A security review before the next customer
We ran a full security review of Stage 1, attacked it the way an outsider would, and closed what we found the same day.
· 2 min read
Stage 1 sends messages from your LinkedIn and your mailbox. That's a lot of trust to hand a piece of software. So before the next firm connects, we went looking for the ways someone could abuse it.
We read every route, then ran the app and attacked it. Could one customer see another's accounts? Could someone become an admin by signing up with the right address? Could a planted link run code in your browser? Could a page Stage 1 reads send it somewhere it shouldn't go?
The foundations held. Every account, person and message stays inside its own workspace. Passwords are hashed with scrypt. Connection keys are encrypted at rest. Every query uses bound parameters. Nothing goes to a prospect until a person approves it.
We found gaps around the edges, and we closed every serious one the same day. Admin rights now need a confirmed email. A workspace can only use the LinkedIn and email accounts it connected itself. Signing in with Google takes over an unconfirmed account cleanly, with the old password gone. Pages Stage 1 reads get checked at every redirect. Imported links have to be real web links. A follow-up written at send time waits for your approval like any other message.
Each fix ships with a test that tries the attack again on every build.
Security isn't a page on the website. It's the review you run before you need it, and again after every change that matters.