it, and it is heartbreaking to have to remove it. 

At this point, we have to make the decision to completely halt all usage of Sally. This is totally against the strategy and purchase decision altogether. Any other admin reading about this has an ethical obligation to report this to their security teams if they use Slack Connect channels with customers or external parties. How is this not a bigger priority automatically? Especially with the recent announcements of Sally for All...it is truly ALL. 

To be clear - we are also accordingly taking action to review any other Slack apps now to see how they may function. But this surfaced due to Gainsight Sally, and so you guys are hearing the most about it so far. 

Gunjan
john_apple
Expert ⭐️
June 15, 2023

Does Slack provide a control over 3rd party apps and Slack Connect? We don’t use Slack Connect but as an admin, I would like to have control over whether the app is added to a channel.

Gainsight Employee ⭐️
June 15, 2023

Hi Gunjan,

If it helps can we get into a call to discuss on this and conclude if it make sense please do invite your security team to the call so that we can cover the point in holistic way.

gunjanm
gunjanmAuthor
Expert ⭐️
June 16, 2023

Does Slack provide a control over 3rd party apps and Slack Connect? We don’t use Slack Connect but as an admin, I would like to have control over whether the app is added to a channel.

According to our IT team's chat with Slack, they do not, and are pointing back at the third party aka Gainsight here. We also tested the Salesforce app and found that they go through a pop-up instead, which shows the information strictly to the querying user, then gives them a prompt asking whether they want to share the info. If they click share, it will give them yet another prompt to ask which channel they want to share it in. Even that much would be much more secure IMO. 

Gunjan
gunjanm
gunjanmAuthor
Expert ⭐️
June 16, 2023

Hi Gunjan,

If it helps can we get into a call to discuss on this and conclude if it make sense please do invite your security team to the call so that we can cover the point in holistic way.

Ajay, please email me on this. We are meeting with the security team on Tuesday as it is a long weekend in the US and will be discussing next steps and options accordingly. Thanks. 

Gunjan
Gainsight Employee ⭐️
June 16, 2023

Hi Gunjan

 

I have sent an email, let us connect and take this discussion forward on email/call. 

gunjanm
gunjanmAuthor
Expert ⭐️
June 16, 2023

I tested this with Salesforce’s Slack app. They have two security tactics in play: one method of querying strictly sets it as "only visible to you" with an optional button that says "post to channel". 

The other method provides the information in that Slack popup style with a big green "Share" button that further puts you through a secondary validation of which channel you want to post to - and get this: external channels do not appear in this list. I can type one out and it will not be an option.

I am meeting further with Gainsight on this today, thanks, Ajay. 

Gunjan
darkknight
Expert ⭐️
June 16, 2023

How is this an idea/enhancement request?! It’s a security hole!

Jeff Kirkpatrick
manu_mittal
Gainsight Employee ⭐️
Gainsight Employee ⭐️
June 20, 2023

We are looking into this on priority. Sally was built prior to Slack Connect, so we have to revisit some of our original assumptions. 

gunjanm
gunjanmAuthor
Expert ⭐️
June 20, 2023

We are looking into this on priority. Sally was built prior to Slack Connect, so we have to revisit some of our original assumptions. 

Agreed, Manu - and might I add one thing: as different elements of the platform are built on other platforms, your PD owes it to your customers to have a vested interest in re-validating these builds and assumptions proactively.

Gunjan