Live data from Hacker News

Slack closes account of an Iranian user living in Canada

twitter.com

571–580 of 638 posts

Re: Slack closes account of an Iranian user living in Canada

#571

Sanctions are a very blunt instrument; sanctions will always harm people we like, indeed often the very people we want to help with the sanctions. You can disagree with the idea of sanctions based upon this, but this is how sanctions work. Companies need to comply with sanctions and the repercussions of not complying can be severe. I'm not sure WHY Slack chose this method to respond to the sanctions, nor why they've…

"the very people we want to help with the sanctions"

That was funny.

Re: Slack closes account of an Iranian user living in Canada

#572
post #354

First off, as many know, this is not a single incident. This has happened to many of us (including me) from "sanctioned" countries. (I am from Iran, but live in Germany) But this makes me think. Many of the services I use are from US companies. Most notable are: Gmail (Google Drive, Google Calendar, etc.), Github, Dropbox, Trello and Toggl. Should I be worried? Should I actually start switching away from these servic…

Yes

Re: Slack closes account of an Iranian user living in Canada

#573

Earlier quoted context omitted.

An effort is underway to standardize E2E encrypted group messaging in the IETF with the MLS [1] protocol. Open-source participants include Wire and Matrix. Commercial participants include Facebook, Cisco, Google and Apple. [1] https://datatracker.ietf.org/wg/mls/about/ Wire is open-source today and usable by regular people, with E2E encryption and email-only accounts.

How is Wire developed and funded? This was my biggest problem with Matrix (unsustainable funding model for the protocol and no proper standards body). Why not just use XMPP? Yes, everyone hates XML, but the protocol is well designed, has sustainable funding (via the IETF and XSF), and there's lots of experience out there, and it's flexible enough to develop services like Slack on top of.

Because XMPP itself is not enough. If you want to deploy XMPP-based chat service in your org, and you want everyone to have same features (offline, mobile, images), you will have a hard time.

You cannot just tell people "go choose any XMPP client, and it will work fine". Instead, it is more like "get XMPP client, but make sure it supports XEP-1111, XEP-2222 and XEP-3333". And if you have multiple platforms (Android, iOS, Win, Linux), let's hope you can find a client for each.

Re: Slack closes account of an Iranian user living in Canada

#574

Earlier quoted context omitted.

I would love to see more things built on open protocols. But for that to be the case, we have to find ways to make better apps built on top of open protocols. We should start by admitting that Slack beat IRC. Beat it like a cheap hallway rug. IRC was always a terrible experience for novices, and it wasn't a great experience for experts. That it had any users at all is a testament not to IRC, but to what it enabled. S…

If FLOSS developers started building their software products like businesses built their products, then they would have to turn into businesses. You see this in pretty much every segment, I'm looking at you, Canonical. More to the point, there is always going to be some value-added service a profit-seeking enterprise is going to be able to provide over what's freely available. If we built IRC 2.0, then Slack 3.0 will…

Right. I'm not saying open-source developers have to start building in the same way as for profit companies. I'm saying they have to build products that are, from the user perspective, as good as the for-profit ones.

A good example here is Firefox. When it started out, it was better than the competition. Chrome pulled ahead for a while, but Mozilla responded and now it's competitive again. And Firefox has done this while advocating energetically for an open web.

Another one that interests me is WhatsApp. They built a messaging product that was clearly superior to the alternatives. They eventually sold out for billions. But there's no reason they couldn't have done that as a nonprofit. And Signal has shown that a nonprofit can still jump into the space and do good things.

Re: Slack closes account of an Iranian user living in Canada

#575

Earlier quoted context omitted.

I would love to see more things built on open protocols. But for that to be the case, we have to find ways to make better apps built on top of open protocols. We should start by admitting that Slack beat IRC. Beat it like a cheap hallway rug. IRC was always a terrible experience for novices, and it wasn't a great experience for experts. That it had any users at all is a testament not to IRC, but to what it enabled. S…

I think as ethical, intelligent and conscious individuals, we folks in the developer and hacker community want people to make decisions on the basis of principles, when the reality is that people generally make decisions on the basis of convenience. In fact, people are often willing to sacrifice their principles (to a certain extent) in the name of convenience. If we want people to use principled technology, then we…

To have competitive apps built on top of open protocols, you need a big investment of time and money, so we need users to ask for it, or at least to reward companies when they invest money in it. For that, we need users to understand what they're asking for.

An example of how it might be possible to push this in the right direction is LEED. It didn't matter what the individual environmental ethics of people manufacturing electronics and designing houses was. Environmentally efficient building practices cost more, and there was no way for all the companies involved to form an opaque conspiratorial cabal to secretly impose the cost on consumers who would rather not pay it. Instead, they created LEED and used marketing to teach end consumers that LEED stood for more environmentally responsible practices.

Right now computer privacy and security are huge in the headlines, and a large number of people in the public and in industry want to do the right thing. But consumers don't know how to make the right choices, and companies aren't going to spend extra on the right thing if users are just as likely to choose something horrible. What companies need in order to invest extra capital in privacy and security is a plausible story of how to get users to choose the right thing and pay a bit more for it, if the industry builds it. They need a LEED standard for privacy and security. Then they can promote it and use it as a way to justify their investment in better, more ethical software. Corporations, schools, nonprofits, and other organizations can be pressured to make public commitments to use, or at least prefer, software that meets the standard. This won't drive horrible software out of the market, but it will create a sub-market where good software can survive.

Obviously laws and regulation are the bedrock, but in areas where consumers have a choice, we need to make it easy for them to make the right choice if they want to.

