Live data from Hacker News

Slack enables customers to control their encryption keys in enterprise version

techcrunch.com

11–20 of 178 posts

Re: Slack enables customers to control their encryption keys in enterprise version

#11
post #9
post #2

Reads more like "Hands over control to any customer that will pay for it." [1] I wonder if the UI shows the employees that their employers have the keys. [1] Edit: as opposed to only regulated customers. Also, there's an upcharge...you don't automatically get control.

There are industries where you have no expectation of privacy at work because all comms are required to be monitored and stored due to the law . So this new feature really enables them to serve these customers who operate under such laws.

Sure but being that it's a distinct change some sort of indicator in the UI seems reasonable.

Re: Slack enables customers to control their encryption keys in enterprise version

#12
post #4
post #3

At this point, between no encryption, horrible clients, mistreatment of irc users, and questionable corporate behavior there's nothing in Slack that's worth saving it for me. Superior free software alternatives exist that bring the same or better functionality while also giving the user full control.

Which free alternatives?

I find Rocketchat quite good.

Re: Slack enables customers to control their encryption keys in enterprise version

#13
post #2

Reads more like "Hands over control to any customer that will pay for it." [1] I wonder if the UI shows the employees that their employers have the keys. [1] Edit: as opposed to only regulated customers. Also, there's an upcharge...you don't automatically get control.

What is your expectation if the UI does not show that? That your communication is private? Why would you expect private communication when using your employer's infrastructure or, worse, a third party infrastructure like Slack?

If you don't own the keys, it's not your data.

Re: Slack enables customers to control their encryption keys in enterprise version

#14
I am not sure slack can ever meaningfully become encrypted while having persistence. All it takes is for a admin (or hacked admin account) to change the password of the target slack user and login as said user to view all their private messages. The encryption is mostly pointless as far as I can tell when all of it is circumvented by a changed password.

Re: Slack enables customers to control their encryption keys in enterprise version

#15
post #2

Reads more like "Hands over control to any customer that will pay for it." [1] I wonder if the UI shows the employees that their employers have the keys. [1] Edit: as opposed to only regulated customers. Also, there's an upcharge...you don't automatically get control.

Are you saying you had some sort of presumption of privacy on a corporate Slack account?

If you did, you had it in error.

If I am reading this right, this actually reduces your exposure as an employee. Instead of your employer and Slack having full access to everything you do on that account, now your employer has full access but Slack's access is reduced substantially. (If the setup is working as I expect, Slack will still get metadata.)

Re: Slack enables customers to control their encryption keys in enterprise version

#16
post #3

At this point, between no encryption, horrible clients, mistreatment of irc users, and questionable corporate behavior there's nothing in Slack that's worth saving it for me. Superior free software alternatives exist that bring the same or better functionality while also giving the user full control.

What "questionable corporate behavior" are you referring to?

Re: Slack enables customers to control their encryption keys in enterprise version

#17
Out of curiosity, does Slack allow a single person multiple Screennames? I see a scenario where a single person can have different handles, so personal communication doesn't overlap with work related communication. But the article does not make that clear.

Re: Slack enables customers to control their encryption keys in enterprise version

#18
post #9
post #2

Reads more like "Hands over control to any customer that will pay for it." [1] I wonder if the UI shows the employees that their employers have the keys. [1] Edit: as opposed to only regulated customers. Also, there's an upcharge...you don't automatically get control.

There are industries where you have no expectation of privacy at work because all comms are required to be monitored and stored due to the law . So this new feature really enables them to serve these customers who operate under such laws.

Matrix allows encryption with only access by people in the room, and even since they joined.

Re: Slack enables customers to control their encryption keys in enterprise version

#20
post #14

I am not sure slack can ever meaningfully become encrypted while having persistence. All it takes is for a admin (or hacked admin account) to change the password of the target slack user and login as said user to view all their private messages. The encryption is mostly pointless as far as I can tell when all of it is circumvented by a changed password.

I thought it was rather difficult for an admin to view private messages on Slack? Last I checked you had to apply for this kind of access, on your own account.
Post reply on HN