"Internally Public" setting?

Jordan's Avatar

Jordan

10 Nov, 2011 01:47 PM via web

We would really like to have a "internally public" setting for rooms, does this exist? We want anyone that's a member in our chat to be able to join a particular room at will without leaving it wide open to the public internet. Does that feature exist?

  1. Support Staff 2 Posted by Nick on 20 Nov, 2011 09:52 AM

    Nick's Avatar

    Do you really have a problem with people joining your rooms from internet? We will think about this but I don't see this as a major flaw at the moment.

  2. Nick closed this discussion on 20 Nov, 2011 09:52 AM.

  3. Jordan re-opened this discussion on 21 Nov, 2011 03:30 PM

  4. 3 Posted by Jordan on 21 Nov, 2011 03:30 PM

    Jordan's Avatar

    It's a pretty easy hack to script isn't it? Guess some *.jaconda.im domains and guess some chat room names and you're in.

    Use a fairly common name and you may not be noticed, or even do some social engineering on the company and find out what the CEO's name is and use that.

    Related question: Is our domain's list of public rooms published anywhere that an attacker could query?

  5. 4 Posted by Dan DeMaggio on 21 Nov, 2011 07:40 PM

    Dan DeMaggio's Avatar

    Do you really have a problem with people joining your rooms from internet?

    Yes. We'd like to talk about internal company projects without worrying about interlopers. I see two options:

    1) Since a room name is it's password, we could create hard-to-guess room names.

    2) Jaconda could support private, but company-wide chat rooms.

    If we go with option 1, we'd want assurances that Jaconda won't make a "List all Public Chat Rooms" API, where people could discover our room.

  6. Support Staff 5 Posted by Nick on 10 Dec, 2011 01:35 PM

    Nick's Avatar

    Hi,

    Sorry for delay, couldn't answer earlier. We will consider this but most likely not before the new year at the earliest.

    No we don't publish rooms or anything anywhere. You might access to them through the API, but to gain access to the API token you got to be the domain owner.

  7. 6 Posted by Peter Baker on 14 Jan, 2012 04:25 PM

    Peter Baker's Avatar

    Would love to see this as well. It would be great to have the option to invite outsiders only if we send them a 'secure' invite code (and of course we can kick them out).

Reply to this discussion

Internal reply

Formatting help or Preview

Attached Files

You can attach files up to 10MB

How many minutes are in an hour?

If you don't have an account yet, we need to confirm you're human and not a machine trying to post spam.