Live data from Hacker News

Please don't use Slack for FOSS projects

drewdevault.com

311–320 of 499 posts

Re: Please don't use Slack for FOSS projects

#312

Earlier quoted context omitted.

Your company puts private information on a server that has a 6667/tcp sitting out on the Internet? I'm guessing it does not, and setting this server up was considerably more irritating than just spawning off another t1.micro and apt installing IRC onto it.

So put in an iptables rule that restricts it to their network and make people remote in to use their client. Done and done.

iptables rules are not magic security talismans.

Re: Please don't use Slack for FOSS projects

#314
post #73

Please for the love of god just don't use Slack. We have learned absolutely nothing. Let's all jump on the bandwagon of another closed-source, proprietary, walled-garden service and hand over all of our private intra-company communications to a private third-party in another country. GREAT IDEA.

I don't know how "proprietary" or "walled-garden" it is, but I can connect to slack using open-source "irssi" on linux. http://www.tricksofthetrades.net/2015/09/10/slack-irssi-conn... I feel like that has to diminish the walled-garden, proprietary weight at least a little bit if slack & irssi can communicate. And it works over SSL too. Once I started doing that, I didn't mind using slack. You have to "/ignore" certai…

Slack may have a working IRC bridge, but it still has a closed-source server. You're still trusting a third-party with all your data.

Re: Please don't use Slack for FOSS projects

#315
I run a large FOSS project; we use both Slack and IRC. Working with maintainers in 3 or 4 different timezones you can’t afford to lose your IRC session if you don’t want to miss messages. As pointed in the article however Slack is for teams, not communities. We use IRC for open discussions and keep internal discussions on Slack.

Re: Please don't use Slack for FOSS projects

#316

Please for the love of god just don't use Slack. We have learned absolutely nothing. Let's all jump on the bandwagon of another closed-source, proprietary, walled-garden service and hand over all of our private intra-company communications to a private third-party in another country. GREAT IDEA.

> We have learned absolutely nothing. Let's all jump on the bandwagon of another closed-source, proprietary, walled-garden service and hand over all of our private intra-company communications to a private third-party in another country. GREAT IDEA. So don't use AWS or Google App Engine or Heroku? etc. Why? I use Facebook for a lot of my communications. Seems to be working out OK so far. Use the tools that help you g…

> So don't use AWS or Google App Engine or Heroku? etc. Why?

Leaving aside that there are extremely valid reasons not to use those services, communication is a huge deal. Can you imagine if email was a walled garden?

Re: Please don't use Slack for FOSS projects

#317
post #273

Earlier quoted context omitted.

> In many cases, things are popular because they are better/easier for a given audience. Which is the horse and which is the cart? Slack is easy because it got resources to be easy. Those same resource could have invested time to make IRC just as easy. There is no inherent reason why IRC cannot be just as simple. The reason slack is popular is because it got pushed hard and lots of money went into making it easy and…

This is like saying Apple products are popular because Apple has a great marketing team, as opposed to because said products are genuinely easier to use (they "just work") than their alternatives.

Can't tell if this is sarcasm or not...

Re: Please don't use Slack for FOSS projects

#318

Earlier quoted context omitted.

So put in an iptables rule that restricts it to their network and make people remote in to use their client. Done and done.

iptables rules are not magic security talismans.

True, but for this case it's more than adequate. An attacker would need to be able to tunnel through your companies network, and then what? Assuming they're that far, who cares if they can read what you talk about on IRC?

And even then, they'd further need to exploit some vulnerability in your IRC server to do it unnoticed.

Re: Please don't use Slack for FOSS projects

#319
post #273

Earlier quoted context omitted.

> In many cases, things are popular because they are better/easier for a given audience. Which is the horse and which is the cart? Slack is easy because it got resources to be easy. Those same resource could have invested time to make IRC just as easy. There is no inherent reason why IRC cannot be just as simple. The reason slack is popular is because it got pushed hard and lots of money went into making it easy and…

This is like saying Apple products are popular because Apple has a great marketing team, as opposed to because said products are genuinely easier to use (they "just work") than their alternatives.

But that is why Apple is so popular. They are a marketing monster! They sell a "lifestyle" and they do it extremely well. They tell you to "Think Different" (as long as it means buying an apple product). They tell you one button is easy and the best. They tell people what to think and (some) people think that.

Re: Please don't use Slack for FOSS projects

#320

Earlier quoted context omitted.

So put in an iptables rule that restricts it to their network and make people remote in to use their client. Done and done.

iptables rules are not magic security talismans.

Oh yes they are you just need to add the --rabbit-foot switch.
Post reply on HN