Live data from Hacker News

Guide to Slack import and export tools

get.slack.help

301–310 of 529 posts

Re: Guide to Slack import and export tools

#301
post #242

Earlier quoted context omitted.

> socio-political paradigm Sigh. And workplaces are socio-political contexts... I didn't find it very difficult to get past his hyperbole, and I frankly find it hard to believe that you did. It isn't hard to argue that monitoring channels that even just imply privacy, regardless of whether they take place in the workplace (or in academia, or at home) is a violation of personal rights - regardless of the fact that you…

> And workplaces are socio-political contexts They're not governments, they're companies. > monitoring channels that even just imply privacy, regardless of whether they take place in the workplace (or in academia, or at home) is a violation of personal rights It isn't, unless your definition of "personal rights" includes "things I personally want which are neither codified in, nor protected by, laws."

>They're not governments, they're companies.

You're right, it's important to note they are more powerful and exercise more control over the lives of their employees than many governments, though employees often have the same opportunity to leave their company as they do their government (none).

>It isn't, unless your definition of "personal rights" includes "things I personally want which are neither codified in, nor protected by, laws."

Yes that's literally exactly what personal rights always means. Legal rights are legal rights, personal rights are a conception of what the person who uses the term wants or believes rights to be.

Re: Guide to Slack import and export tools

#302
post #224

Earlier quoted context omitted.

I hate to tell you this but if you would quit a job for this reason you probably can't work in the US. The US has laws about corporate compliance, and it has requirements for things like dealing with sexual harassment. There is no such thing as a "private conversation" that takes place over a corporate network. For example, in the US sexual harassment is taken seriously. If a company gets a complaint of sexual harass…

That line or reasoning makes no sense. If that were true, then states like California couldn't make it illegal for companies to eavesdrop on its employees(e.g. recording audio, bugging offices). But allowing companies to read direct messages is very, very similar. Also, what's preventing a victim of harassment from handing over the offending messages? I don't see how this helps anyone.

Recording audio and bugging offices is a completely different matter than reading through already preserved text that exists on company infrastructure (email or slack conversations). The records already exist in the case we're talking about.

Presumably the victim would share the harassing messages, but by being able to review the records directly the supervisors can gain more information such as whether the harasser was also harassing others, whether there was coordination between multiple people, or even if the original shared messages were missing some context which would vindicate the accused harasser. There's a lot of reasons why a real investigation will bring up more information than a simple one sided copy/paste would.

Re: Guide to Slack import and export tools

#303
post #241

Earlier quoted context omitted.

If two people want to have a private conversation, they'll just find another means by which to do it. In the long run, abusing your privileged access to conversations intended to be private (however justified you may consider it to be) will just breed mistrust among employees. I would quit a job that treated me as a child which must be supervised in such a manner.

Hope this doesn't sound too harsh but your reply comes off as extremely self-centered. What about looking—at the very least—at it from a legal perspective? It's not like lawsuits and aspects related to discovery haven't been in the tech news lately.

It’s sad how many bullshit decisions were buldozed by “because legal” excuse. By that logic eveything should be recorded everywhere — including bathrooms.

Re: Guide to Slack import and export tools

#304
post #180

Earlier quoted context omitted.

You are assuming that harassment was direct, sending messages to the accusers. My impression is that this was a group chatting privately about the accusers either making fun of them or coordinating actions. While this can be done through other channels (in person or private cellphone) allowing it on corporate infrastructure without monitoring is not acceptable.

If harassers, as you have mentioned, can simply switch to another channel, then what problem exactly is this measure trying to solve? I'm honestly confused.

Friction. Yes they could use PGP messages. But most people are idiots and use the systems that are available and simple. If somebody needs to think "I've got to go through these extra steps to be an asshole" then they might think twice in the first place.

Re: Guide to Slack import and export tools

#305
post #105

Earlier quoted context omitted.

> "Compare that to our email, where I can go into anyone's messages immediately if need-be. This is all very standard corporate IT stuff that you need for HR and legal reasons." Wow, THAT is highly illegal in Europe.

Europe consists of plenty of countries, all of them different. It seems like statements on HN about how it is "in Europe" is usually Americans writing fan fiction about some never-never land.

