Live data from Hacker News

Guide to Slack import and export tools

get.slack.help

231–240 of 529 posts

Re: Guide to Slack import and export tools

#231
post #108

Earlier quoted context omitted.

What is the material difference between having employees save DM logs in an auditable, authenticated way and being able to view employee DMs? If any employee can ostensibly be compelled to provide their logs when asked by their employer, you are getting just as much information as if IT can view them directly. The only way IT doesn't get as much information is if the system doesn't work, for example because employees…

> What is the material difference between having employees save DM logs in an auditable, authenticated way and being able to view employee DMs? > When you are reviewing an auditable log of information related to an employee, you don't necessarily want to have to ask the employee for that information, nor do you necessarily want them to know you're reviewing it. You just answered your own question. You might not want…

> You might not want them to know you're reviewing it but they most certainly do want to know that you are.

Of course they want to know. Everyone wants to know. But if they committed a crime, or at least are complicit in a lawsuit the company is facing, their desire for privacy on an information channel they don't own is irrelevant.

I don't understand why this is controversial. When the SEC, FBI, local police, opposing legal team, etc. want you to hand over information about an employee, having to ask the employee directly or even let them know is problematic.

Re: Guide to Slack import and export tools

#232
post #105

Earlier quoted context omitted.

> "Compare that to our email, where I can go into anyone's messages immediately if need-be. This is all very standard corporate IT stuff that you need for HR and legal reasons." Wow, THAT is highly illegal in Europe.

I was under the impression it WAS legal in Europe as well after being litigated to the Court of Human Rights[1]. The requirement is simply that they inform you ahead of time that they can (and will) monitor your email. In the US there is usually a form you sign at your hiring that says you understand the company may monitor your email. It is couched in terms like "to ensure compliance with laws and company policy" bu…

We're US based, and it's very explicit that we can and will do this if necessary. We state clearly to all employees that the computers and accounts we give them are not theirs and are subject to monitoring. Thankfully, it's almost never necessary.

Re: Guide to Slack import and export tools

#233
post #89
post #43

Earlier quoted context omitted.

There are security issues here that you may not be aware. For one example, if technically knowledgeable people want to falsify signed logs without having the signing key, they can simply keep a separate set of logs with actual innocuous conversations. Slack would sign those in your scenario without a problem. This is the canonical problem of keeping "double-books".

While I agree with auditable access to employee DMs, there is a middle ground solution that trivially solves the problem you've presented. Instead of providing the employer with access to the employee's messages directly, logs can be signed at both the blob and message level. Then if an employee selectively turns over only some of their logs, the mismatch will be readily apparent.

Not sure what you mean by blobs? If Slack implemented a scheme like this, they should sign a message which includes metadata like the org name, channel name and timestamps in addition to text.

Re: Guide to Slack import and export tools

#234

On a semi-side topic: Canadian dev here, I always immediately hard delete e-mail correspondence (both inbox and sent) with HR on anything that I feel private about, as I don't want the guys in IT reading it. I know they don't, but I also know they can . For example, I might trust the head of IT but I might not trust that new intern or "new guy" they just hired. What do you guys do when it comes to HR correspondence a…

With most corporate email systems, I'm pretty sure you can't hard delete any message. Sure, it may no longer show up in your inbox but it won't be vanishing off of the compliance logs.

Re: Guide to Slack import and export tools

#235
post #180

Earlier quoted context omitted.

You are assuming that harassment was direct, sending messages to the accusers. My impression is that this was a group chatting privately about the accusers either making fun of them or coordinating actions. While this can be done through other channels (in person or private cellphone) allowing it on corporate infrastructure without monitoring is not acceptable.

If harassers, as you have mentioned, can simply switch to another channel, then what problem exactly is this measure trying to solve? I'm honestly confused.

Because you could just forbid employees from using such other form of communication at work.

Re: Guide to Slack import and export tools

#236
post #85

Earlier quoted context omitted.

Your employer owns the data, not you. The owner of something doesn't need special permission to look at it. It could be a company provided computer, email, or filing cabinet; they all belong to your work and they do not need to ask anyone to get in and look at the contents. Even something that has a reasonable expectation of only containing personal belongings (eg. a locker) may or may not be protected from employer…

How can a personal conversation be a "data". you mean they can potentially sell my personal conversation with a friend as if its a company owned data?

Assuming you and your friend both work at the same company using the same Slack Workspace and someone would be willing to pay for the data? Yes, it is a possible scenario. I have no idea why a company would offer to sell it's employee chat logs but I am sure there's a more clever individual out there who can think of reasons.

Re: Guide to Slack import and export tools

#237
As an owner of a free slack that has thousands of historical and unaccessible messages by the users, how can I delete these stored but not unaccessible messages to protect them?

It seems unconscionable that Slack retains messages but provides no way to remove them without paying.

Re: Guide to Slack import and export tools

#238

Jesus, nobody here has any clue what they're talking about. Slack has allowed companies to read private messages for well over a year. It has been called "compliance exports" and you as a slack user could always see if you had them turned on, as well as which individuals had access to read your private messages. Source: CTO of a unicorn confirmed he had used this feature to read private communications (private rooms…

The fact that they specify that consent is required on the free plan but not on the Plus or Enterprise plan suggests that the old compliance export requirements have changed. The old compliance export process required consent AND it only allowed you to access data from that point forward. The changes introduced today seem to suggest that historic data is now available by default.

Re: Guide to Slack import and export tools

#239
post #105

Earlier quoted context omitted.

> "Compare that to our email, where I can go into anyone's messages immediately if need-be. This is all very standard corporate IT stuff that you need for HR and legal reasons." Wow, THAT is highly illegal in Europe.

Europe consists of plenty of countries, all of them different. It seems like statements on HN about how it is "in Europe" is usually Americans writing fan fiction about some never-never land.

Usually people mean the EU, and there is lots of EU level law.

They even do it in the UK, which is weird "Here in Britain, we drive on the left, and in Europe they drive on the right"

Post reply on HN