Live data from Hacker News

Ask HN: If your company cares about security, why does it use Slack?

news.ycombinator.com

11–20 of 71 posts

Re: Ask HN: If your company cares about security, why does it use Slack?

#11
post #3

Umm... why do people always assume "hosting it yourself" is more secure and not less? Do you have Slack's security expertise and budget? In my experience when small to mid-size companies attempt to manage security themselves they do a passable job but are convinced they are doing an excellent job - until they get hacked. Larger companies usually have the budget, tools and expertise. But even then there are lots big c…

I think both options have tradeoffs.

If you use a service, you're outsourcing your security to perhaps more competent people, but you're making yourself a larger target.

Self-hosting makes you a smaller target, but you're taking all the risk on yourself.

Neither is a panacea.

Re: Ask HN: If your company cares about security, why does it use Slack?

#12
post #3

Umm... why do people always assume "hosting it yourself" is more secure and not less? Do you have Slack's security expertise and budget? In my experience when small to mid-size companies attempt to manage security themselves they do a passable job but are convinced they are doing an excellent job - until they get hacked. Larger companies usually have the budget, tools and expertise. But even then there are lots big c…

Because when you host it yourself, it can be off of the public internet.

That's not very useful for your CEO/CTO/CFO/sales/etc when they are offsite or traveling.

Re: Ask HN: If your company cares about security, why does it use Slack?

#13
post #7
post #3

Umm... why do people always assume "hosting it yourself" is more secure and not less? Do you have Slack's security expertise and budget? In my experience when small to mid-size companies attempt to manage security themselves they do a passable job but are convinced they are doing an excellent job - until they get hacked. Larger companies usually have the budget, tools and expertise. But even then there are lots big c…

Corollary question: Why do you assume that Slack's security expertise and security budget is greater than your own? All we can do is assume that Slack cares about security enough to be sufficient. Last I checked, they didn't have any form of compliance certification, yet HIPPA, PCI, etc. compliant clients use them without reservation.

You should look again:

https://slack.com/security

Re: Ask HN: If your company cares about security, why does it use Slack?

#14
A selection of reasons I have heard.

- Because self hosted HipChat / IRC / XMPP / is not cool enough.

- Because we are all supposed to use Lync / Skype for Business, but it sucks on OSX / Linux / in general.

- Because we are a small team, and maintaining a chat server is too much for us.

- Because we don't know (or want to know) how Slack works.

- Because shiney, such giffy, such memes.

- Because its free.

- Because my software engineers don't know how to connect to IRC

There is varying levels of good and bad reasons in there. (personally I am still a irrsi / IRC person, but I fully acknowledge I am not in the majority anymore)

Re: Ask HN: If your company cares about security, why does it use Slack?

#17
post #3

Umm... why do people always assume "hosting it yourself" is more secure and not less? Do you have Slack's security expertise and budget? In my experience when small to mid-size companies attempt to manage security themselves they do a passable job but are convinced they are doing an excellent job - until they get hacked. Larger companies usually have the budget, tools and expertise. But even then there are lots big c…

Because when you host it yourself, it can be off of the public internet.

and what about if your network is compromised? For most small-medium businesses, that's more likely than Slack being compromised.

Re: Ask HN: If your company cares about security, why does it use Slack?

#18
>> It's just a matter of time before there's a huge incident.

I suppose that's correct. When (or maybe if, but probably when) Slack gets breached/hacked/owned it's going to be huge because a huge number of people are going to lose something that they didn't want to lose.

When I'm self hosting something and that thing gets breached/hacked/owned it's going to be huge for me because I and/or my company are going to lose something that we didn't want to lose.

I don't believe I can keep my stuff much safer than the big guys, though the point about Slack having a massive target is a good one. Maybe that makes it less secure?

I really don't know what's better for us in the case.

Re: Ask HN: If your company cares about security, why does it use Slack?

#20
post #7
post #3

Umm... why do people always assume "hosting it yourself" is more secure and not less? Do you have Slack's security expertise and budget? In my experience when small to mid-size companies attempt to manage security themselves they do a passable job but are convinced they are doing an excellent job - until they get hacked. Larger companies usually have the budget, tools and expertise. But even then there are lots big c…

Corollary question: Why do you assume that Slack's security expertise and security budget is greater than your own? All we can do is assume that Slack cares about security enough to be sufficient. Last I checked, they didn't have any form of compliance certification, yet HIPPA, PCI, etc. compliant clients use them without reservation.

HIPPA, PCI, etc. compliancy doesn't actually mean you are secure, it just means you are compliant. Take ransomware attacks for example, most of the bigger companies that get hit and have no working plan to continue their business are compliant to all sorts of things, hell complete governments are in that category...

Compliancy only tells a story about management and how many MBA's you have, it doesn't actually mean you have good security. Only being compliant isn't going to help you not get data leaks or data loss!

Post reply on HN