Technically this was possible before this. Since the email to each slack user is an @company.com address all you need to do is take control of the employees email address, reset the slack password and login as the target user.
Not necessarily
71–80 of 529 posts
Technically this was possible before this. Since the email to each slack user is an @company.com address all you need to do is take control of the employees email address, reset the slack password and login as the target user.
Not necessarily
Earlier quoted context omitted.
Meh. Nobody should be surprised by any of this in the slightest. If your employer provides / pays for any kind of communications tool, the only sane position is to assume that they can - and probably do - monitor every single byte you send.
I think there's some middle ground, some grey area where whether it's alright is murky. It's kind of pulling the rug out from under people when the policy of a 3rd party provider abruptly changes and suddenly tons of messages become available to the company. There are a number of things I might mention to a coworker over a private IM which wouldn't necessarily put my employment at risk, but would be awkward for manag…
Earlier quoted context omitted.
You should not assume your communications are private if there is no end-to-end encryption. Also, the employers are often required to do this because of regulations. (I think those are silly regulations given that end-to-end encryption is so easily available nowadays, but the companies don't really have a choice here.)
You shouldn't assume they're private just because they're encrypted. Employers can and will install SSL certs on your desktop machine so that they can decrypt and scan/archive everything at the gateway. This is standard practice in financial companies, and is easily done anywhere. They can also install screen capture and key logging software if they want, but that's less common and without disclosure is a lot shadier…
Of course, you also need to trust your hardware.
I had a toxic manager who would screenshot DMs and post them publicly. Just consider any work communication of any form to be public.
As head of IT for a company using Slack: FINALLY. Don't get me wrong--it's not like I want to read your messages and very likely won't. But there are times when I have no choice. A few years back, a group of interns started privately harassing other interns via Slack. Only way to see it was to boot an offending intern from his work station and go into his Slack to see what was happening. We had to make all intern acc…
> Only way to see it was to boot an offending intern from his work station and go into his Slack to see what was happening. Why couldn't you just ask the recipient to look on his station? > We had to make all intern accounts into multi-channel guests after that Are 2 interns ever allowed to be alone together? I mean it's essentially the same, you are saying they can't be trusted so either you always need them in grou…
Earlier quoted context omitted.
how is it legal. Even the law enforcement needs to provide a warrant in case they want to search my apartment.
Not if you're living in one of their cells. Your employer pays for slack and it is a work related tool, just like your emails. If you want to have private communications then send a text. BTW they can also search your desk because, you know, it's not yours.
Previously, you could only see employee DMs if you turned on Compliance Exports, at which point you could download all of them going forward . Now it sounds like everything you've ever written could be downloaded at any time without notice. So, all of those communications you had with co-workers based on the promise they would be private until you were notified future ones wouldn't be anymore? Now it's ALL available…
I doubt this has anything to do with GDPR which is about personal information of customers and users. In this case the customer is the company and I don't think GDPR applies.
Unfortunately, Slack also gets used for a lot of OSS communities. Arguably this was already a poor fit, but now it's even more obviously a mismatched relationship; it's unclear whether one could just start paying for a Slack account and immediately pull all DM history for something that didn't come with the expectation of corporate ownership.
#freenodeforlyfe, I suppose.
Earlier quoted context omitted.
why presumably due to GDPR? I would think it was a possible GDPR problem for them in the future. Specifically, you wrote it based on expectation it was private and now it is not, when did you give permission for sharing that data?
If it's your company's asset, you gave permission for sharing that data when you signed the e-handbook at orientation, the same document that gives them the right to monitor your work emails, put MDM on your work-issued phone, and log your work machine's network traffic into their SIEM. You have no right to privacy when you're inside your company's office using your company's computers to access your company's networ…