News: Articles for Jul 2019

  • 2019/07/26

    Member users were able to retrieve Channel secret because of a bug (resolved)

    We discovered and fixed a bug in the LINE Developers console that allowed Member users to obtain a channel secret. We sincerely apologize for any inconvenience caused.

    On July 24, 2019, we emailed this information to all administrators of channels with Member users.

    Issue time

    Issue inception: September 21, 2017

    Issue solved: July 17, 2019

    Details

    There was a bug that allowed Member users to obtain the channel secret, which should have appeared only to Admin users.

    The Channel settings tab did not display the channel secret when a Member user viewed the page. However, the API that the LINE Developers console called in the background did return the channel secret. Therefore, a malicious Member user could have obtained and abused the channel secret.

    tip What is a channel secret?

    The channel secret is a secret key provided by LINE to call our APIs and validate identities. It should be kept secret from unauthorized parties.

    tip Member user permissions

    Originally, Member users can only view basic information and statistics for a channel. They don't have access to the channel secret.

    What you should do

    If you're concerned that unauthorized Member users have obtained your channel secret, you should issue a new one. Doing so will invalidate the previous channel secret.

    After you issue a new channel secret, you'll have to update it in the app which uses the channel secret. Carefully consider the impact of issuing a new channel secret on your app.

    How to issue a new channel secret

    You can issue a new channel secret on the Channel settings tab in the LINE Developers console.

    tip Forced reissue of channel secret

    LINE will not forcibly reissue new channel secrets. The Admin user for each channel should decide whether it's necessary to reissue a new channel secret.

    Acknowledgement

    This bug was reported through the LINE Security Bug Bounty Program.

    LINE will continue to improve the quality of its services to prevent future outages. Thank you for your understanding.

  • 2019/07/18

    Notice about service outage for LINE Login (resolved)

    We want to inform you about a service outage regarding LINE Login. The issue has now been resolved. We apologize for any inconvenience this may have caused.

    Date and time of outage

    Date: July 18, 2019 Time: 9:38–10:40 JST (GMT+9)

    Cause

    Issue with our servers.

    Details

    LINE Login returned http error codes with the pattern 5xx (500, 501, etc.) for some requests. As a result, LINE Login was unavailable in the following applications:

    • Web application
    • Desktop app

    LINE will continue to improve the quality of its services to prevent future outages. Thank you for your understanding.

  • 2019/07/08

    New Messaging API endpoints for friend statistics

    We're happy to announce that we've added 3 new Messaging API endpoints that enable you to get detailed information about the friends of your LINE official account:

    The data returned by these endpoints is the same data displayed on the Insight tab in the LINE Official Account Manager.