<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Workato Recipe Sharing Security in Workato Pros Discussion Board</title>
    <link>https://systematic.workato.com/t5/workato-pros-discussion-board/workato-recipe-sharing-security/m-p/799#M388</link>
    <description>&lt;P&gt;Hi Gordon, thanks for the feedback. It makes sense to have some type of expiration or control the sharing. We have Okta like disabling of sharing to community in &lt;EM&gt;Account Settings &amp;gt; Recipe preferences &amp;gt; Allow recipes to be listed on community&lt;/EM&gt;. &lt;/P&gt;&lt;BR /&gt;&lt;P&gt;Similar global setting can be made available for recipe private sharing so admin can disable sharing if needed. Although it will apply globally to all recipes. Let me take this feedback and discuss it internally and see what we can do here.&lt;/P&gt;</description>
    <pubDate>Sun, 18 Apr 2021 11:08:39 GMT</pubDate>
    <dc:creator>deven-maru</dc:creator>
    <dc:date>2021-04-18T11:08:39Z</dc:date>
    <item>
      <title>Workato Recipe Sharing Security</title>
      <link>https://systematic.workato.com/t5/workato-pros-discussion-board/workato-recipe-sharing-security/m-p/798#M387</link>
      <description>&lt;P&gt;This is more for workato team. I know we can set up permission so that a recipe is not by default available in the community.&lt;BR /&gt;&lt;BR /&gt;Each recipe by default comes with a sharing URL, which is useful for sharing and for support.&lt;BR /&gt;&lt;BR /&gt;However the URL is open (if you have it), and the string after “st” is not very long. So...I am wondering if there could be some malicious users harvesting the recipes by trying random recipe numeric number and the token.&lt;BR /&gt;&lt;BR /&gt;I know the chance of getting a hit may be low but ... you never know. Can’t underestimate the super computer’s power &lt;span class="lia-unicode-emoji" title=":grinning_face_with_sweat:"&gt;😅&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;I am wondering if this is on workato’s radar? I can see a few options:&lt;BR /&gt;&lt;BR /&gt;Box’s approach:&lt;BR /&gt;1. Set up policy to auto expire share links after x days&lt;BR /&gt;&lt;BR /&gt;2. Allow token regeneration ad-hoc&lt;BR /&gt;&lt;BR /&gt;3. Allow manually extending the sharing period&lt;BR /&gt;&lt;BR /&gt;Okta’s approaxh: disable sharing altogether and when workato support needs to get in, grant just in time access globally, or only to the recipe.&lt;BR /&gt;&lt;BR /&gt;Thoughts?&lt;/P&gt;</description>
      <pubDate>Sat, 17 Apr 2021 13:57:41 GMT</pubDate>
      <guid>https://systematic.workato.com/t5/workato-pros-discussion-board/workato-recipe-sharing-security/m-p/798#M387</guid>
      <dc:creator>gordonhuworkato</dc:creator>
      <dc:date>2021-04-17T13:57:41Z</dc:date>
    </item>
    <item>
      <title>Re: Workato Recipe Sharing Security</title>
      <link>https://systematic.workato.com/t5/workato-pros-discussion-board/workato-recipe-sharing-security/m-p/799#M388</link>
      <description>&lt;P&gt;Hi Gordon, thanks for the feedback. It makes sense to have some type of expiration or control the sharing. We have Okta like disabling of sharing to community in &lt;EM&gt;Account Settings &amp;gt; Recipe preferences &amp;gt; Allow recipes to be listed on community&lt;/EM&gt;. &lt;/P&gt;&lt;BR /&gt;&lt;P&gt;Similar global setting can be made available for recipe private sharing so admin can disable sharing if needed. Although it will apply globally to all recipes. Let me take this feedback and discuss it internally and see what we can do here.&lt;/P&gt;</description>
      <pubDate>Sun, 18 Apr 2021 11:08:39 GMT</pubDate>
      <guid>https://systematic.workato.com/t5/workato-pros-discussion-board/workato-recipe-sharing-security/m-p/799#M388</guid>
      <dc:creator>deven-maru</dc:creator>
      <dc:date>2021-04-18T11:08:39Z</dc:date>
    </item>
    <item>
      <title>Re: Workato Recipe Sharing Security</title>
      <link>https://systematic.workato.com/t5/workato-pros-discussion-board/workato-recipe-sharing-security/m-p/800#M389</link>
      <description>&lt;P&gt;Can you tell me more how this concern around recipe sharing came about? &lt;/P&gt;</description>
      <pubDate>Sun, 18 Apr 2021 11:11:03 GMT</pubDate>
      <guid>https://systematic.workato.com/t5/workato-pros-discussion-board/workato-recipe-sharing-security/m-p/800#M389</guid>
      <dc:creator>deven-maru</dc:creator>
      <dc:date>2021-04-18T11:11:03Z</dc:date>
    </item>
    <item>
      <title>Re: Workato Recipe Sharing Security</title>
      <link>https://systematic.workato.com/t5/workato-pros-discussion-board/workato-recipe-sharing-security/m-p/801#M390</link>
      <description>&lt;P&gt;I know sometimes a recipe might contain sensitive info, such as username, user ID, PII, or worse....keys.&lt;BR /&gt;&lt;BR /&gt;If I am an attacker, I will try a combo to see if I can get in a recipe and harvest useful info.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 18 Apr 2021 11:45:33 GMT</pubDate>
      <guid>https://systematic.workato.com/t5/workato-pros-discussion-board/workato-recipe-sharing-security/m-p/801#M390</guid>
      <dc:creator>gordonhuworkato</dc:creator>
      <dc:date>2021-04-18T11:45:33Z</dc:date>
    </item>
    <item>
      <title>Re: Workato Recipe Sharing Security</title>
      <link>https://systematic.workato.com/t5/workato-pros-discussion-board/workato-recipe-sharing-security/m-p/802#M391</link>
      <description>&lt;P&gt;FYI I am referring to the “sharing” that is using the token. The type that workato support uses to have access to the recipe. I am not sure if that token is refreshed periodically. But I have a feeling not - because we have to put that URL in the case. If it expires, the support loses access. &lt;/P&gt;</description>
      <pubDate>Sun, 18 Apr 2021 12:49:23 GMT</pubDate>
      <guid>https://systematic.workato.com/t5/workato-pros-discussion-board/workato-recipe-sharing-security/m-p/802#M391</guid>
      <dc:creator>gordonhuworkato</dc:creator>
      <dc:date>2021-04-18T12:49:23Z</dc:date>
    </item>
    <item>
      <title>Re: Workato Recipe Sharing Security</title>
      <link>https://systematic.workato.com/t5/workato-pros-discussion-board/workato-recipe-sharing-security/m-p/803#M392</link>
      <description>&lt;DIV dir="ltr"&gt;&lt;DIV dir="ltr"&gt;&lt;DIV class="gmail_default"&gt;Thanks Gordon. Yes, it needs to balance the need for security as well as the ease of sharing with support or other stakeholders. &lt;BR /&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Mon, 19 Apr 2021 02:48:39 GMT</pubDate>
      <guid>https://systematic.workato.com/t5/workato-pros-discussion-board/workato-recipe-sharing-security/m-p/803#M392</guid>
      <dc:creator>deven-maru</dc:creator>
      <dc:date>2021-04-19T02:48:39Z</dc:date>
    </item>
  </channel>
</rss>