Hadn't thought they were actually Americans, since it's usually critical of the US. That explains why they never mention which country they're from.

Re: Guide to Slack import and export tools

#306

I was always under the impression this was already going on. I don't see the surprise here: there shouldn't be any expectation of privacy with regards to conversations between employees happening on company virtual grounds. Heck, in my previous company when we wanted to talk about something off-the-record, we'd even physically go off campus due to the sheer amount of walls equipped with 'ears'.

Never mind the walls: what about the people equipped with literal ears?

Re: Guide to Slack import and export tools

#307
post #170

Earlier quoted context omitted.

> but your chosen solution is totalitarian surveillance in the workplace because an intern got offended? Sigh Totalitarianism is a socio-political paradigm, not a stand-in word to describe things you think constitute surveillance in the context of a business. Companies require the capability to maintain auditable records of employee activity on the information channels they own and manage. Your company is not recordi…

> socio-political paradigm Sigh. And workplaces are socio-political contexts... I didn't find it very difficult to get past his hyperbole, and I frankly find it hard to believe that you did. It isn't hard to argue that monitoring channels that even just imply privacy, regardless of whether they take place in the workplace (or in academia, or at home) is a violation of personal rights - regardless of the fact that you…

> imply privacy

Workplace provided communication mechanisms do not in any way imply privacy. Best practices are that staff sign an acknowledgement of such, so that there is no such confusion.

Re: Guide to Slack import and export tools

#308
post #89
post #43

Earlier quoted context omitted.

There are security issues here that you may not be aware. For one example, if technically knowledgeable people want to falsify signed logs without having the signing key, they can simply keep a separate set of logs with actual innocuous conversations. Slack would sign those in your scenario without a problem. This is the canonical problem of keeping "double-books".

While I agree with auditable access to employee DMs, there is a middle ground solution that trivially solves the problem you've presented. Instead of providing the employer with access to the employee's messages directly, logs can be signed at both the blob and message level. Then if an employee selectively turns over only some of their logs, the mismatch will be readily apparent.

Of course it can be solved! I was pointing out that the prior comment was incorrect.

If an employee is in possession of chat logs that if divulged will get them fired, they can simply delete the logs. "Sorry, the drive crashed. IT is working to fix it right now." Stepwise refinement to insecurely re-create security solutions is one of the reasons for many security vulnerabilities.

Logs are well understood, and logging of sensitive information is not just a small technical issue but a security issue. The same way that people shouldn't design their own crypto, when people design logging mechanisms for sensitive data, which is seemingly simple, they will almost always introduce these security errors, as in your post.

Unfortunately, there are also a number of legal issues (and possibly compliance issues) that need to be accounted for from redaction to anonymity and from GDPR to encryption.

Re: Guide to Slack import and export tools

#309

How is this possibly news? Besides the fact than Slack has let owners read DMs through compliance export since forever, most company Slacks authenticate via mail (usually Google mail), which your employer controls . This is no different than company emails, which (I hope this isn't surprising) your employer can also read. Don't have personal conversations on your company Slack!

> Don't have personal conversations on your company Slack!

You may be discussing unionization on your company Slack, though, and the employer may now use that against you. There’s a lot more than strictly work-related content, and strictly private content. A huge grey area is inbetween, and the employer shouldn’t be able to access any of them (and as the ECHR ruled, the employer may now)

Re: Guide to Slack import and export tools

#310

Earlier quoted context omitted.

There's an infinite space of solutions to your particular problem, but your chosen solution is totalitarian surveillance in the workplace because an intern got offended? I avoid workplaces which force shit like this. So do all the good developers I know, because they're people who can afford to be choosy. Bullies are pretty adept at functioning in these environments. Instead of harassing on monitored DMs, they'll mak…

Totalitarian surveilance? While you’re at removing that from the workplace don’t forget to instigate democratic revolution in your company as well.

Well yes, this is a good idea, democratization of the workplace and worker co-ops generally promote better quality of life for employees and the surrounding community, less exploitation, less corruption, more justice and similar or better efficiency as the normal dictatorial corporate model.
Post reply on HN