Live data from Hacker News

Ask HN: If your company cares about security, why does it use Slack?

news.ycombinator.com

61–70 of 71 posts

Re: Ask HN: If your company cares about security, why does it use Slack?

#61
post #38

Earlier quoted context omitted.

OK: Slack is not currently a PCI-certified Service Provider. I was also a bit surprised what they consider out of scope for their bug bounty program: https://hackerone.com/slack

I can't begin to fathom a use case for slack where you would put card data in the system...

The use case is user error. I have also seen no shortage accidentally people paste passwords into Slack as well

Re: Ask HN: If your company cares about security, why does it use Slack?

#62

Earlier quoted context omitted.

You're kind of right. At the same time, the comments appear to be answering the question, so...

But, perhaps more relevant, the post doesn't say "flagged" on my end (which I'm pretty sure they do when they're flagged).

It has to be flagged enough to get that tag. As to 'commenters are commenting', that's not the criterion for what makes a good post. You're basically trying to stir up a silly fight. Sure, that gets upvotes and comments. It's still bad.

Re: Ask HN: If your company cares about security, why does it use Slack?

#63
post #62

Earlier quoted context omitted.

But, perhaps more relevant, the post doesn't say "flagged" on my end (which I'm pretty sure they do when they're flagged).

It has to be flagged enough to get that tag. As to 'commenters are commenting', that's not the criterion for what makes a good post. You're basically trying to stir up a silly fight. Sure, that gets upvotes and comments. It's still bad.

Hm, ok. Would it have been OK if I hadn't posted it under "Ask HN"? Surely this site supports sharing opinions like this one in some contexts -- it's not like this was a political shitpost or something. Right?

Re: Ask HN: If your company cares about security, why does it use Slack?

#64
Have you tried Semaphor from SpiderOak? We provide a secure Slack alternative designed using our No Knowledge architecture--meaning that we (SpiderOak) know nothing about the encrypted data you store on our servers. This approach allows a third party to host the data, making it way more convenient from an operations standpoint. Slack provides convenience, but it severely lacks in security.

Re: Ask HN: If your company cares about security, why does it use Slack?

#65

Earlier quoted context omitted.

A VPN resolves this issue and provides encryption and authentication.

A VPN is non-trivial to set up correctly. Have you set up an internal DNS to prevent leaking the domains from requests? How about IPv6 leaks? There are many things to consider, and I wouldn't trust a random programmer to do it correctly.

I wouldn't trust your programmer much at all if they couldn't configure OpenVPN with correct DNS settings, given some time.

Re: Ask HN: If your company cares about security, why does it use Slack?

#66
post #62

Earlier quoted context omitted.

It has to be flagged enough to get that tag. As to 'commenters are commenting', that's not the criterion for what makes a good post. You're basically trying to stir up a silly fight. Sure, that gets upvotes and comments. It's still bad.

Hm, ok. Would it have been OK if I hadn't posted it under "Ask HN"? Surely this site supports sharing opinions like this one in some contexts -- it's not like this was a political shitpost or something. Right?

Probably but the result would have likely been similar. The standard is supposed to be a bit higher than 'isn't a political shitpost'. If you have something interesting to say about this, you can always write it up as a blog post and submit that. If you just want to vent a bit, it's probably not going to get too far as a post.

Re: Ask HN: If your company cares about security, why does it use Slack?

#67

Earlier quoted context omitted.

HIPPA, PCI, etc. compliancy doesn't actually mean you are secure, it just means you are compliant. Take ransomware attacks for example, most of the bigger companies that get hit and have no working plan to continue their business are compliant to all sorts of things, hell complete governments are in that category... Compliancy only tells a story about management and how many MBA's you have, it doesn't actually mean y…

You're correct - it doesn't mean you're secure. It does, however, point out that you're putting some thought and effort into security. PCI requires remediation plans or justifications to pass, as does HIPPA. And, for better or worse, you need your service providers, including chat, to be compliant. If your company were to leak PII via Slack, your company would be in pretty hot water for putting PII on a non-certified…

In this case, however, Slack is certified.

Re: Ask HN: If your company cares about security, why does it use Slack?

#68

Earlier quoted context omitted.

A VPN is non-trivial to set up correctly. Have you set up an internal DNS to prevent leaking the domains from requests? How about IPv6 leaks? There are many things to consider, and I wouldn't trust a random programmer to do it correctly.

I wouldn't trust your programmer much at all if they couldn't configure OpenVPN with correct DNS settings, given some time.

Many good resources exist: https://www.linode.com/docs/networking/vpn/set-up-a-hardened...

Re: Ask HN: If your company cares about security, why does it use Slack?

#69
post #4

The usual answer is "the self-hosted options are worse to use and make people hate them". Mattermost is a prime example, it's really clunky and uncomfortable to use. I like Rocket Chat and have hosted an instance of it myself, but it's shot through with inconsistencies and annoyances that Slack just doesn't have. The notion that self-hosted is more secure is curious, though. Slack's security team is almost certainly…

Hi Eropple, Mattermost team here. Sorry to hear your Mattermost experience wasn't smooth. Could you share an example or two of what we can improve? We ship new releases every month on the 16th. If there's something you feel should be corrected I would love to see it addressed. There's over 500 contributors on the project and thousands of companies that deploy it.

In terms of security, I would propose that professionals dealing with sensitive data are often more comfortable with a self-hosted solution. As an example, former members of the CIA, FBI and NSA have used Mattermost on national television in the US: https://about.mattermost.com/open-source-mattermost-software...

Re: Ask HN: If your company cares about security, why does it use Slack?

#70
post #69
post #4

The usual answer is "the self-hosted options are worse to use and make people hate them". Mattermost is a prime example, it's really clunky and uncomfortable to use. I like Rocket Chat and have hosted an instance of it myself, but it's shot through with inconsistencies and annoyances that Slack just doesn't have. The notion that self-hosted is more secure is curious, though. Slack's security team is almost certainly…

Hi Eropple, Mattermost team here. Sorry to hear your Mattermost experience wasn't smooth. Could you share an example or two of what we can improve? We ship new releases every month on the 16th. If there's something you feel should be corrected I would love to see it addressed. There's over 500 contributors on the project and thousands of companies that deploy it. In terms of security, I would propose that professiona…

I'd be a lot more inclined to spend time responding to you, because I certainly have a list of beefs with the software, if you didn't immediately launch into pimping your stuff and trying to sneak in how wrong I am. That's "I choose to exhibit the social acuity of a space alien" behavior.
Post reply on HN