Live data from Hacker News

Guide to Slack import and export tools

get.slack.help

41–50 of 529 posts

Re: Guide to Slack import and export tools

#41
post #2

Previously, you could only see employee DMs if you turned on Compliance Exports, at which point you could download all of them going forward . Now it sounds like everything you've ever written could be downloaded at any time without notice. So, all of those communications you had with co-workers based on the promise they would be private until you were notified future ones wouldn't be anymore? Now it's ALL available…

[deleted]

Re: Guide to Slack import and export tools

#43
post #29
post #24

Earlier quoted context omitted.

Because they typically can be easily falsified.

You could have the logs signed with Slack's PGP key so they cannot be altered without the signature causing a mismatch.

There are security issues here that you may not be aware. For one example, if technically knowledgeable people want to falsify signed logs without having the signing key, they can simply keep a separate set of logs with actual innocuous conversations. Slack would sign those in your scenario without a problem. This is the canonical problem of keeping "double-books".

Re: Guide to Slack import and export tools

#44
post #32

Earlier quoted context omitted.

This is not completely true. Been able to pull DMs via the Discovery API.

I actually didn't know this. Why did they have the big alert when turning on the Compliance Exports then?

Wanted to let people know about GDPR. More for optics I am sure.

Re: Guide to Slack import and export tools

#45
post #17
post #2

Previously, you could only see employee DMs if you turned on Compliance Exports, at which point you could download all of them going forward . Now it sounds like everything you've ever written could be downloaded at any time without notice. So, all of those communications you had with co-workers based on the promise they would be private until you were notified future ones wouldn't be anymore? Now it's ALL available…

You should not assume your communications are private if there is no end-to-end encryption. Also, the employers are often required to do this because of regulations. (I think those are silly regulations given that end-to-end encryption is so easily available nowadays, but the companies don't really have a choice here.)

You shouldn't assume they're private just because they're encrypted. Employers can and will install SSL certs on your desktop machine so that they can decrypt and scan/archive everything at the gateway. This is standard practice in financial companies, and is easily done anywhere.

They can also install screen capture and key logging software if they want, but that's less common and without disclosure is a lot shadier (although certainly legal in the US). I wouldn't expect it most places; it's a more extreme step.

But never trust encryption at work unless you know your company's policies.

Re: Guide to Slack import and export tools

#46
It's hard to see how this is bad -- they have/should be able to have access to your other work-related communication and work product (modulo the weird rules around things like salespersons' "rolodex"es).

It's so easy to have private channels these days it's hard to see how this should even inconvenience anyone.

Re: Guide to Slack import and export tools

#47
post #29
post #24

Earlier quoted context omitted.

Because they typically can be easily falsified.

You could have the logs signed with Slack's PGP key so they cannot be altered without the signature causing a mismatch.

Arguably, but what if the company wants to find proof of, say, two employees colluding to exfiltrate sensitive data or something like that? Would they have to convince them to turn in the PGP signed logs?

More generally like the parent I don't see why a company couldn't have full control over their corporate tools.

Re: Guide to Slack import and export tools

#48
post #2

Previously, you could only see employee DMs if you turned on Compliance Exports, at which point you could download all of them going forward . Now it sounds like everything you've ever written could be downloaded at any time without notice. So, all of those communications you had with co-workers based on the promise they would be private until you were notified future ones wouldn't be anymore? Now it's ALL available…

I doubt this has anything to do with GDPR which is about personal information of customers and users. In this case the customer is the company and I don't think GDPR applies.
Post reply on HN