Earlier quoted context omitted.
OK: Slack is not currently a PCI-certified Service Provider. I was also a bit surprised what they consider out of scope for their bug bounty program: https://hackerone.com/slack
I can't begin to fathom a use case for slack where you would put card data in the system...
Ask HN: If your company cares about security, why does it use Slack?
61–70 of 71 posts
Re: Ask HN: If your company cares about security, why does it use Slack?
#62Earlier quoted context omitted.
You're kind of right. At the same time, the comments appear to be answering the question, so...
But, perhaps more relevant, the post doesn't say "flagged" on my end (which I'm pretty sure they do when they're flagged).
Re: Ask HN: If your company cares about security, why does it use Slack?
#63Earlier quoted context omitted.
But, perhaps more relevant, the post doesn't say "flagged" on my end (which I'm pretty sure they do when they're flagged).
It has to be flagged enough to get that tag. As to 'commenters are commenting', that's not the criterion for what makes a good post. You're basically trying to stir up a silly fight. Sure, that gets upvotes and comments. It's still bad.
Re: Ask HN: If your company cares about security, why does it use Slack?
#64Re: Ask HN: If your company cares about security, why does it use Slack?
#65Earlier quoted context omitted.
A VPN resolves this issue and provides encryption and authentication.
A VPN is non-trivial to set up correctly. Have you set up an internal DNS to prevent leaking the domains from requests? How about IPv6 leaks? There are many things to consider, and I wouldn't trust a random programmer to do it correctly.
Re: Ask HN: If your company cares about security, why does it use Slack?
#66Earlier quoted context omitted.
It has to be flagged enough to get that tag. As to 'commenters are commenting', that's not the criterion for what makes a good post. You're basically trying to stir up a silly fight. Sure, that gets upvotes and comments. It's still bad.
Hm, ok. Would it have been OK if I hadn't posted it under "Ask HN"? Surely this site supports sharing opinions like this one in some contexts -- it's not like this was a political shitpost or something. Right?
Re: Ask HN: If your company cares about security, why does it use Slack?
#67Earlier quoted context omitted.
HIPPA, PCI, etc. compliancy doesn't actually mean you are secure, it just means you are compliant. Take ransomware attacks for example, most of the bigger companies that get hit and have no working plan to continue their business are compliant to all sorts of things, hell complete governments are in that category... Compliancy only tells a story about management and how many MBA's you have, it doesn't actually mean y…
You're correct - it doesn't mean you're secure. It does, however, point out that you're putting some thought and effort into security. PCI requires remediation plans or justifications to pass, as does HIPPA. And, for better or worse, you need your service providers, including chat, to be compliant. If your company were to leak PII via Slack, your company would be in pretty hot water for putting PII on a non-certified…
Re: Ask HN: If your company cares about security, why does it use Slack?
#68Earlier quoted context omitted.
A VPN is non-trivial to set up correctly. Have you set up an internal DNS to prevent leaking the domains from requests? How about IPv6 leaks? There are many things to consider, and I wouldn't trust a random programmer to do it correctly.
I wouldn't trust your programmer much at all if they couldn't configure OpenVPN with correct DNS settings, given some time.
Re: Ask HN: If your company cares about security, why does it use Slack?
#69The usual answer is "the self-hosted options are worse to use and make people hate them". Mattermost is a prime example, it's really clunky and uncomfortable to use. I like Rocket Chat and have hosted an instance of it myself, but it's shot through with inconsistencies and annoyances that Slack just doesn't have. The notion that self-hosted is more secure is curious, though. Slack's security team is almost certainly…
In terms of security, I would propose that professionals dealing with sensitive data are often more comfortable with a self-hosted solution. As an example, former members of the CIA, FBI and NSA have used Mattermost on national television in the US: https://about.mattermost.com/open-source-mattermost-software...
Re: Ask HN: If your company cares about security, why does it use Slack?
#70The usual answer is "the self-hosted options are worse to use and make people hate them". Mattermost is a prime example, it's really clunky and uncomfortable to use. I like Rocket Chat and have hosted an instance of it myself, but it's shot through with inconsistencies and annoyances that Slack just doesn't have. The notion that self-hosted is more secure is curious, though. Slack's security team is almost certainly…
Hi Eropple, Mattermost team here. Sorry to hear your Mattermost experience wasn't smooth. Could you share an example or two of what we can improve? We ship new releases every month on the 16th. If there's something you feel should be corrected I would love to see it addressed. There's over 500 contributors on the project and thousands of companies that deploy it. In terms of security, I would propose that professiona…