Live data from Hacker News

An Apology and an Update

slackhq.com

181–190 of 236 posts

Re: An Apology and an Update

#182
post #40

I'm a big fan and critic of apologies. This one is pretty good. They admit the mistake was theirs and they take responsibility for it. They say sorry. They explain what they're going to do to fix the situation. They say they're going to learn from this and not have similar mistakes in the future. Pretty solid. The only thing that is missing, in my view, is personalization. Tell me who you are, speaking for the organi…

[deleted]

Re: An Apology and an Update

#183
post #40

I'm a big fan and critic of apologies. This one is pretty good. They admit the mistake was theirs and they take responsibility for it. They say sorry. They explain what they're going to do to fix the situation. They say they're going to learn from this and not have similar mistakes in the future. Pretty solid. The only thing that is missing, in my view, is personalization. Tell me who you are, speaking for the organi…

Who says they didn't hire a PR firm to write this apology?

Re: An Apology and an Update

#184
post #40

I'm a big fan and critic of apologies. This one is pretty good. They admit the mistake was theirs and they take responsibility for it. They say sorry. They explain what they're going to do to fix the situation. They say they're going to learn from this and not have similar mistakes in the future. Pretty solid. The only thing that is missing, in my view, is personalization. Tell me who you are, speaking for the organi…

Who says they didn't hire a PR firm to write this apology?

quality and sincerity are orthogonal.

Re: An Apology and an Update

#185

Earlier quoted context omitted.

Texts/SMS/voice calls etc are not encrypted. The NSA slurps that data up like a sponge wrapped in Brawny wrapped in a ShamWow. There's a huge list of why we can't export/sale things to certain countries, but encryption is one of them. Things that seem "innocent" enough like a hardware video box might qualify as embargoed because it has the ability to decode SSL network traffic. Can't let that tech get in the hands of…

Encryption is not considered ammo since forever now. And slack doesn't have E2E encryption, and is an american company. The NSA can just knock on the front door and ask for the data, same as they would for an ISP.

It is still expert controlled to embargoed countries. The law makes no distinction between Encryption, so non-E2E doesn't mean anything.

Re: An Apology and an Update

#186
As apologies go, this is a decent one.

But they still say:

> We would also like to notify our users that as we continue to update our systems over the next several weeks, we will soon begin blocking access to our service from IP addresses associated with an embargoed country.

I'm no expert, but I did spend a couple months checking alleged locations of VPN servers. I compared: 1) location alleged by the VPN provider; 2) location from various geolocation databases; and 3) ping results from several hundred servers (from various providers).

Bottom line, locations alleged by VPN providers and locations from geolocation databases were generally in agreement. But for some VPN providers, such as HideMyAss, ping results demonstrated that those locations were very often implausible. Because they implied signal transmission faster than the speed of light.

So anyway, basing life-altering decisions on IP-based geolocation is an extremely stupid (or at least, unjust) thing to do.

Re: An Apology and an Update

#187

Earlier quoted context omitted.

If you did something wrong more than once and gave the same apology that statement would make total sense. The first time though is unfair and kind of selfish minded.

I've spilt things on people more than once, AFAIK that's not unusual. Does that make me at fault morally? I'd say no. Your thesis needs work IMO. Make sure you don't fail morally by ever presenting an incomplete/unsound thesis again!

Spilling something is an accident. Other things can be mistakes but not accidents.

Re: An Apology and an Update

#188
post #126

It’s still profoundly disturbing to my eyes. Technically their underlying problem is relying on IP ranges, wich is flawed and raises false positives all the time. They seem to recognize they shouldn’t be doing irreversible and critical action with only that info, yet will still use it to drop traffic. To me their message is “sorry we screwed with your accounts, going forward we’ll only screw with your messages”. Am I…

I totally agree.

But the problem then is what they ought to rely on. If in fact they are legally required to deny service to those in sanctioned countries.

The whole thing is silly. I mean, anyone in a sanctioned country who was truly up to no good would be spoofing their IP address in some way. So most of the users that they ban or block will be innocent.

Post reply on HN