Live data from Hacker News

Guide to Slack import and export tools

get.slack.help

161–170 of 529 posts

Re: Guide to Slack import and export tools

#161
post #47
post #29

Earlier quoted context omitted.

You could have the logs signed with Slack's PGP key so they cannot be altered without the signature causing a mismatch.

Arguably, but what if the company wants to find proof of, say, two employees colluding to exfiltrate sensitive data or something like that? Would they have to convince them to turn in the PGP signed logs? More generally like the parent I don't see why a company couldn't have full control over their corporate tools.

What if those two employees collude to do something like that via their own private phones? Should employers have access to those too?

It doesn't seem to me like any of this really does anything, since there are (and should be) plenty of ways that employees can communicate without their employer having access.

Re: Guide to Slack import and export tools

#162
post #83

Earlier quoted context omitted.

Depends on the state I would assume, but of course IANAL. Some states have single party consent, and you're certainly not in a private area. You'd have to look into the eavesdropping laws where you live. You realize that many buildings have security cameras, right? I'm still very confused as to why you believe that your communications over a company owned platform should/would be private.

because I dont see the difference between having direct conversation vs having electronic conversation in the office premises. why would there be different rules for them?

Well, one is a platform provided specifically for work related communications (again, like your email). Also, read the above linked article which discusses wiretapping:

>employers are given an exemption for calls made “in the ordinary course of business.” Courts interpret this to mean that employers can eavesdrop on all business telephone calls but cannot listen to or record messages it knows are personal.

Also:

>ECPA also applies to audio monitoring of the workplace. Employers can install recording devices in any location that is used primarily for work. But employers may not conduct audio recording of nonworking areas such as cafeterias, break rooms, or locker rooms. In practice, this means little because employers are not required to notify employees that they are being recorded and employees are unlikely to discover the hidden microphone.

So there is an obvious legal distinction between communications which are intended to be work related and those which are not. In your cafeteria example, no, they should not (assuming this article is the entire story.) However, your slack messages are not considered the same as a cafeteria conversation.

Again, I'm not a lawyer and have zero real knowledge here, but I think it's silly to expect privacy in your work provided messaging system.

Re: Guide to Slack import and export tools

#163

Earlier quoted context omitted.

How does it work, an outlook 365 admin(?) Can read anyone's email that they want? Do they essentially just log onto the normal Hi as that user?

As a manager, if I fire somebody or they leave, I get access to their mailbox via Outlook365 for like 3 months, just in case I need to grab something from it. So there must be a way to assign ownership of a mailbox to another user.

Yeah, you can attach mailboxes to other users with Powershell.

You could also just create a mail rule that sends a copy of every email everytime someone sends and receives one and they wouldn't know.

Re: Guide to Slack import and export tools

#164
post #108

Earlier quoted context omitted.

Why can't the recipient save a copy of logs?

What is the material difference between having employees save DM logs in an auditable, authenticated way and being able to view employee DMs? If any employee can ostensibly be compelled to provide their logs when asked by their employer, you are getting just as much information as if IT can view them directly. The only way IT doesn't get as much information is if the system doesn't work, for example because employees…

> What is the material difference between having employees save DM logs in an auditable, authenticated way and being able to view employee DMs?

> When you are reviewing an auditable log of information related to an employee, you don't necessarily want to have to ask the employee for that information, nor do you necessarily want them to know you're reviewing it.

You just answered your own question.

You might not want them to know you're reviewing it but they most certainly do want to know that you are.

Re: Guide to Slack import and export tools

#166
post #74

I had a toxic manager who would screenshot DMs and post them publicly. Just consider any work communication of any form to be public.

If someone is determined to be an ass, technology isn't a barrier.

Technology helps asses act like asses more effectively.

Re: Guide to Slack import and export tools

#167
post #83
post #76

Earlier quoted context omitted.

what about, lets say, conversations in the company owned cafeteria? can the employer record them without your consent and use as evidence against you?

Depends on the state I would assume, but of course IANAL. Some states have single party consent, and you're certainly not in a private area. You'd have to look into the eavesdropping laws where you live. You realize that many buildings have security cameras, right? I'm still very confused as to why you believe that your communications over a company owned platform should/would be private.

>> I'm still very confused as to why you believe that your communications over a company owned platform should/would be private.

Is this a generational thing? When I got my first job, there were cultural norms about not making personal calls on the company phone (this was a time when people still used paper for memos) or using company resources like copiers.

While I realize times have changed and things appear much more relaxed today, I don't understand why people would even think to use company owned devices/servers/resources for personal stuff for anything short of an emergency.

Re: Guide to Slack import and export tools

#170

As head of IT for a company using Slack: FINALLY. Don't get me wrong--it's not like I want to read your messages and very likely won't. But there are times when I have no choice. A few years back, a group of interns started privately harassing other interns via Slack. Only way to see it was to boot an offending intern from his work station and go into his Slack to see what was happening. We had to make all intern acc…

There's an infinite space of solutions to your particular problem, but your chosen solution is totalitarian surveillance in the workplace because an intern got offended? I avoid workplaces which force shit like this. So do all the good developers I know, because they're people who can afford to be choosy. Bullies are pretty adept at functioning in these environments. Instead of harassing on monitored DMs, they'll mak…

> but your chosen solution is totalitarian surveillance in the workplace because an intern got offended?

Sigh

Totalitarianism is a socio-political paradigm, not a stand-in word to describe things you think constitute surveillance in the context of a business. Companies require the capability to maintain auditable records of employee activity on the information channels they own and manage. Your company is not recording your activity in the privacy of your home or on the street, it's protecting itself and other employees from potentially problematic abuse scenarios. These requirements are also directly imposed by a variety of regulations in various countries.

When you twist the meaning of loaded words like this to describe things you don't like, you make it very difficult for people to get past the hyperbole and take you seriously. You're conflating assaults on personal rights with the routine and mundane business practice of keeping auditable logs.

> I avoid workplaces which force shit like this. So do all the good developers I know, because they're people who can afford to be choosy.

I'm not sure what you're getting at here, because almost all the good developers I know work in environments like this. So where does trading these anecdotes leave us? Do you really believe most competent software engineers don't work in companies that do this? In most cases, that means the company is actively breaking the law, or at best making adherence with the law very difficult and error-prone.

Post reply on HN