On a semi-side topic: Canadian dev here, I always immediately hard delete e-mail correspondence (both inbox and sent) with HR on anything that I feel private about, as I don't want the guys in IT reading it. I know they don't, but I also know they can . For example, I might trust the head of IT but I might not trust that new intern or "new guy" they just hired. What do you guys do when it comes to HR correspondence a…
Well, there's nothing I can really do about it. When I hit "delete", my company email doesn't actually get deleted. It just disappears from my view. I believe the stated policy is they delete after 3 years post "delete".
If I worked in or near the office, I'd walk over to HR and request printouts instead of emails, but since I work remotely, I'm stuck.
If you publicize that you can read the messages, no problem.
I had a boss that liked to spy in the private messages of the employees without their knowledge. A bunch of interns started to privately create offensive nicknames for a fat employee. They didn't used the name in public. The read and started to use to use the nicknames in his conversation.
Well, this guy also publish jobs ads for our old tech stack with a false company name to see if any of his employees were applying.
As head of IT for a company using Slack: FINALLY. Don't get me wrong--it's not like I want to read your messages and very likely won't. But there are times when I have no choice. A few years back, a group of interns started privately harassing other interns via Slack. Only way to see it was to boot an offending intern from his work station and go into his Slack to see what was happening. We had to make all intern acc…
If two people want to have a private conversation, they'll just find another means by which to do it. In the long run, abusing your privileged access to conversations intended to be private (however justified you may consider it to be) will just breed mistrust among employees. I would quit a job that treated me as a child which must be supervised in such a manner.
If you're required to be on Slack to do your job, then your employer is obligated to make sure going on Slack is safe and free from harassment. You can't just sign off or block other employees.
As head of IT for a company using Slack: FINALLY. Don't get me wrong--it's not like I want to read your messages and very likely won't. But there are times when I have no choice. A few years back, a group of interns started privately harassing other interns via Slack. Only way to see it was to boot an offending intern from his work station and go into his Slack to see what was happening. We had to make all intern acc…
If two people want to have a private conversation, they'll just find another means by which to do it. In the long run, abusing your privileged access to conversations intended to be private (however justified you may consider it to be) will just breed mistrust among employees. I would quit a job that treated me as a child which must be supervised in such a manner.
I hate to tell you this but if you would quit a job for this reason you probably can't work in the US. The US has laws about corporate compliance, and it has requirements for things like dealing with sexual harassment. There is no such thing as a "private conversation" that takes place over a corporate network.
For example, in the US sexual harassment is taken seriously. If a company gets a complaint of sexual harassment on Slack they are legally obligated to look into it, and if they refuse to the individual managers could personally be held liable for it. This includes situations where the person being harassed isn't directly in the conversation- the above example of harassment over slack could have evidence of coordination in a different private channel than the ones the harassment target is in.
On a semi-side topic: Canadian dev here, I always immediately hard delete e-mail correspondence (both inbox and sent) with HR on anything that I feel private about, as I don't want the guys in IT reading it. I know they don't, but I also know they can . For example, I might trust the head of IT but I might not trust that new intern or "new guy" they just hired. What do you guys do when it comes to HR correspondence a…
Are you certain that IT can't read deleted emails? I would think there would be backups and logs in the email server.
As head of IT for a company using Slack: FINALLY. Don't get me wrong--it's not like I want to read your messages and very likely won't. But there are times when I have no choice. A few years back, a group of interns started privately harassing other interns via Slack. Only way to see it was to boot an offending intern from his work station and go into his Slack to see what was happening. We had to make all intern acc…
I wish a compromise between willy-nilly dumps of private DMs and their Compliance Exports could have been found. As a user who is not the head of IT this is frustrating. Now frank discussions have to go back to out-of-band channels. If anyone thinks this won't get abused, think again. I've worked with IT folks of all shapes and sizes over many years and a tiny percentage do abuse the privilege. Including heads of IT.…
I'll agree that a whole dump of data is not the ideal solution to the problem here.
Technically this was possible before this. Since the email to each slack user is an @company.com address all you need to do is take control of the employees email address, reset the slack password and login as the target user.
> Since the email to each slack user is an @company.com address Not necessarily
for most companies slack channel, you would need the @company.com to get approved for slack access.
Very rare and unprofessional to allow someone's personal email access
I think Gitter is architected differently and doesn't allow this. Your private chats aren't in the context of some company, but the network.
Again, look at this everybody! We are relying on some third parties merely to facilitate our conversations! And they are relying on the "SAAS" developer who hosts all the conversations (not open source) to determine one-size-fits-all rules.
As head of IT for a company using Slack: FINALLY. Don't get me wrong--it's not like I want to read your messages and very likely won't. But there are times when I have no choice. A few years back, a group of interns started privately harassing other interns via Slack. Only way to see it was to boot an offending intern from his work station and go into his Slack to see what was happening. We had to make all intern acc…
If two people want to have a private conversation, they'll just find another means by which to do it. In the long run, abusing your privileged access to conversations intended to be private (however justified you may consider it to be) will just breed mistrust among employees. I would quit a job that treated me as a child which must be supervised in such a manner.
Hey, don't let the door hit yourself on the way out. There are very valid legal reasons for a business to need at least the option for discovery, e.g., legal suits, fraud, violation of trade secret or export controls, serious employee harassment, etc. This goes for chat just as much as email or anything else electronic. If you think this is "treating you like a child", well, perhaps you are the child.
On a semi-side topic: Canadian dev here, I always immediately hard delete e-mail correspondence (both inbox and sent) with HR on anything that I feel private about, as I don't want the guys in IT reading it. I know they don't, but I also know they can . For example, I might trust the head of IT but I might not trust that new intern or "new guy" they just hired. What do you guys do when it comes to HR correspondence a…
This does not necessarily prevent them from being able to read these emails. If the email system has journaling enabled then a copy of every email sent and received is retained.