Live data from Hacker News

Ask HN: If your company cares about security, why does it use Slack?

news.ycombinator.com

41–50 of 71 posts

Re: Ask HN: If your company cares about security, why does it use Slack?

#41
post #31

TLDR we chose Mattermost over Slack because of security. https://www.mattermost.com We recently evaluated many chat systems for a large tech consulting project that includes security needs. Slack was the frontrunner because of ubiquity, ease of use, plentiful third-party integrations, openness to free areas, and helpful in-person meetings with the Slack staff. We picked Slack for our informal connections with externa…

Perhaps this is a bit immature of me, but I despise Ryver for their ads that they put on Twitter a few months (a year?) back where it was completely trying to discredit Slack while having a sub-par UIX itself. Maybe I'll give it another look in the near future.

EDIT: Security-wise, I would think Slack, as a bigger company, would have better security, but that's all assumption. Do you have anything to back up the idea that Ryver is more secure? If so Ill definitely give it another look.

Re: Ask HN: If your company cares about security, why does it use Slack?

#42
Because they care about convenience as well, and that value outshines the elusive "lack of security". You'll probably end up with much less secure option if you try to host one yourself, unless you're really dedicated to the chat app, in which case you have your priorities wrong. You should be focused on your own product.

Re: Ask HN: If your company cares about security, why does it use Slack?

#43
post #26
post #22

Earlier quoted context omitted.

> Why do you assume that Slack's security expertise and security budget is greater than your own? I don't assume it. I know it for a fact; I've met some of their team and I know others by reputation. And I'm not exactly a slouch when it comes to this stuff (I don't eat and sleep crypto but a large part of my business is building secure infrastructure/consulting on the systems running on that infrastructure for regula…

Slack has, publicly, a multi-member security team! That's entirely focused on the chat system that I don't have to put any of my teams time towards.

I'm curious...

Which is more secure?

A) Slack.

B) Open source software on a LAN accessible only through physical entry, SSH, and/or a VPN.

Re: Ask HN: If your company cares about security, why does it use Slack?

#44
post #38

Earlier quoted context omitted.

OK: Slack is not currently a PCI-certified Service Provider. I was also a bit surprised what they consider out of scope for their bug bounty program: https://hackerone.com/slack

I can't begin to fathom a use case for slack where you would put card data in the system...

How about a bug report screen shot? Lots of non-security conscious users don't understand why this could be bad. It's your (making the assumption that "you" in this case is a Slack Administrator) job to protect them from themselves.

Re: Ask HN: If your company cares about security, why does it use Slack?

#45
post #17

Earlier quoted context omitted.

and what about if your network is compromised? For most small-medium businesses, that's more likely than Slack being compromised.

Slack already had a public compromise. Most small businesses haven't been publicly compromised. I'm not saying it's safer to self-host. There are a ton of foot-guns with operating your own IRC server.

That said, you bypass a ton of those foot-guns if you just stick everything behind a corporate VPN with 2FA and the appropriate security. As long as the VPN is secure, everything behind it is secure.

Re: Ask HN: If your company cares about security, why does it use Slack?

#46
post #17

Earlier quoted context omitted.

Because when you host it yourself, it can be off of the public internet.

and what about if your network is compromised? For most small-medium businesses, that's more likely than Slack being compromised.

> and what about if your network is compromised? For most small-medium businesses, that's more likely than Slack being compromised.

If your network and/or workstations are compromised, it is _over anyway_ because they have all your data. This is one of those situations where you are saying "What if they decapitated me? Slack might still be secure."

I mean, technically, you are correct but it isn't relevant because you are dead.

If you think such a business can survive a pentest from an employee workstation...XD

Re: Ask HN: If your company cares about security, why does it use Slack?

#47
post #12

Earlier quoted context omitted.

That's not very useful for your CEO/CTO/CFO/sales/etc when they are offsite or traveling.

A VPN resolves this issue and provides encryption and authentication.

A VPN is non-trivial to set up correctly. Have you set up an internal DNS to prevent leaking the domains from requests? How about IPv6 leaks? There are many things to consider, and I wouldn't trust a random programmer to do it correctly.

Re: Ask HN: If your company cares about security, why does it use Slack?

#48
post #26

Earlier quoted context omitted.

Slack has, publicly, a multi-member security team! That's entirely focused on the chat system that I don't have to put any of my teams time towards.

I'm curious... Which is more secure? A) Slack. B) Open source software on a LAN accessible only through physical entry, SSH, and/or a VPN.

I'd vote slack.

Re: Ask HN: If your company cares about security, why does it use Slack?

#49
post #38

Earlier quoted context omitted.

OK: Slack is not currently a PCI-certified Service Provider. I was also a bit surprised what they consider out of scope for their bug bounty program: https://hackerone.com/slack

I can't begin to fathom a use case for slack where you would put card data in the system...

You've never met a call center.

They've sent bug reports with credit card data they've typed in during a phone call through a variety of insecure methods.

They've also written people's credit card info on sticky notes.

Trust me, the horror that is card data and a call center is scary.

Re: Ask HN: If your company cares about security, why does it use Slack?

#50
It's not just the setup of a self-hosted solution, but maintenance, and otherwise. If you look at the enterprise space, bigger and bigger companies are becoming comfortable with cloud-hosting of services. Growth of companies like Okta demonstrate that shift. As far as it being acceptable, I think there are a few things to consider:

1. The Slack model is such that your staff could start using it without even getting permission from the top. This is the Slack strategy for sales. It comes into companies from the bottom, so companies are more responding to the fact that their employees are using it vs bringing it in from the top.

2. Yes there are risks with cloud products, but risk is a cost consideration so you look at cost impact to the company of a breach and you compare that to a self-hosted high maintenance solution. This is a much more difficult calculation and it really depends on the size of your company, the value of the information Slack will be holding, etc. It's also possible Slack could be seen as more secure because an internal system breach may not include a complete Slack hosted breach. It could be seen as data segregation and diversification.

3. Slack is not the only company that is making inroads here. Slack is known well in the tech industry, but less-so in other industries. Microsoft is a giant because Skype for Business is huge, and there's many others.

Post reply on HN