Re: Slack closes account of an Iranian user living in Canada

#576
post #445

Earlier quoted context omitted.

setting up, just getting started with IRC for a non-tech person is basically way too hard bordering on impossible from their perspective. We can talk about all the other issues around persistence and UX but just getting started is something beyond the vast majority of computer users. It’s really hard for us to remember and empathize with this.

Too hard? I installed mIRC on my own at age ~12 in the late 90s and I don't remember having any issues, the only thing you had to do was to type a nickname and choose a server. Nowadays it's even more simpler since you don't even need to install a client (qwebirc, kiwiirc, etc.).

Sure. 12-year-olds who go on to be software developers can install it. That says nothing about the user experience of the bottom quartile of users in terms of technical aptitude.

Re: Slack closes account of an Iranian user living in Canada

#577
post #565
post #555

Earlier quoted context omitted.

> What I find a lot of people miss when comparing Slack to IRC, is that not everyone using Slack is a developer. I know plenty of non-technical people who chatted on IRC who were not developers. They just used the mIRC client on windows to do that. They also managed to configure their email and news clients to send and read email and browse usenet. I simply don't understand where the idea of needing a technical backg…

I think this is to enable history and mobile, for example? Granted, I have not used IRC for a while, but last time I checked, the story for getting message history was "start a irc client inside a screen session on a server you own". And there were no mobile at all. (I remember writing a script which exported chat logs from my desktop client to text files available over HTTP... I'd then visit those pages from cell ph…

For history, it's either local logging or having an always on client you can connect to (like a bouncer), but most people I knew would just switch their client on, chat for a while, and then close it. They didn't really care much about history.

It was pretty much the same thing with newer chat services like ICQ, AIM, MSN messenger, etc. (though I think they started offering offline messages in later versions).

As for mobile, my older Nokia phone had a Symbian IRC/XMPP client that I could use without any issues.

Re: Slack closes account of an Iranian user living in Canada

#578

Earlier quoted context omitted.

Wait, so sanctions against a country should affect all people who share the common ethnicity in that country regardless of citizenship status or location in the world? So essentially it's a sanction against an ethnic group, not a state. Are you sure that's a reasonable idea? How did Slack figure out this guy's ethnicity / citizenship / status? Why are they allowed to access that information and unilaterally act on it…

They didn't figure out anyone's ethnicity, according to their press statement they banned all accounts which were accessed via Iranian IP's. While seemingly a little heavy handed IMO, they are trying to comply with US laws. They also provided a way for people to send an email to address their specific accounts if they feel they were terminated improperly. Slack is protecting their multi-billion dollar business and th…

Not just a little heavy-handed. If that's what they did, they probably picked up users that just happened to use the service from one of the countries at some previous point in time. And, at that point, the sanctions may not even have been in place.

Now, I admit that visiting the countries on the list aren't on my to-do-list, but if for example I decided to make a vacation trip to Cuba I really shouldn't lose my account at any US-based service just because of that.

Re: Slack closes account of an Iranian user living in Canada

#579

Earlier quoted context omitted.

How is Wire developed and funded? This was my biggest problem with Matrix (unsustainable funding model for the protocol and no proper standards body). Why not just use XMPP? Yes, everyone hates XML, but the protocol is well designed, has sustainable funding (via the IETF and XSF), and there's lots of experience out there, and it's flexible enough to develop services like Slack on top of.

Here's what Moxie Marlinspike has to say about the drawbacks of XMPP. https://signal.org/blog/the-ecosystem-is-moving/ "XMPP is an example of a federated protocol that advertises itself as a “living standard.” Despite its capacity for protocol “extensions,” however, it’s undeniable that XMPP still largely resembles a synchronous protocol with limited support for rich media, which can’t realistically be deployed on mo…

I don't think Moxie's right though; you can still do your own thing, and have it work best with your clients which support all the features, and then allow it to federate or optionally allow third party clients on your server with limited functionality. Naturally, you can also contribute back new extensions that you develop too so that other clients and services can adopt them if you want.

But I do tend to agree in general that we need fewer features and less complexity and to push more for basic profiles that everything should implement and that have a clear compliance label.

Re: Slack closes account of an Iranian user living in Canada

#580
post #573

Earlier quoted context omitted.

How is Wire developed and funded? This was my biggest problem with Matrix (unsustainable funding model for the protocol and no proper standards body). Why not just use XMPP? Yes, everyone hates XML, but the protocol is well designed, has sustainable funding (via the IETF and XSF), and there's lots of experience out there, and it's flexible enough to develop services like Slack on top of.

Because XMPP itself is not enough. If you want to deploy XMPP-based chat service in your org, and you want everyone to have same features (offline, mobile, images), you will have a hard time. You cannot just tell people "go choose any XMPP client, and it will work fine". Instead, it is more like "get XMPP client, but make sure it supports XEP-1111, XEP-2222 and XEP-3333". And if you have multiple platforms (Android,…

I agree to a certain extent, but I don't think you need to support everything, just the subset of features that a particular user cares about. We should have some form of baseline that's more than the basic protocol, and the Compliance Suites will hopefully help there, but in general as long as basic chat works it should be fine. The first party clients can support everything and give you the best experience, the third party ones are juts in case you can't run the first party clients or need eg. better accessibility support or similar.

For example, I used to use Mcabber with HipChat at work. Mcabber doesn't support even basic modern XMPP things (history, for example), but it was plenty good enough for me to chat with my coworkers.

Post reply on HN