Freshdesk Security Issue: What are they hiding?
We use Freshdesk at my company for customer support. One of their features that we use, allows us to setup a custom single sign on page for our users, so that they can sign in to the app with their exsting company credentials instead of creating new ones with Freshdesk.Earlier this week, we received an email from their security team asking us to change our implementation of single sign on for security reasons.Full first email here: http://pastebin.com/5Lx6nB6yThe email said that I have to do it before Thursday (2 days from receiving the email) which looked like a very short period. I was worried and replied to them asking what was going on and what I needed to do specifically. They told me to change the order of the SSO attributes from (name, email, secret key and timestamp) to (name, secret key, email, timestamp). The earlier method apparently allows a vulnerability and the new one would make single sign on more secure.Full reply here: http://pastebin.com/Bjgb3ffWSo I went ahead and t