Live data from Hacker News

Slack enables customers to control their encryption keys in enterprise version

techcrunch.com

31–40 of 178 posts

Re: Slack enables customers to control their encryption keys in enterprise version

#31
post #15
post #2

Reads more like "Hands over control to any customer that will pay for it." [1] I wonder if the UI shows the employees that their employers have the keys. [1] Edit: as opposed to only regulated customers. Also, there's an upcharge...you don't automatically get control.

Are you saying you had some sort of presumption of privacy on a corporate Slack account? If you did, you had it in error. If I am reading this right, this actually reduces your exposure as an employee. Instead of your employer and Slack having full access to everything you do on that account, now your employer has full access but Slack's access is reduced substantially. (If the setup is working as I expect, Slack wil…

I don't know slack internals. but I assume the employer having the key means that they now have a way to rewrite history in a way that looks cryptographically correct.

Re: Slack enables customers to control their encryption keys in enterprise version

#32
post #14

I am not sure slack can ever meaningfully become encrypted while having persistence. All it takes is for a admin (or hacked admin account) to change the password of the target slack user and login as said user to view all their private messages. The encryption is mostly pointless as far as I can tell when all of it is circumvented by a changed password.

I thought it was rather difficult for an admin to view private messages on Slack? Last I checked you had to apply for this kind of access, on your own account.

They are only secure so far as everyone in the DM or private channel is employed. The company can always take over old accounts and get access to DMs that way.

Re: Slack enables customers to control their encryption keys in enterprise version

#33
This is a good thing for computing freedom: it puts more control in the hands of customers instead of requiring them to outsource encryption to Slack. It's a small step, since it's Amazon KMS and since presumably Slack still sees cleartext in transit. But it goes in the direction of restoring the security profile that a customer did when they ran their own internal IRC server, and that's a good thing.

Re: Slack enables customers to control their encryption keys in enterprise version

#35
post #4

Earlier quoted context omitted.

Which free alternatives?

Matrix, Mattermost, Rocket.Chat, and that's just off the top of my head. All three are free (as in speech) and aren't terribly hard to set up on-premise or spin up a container for somewhere else.

Zulip is a great choice, too.

Re: Slack enables customers to control their encryption keys in enterprise version

#36
post #14

I am not sure slack can ever meaningfully become encrypted while having persistence. All it takes is for a admin (or hacked admin account) to change the password of the target slack user and login as said user to view all their private messages. The encryption is mostly pointless as far as I can tell when all of it is circumvented by a changed password.

>All it takes is for a admin (or hacked admin account) to change the password of the target slack user and login as said user to view all their private messages. An admin cannot change a user's password. You can enable an account wide feature which allows admins to view all messages but that's separate and costs money. Also not what you described.

If you're using SSO, which almost every big customer does, you can usually do a password reset in the SSO itself.

Also I'm pretty sure a Slack admin can change a user's email address, at which point they can trigger a password reset.

Re: Slack enables customers to control their encryption keys in enterprise version

#37
post #31
post #15

Earlier quoted context omitted.

Are you saying you had some sort of presumption of privacy on a corporate Slack account? If you did, you had it in error. If I am reading this right, this actually reduces your exposure as an employee. Instead of your employer and Slack having full access to everything you do on that account, now your employer has full access but Slack's access is reduced substantially. (If the setup is working as I expect, Slack wil…

I don't know slack internals. but I assume the employer having the key means that they now have a way to rewrite history in a way that looks cryptographically correct.

That's not how it works. Just because you have the keys doesn't mean you have direct filesystem or database access to change what you please.

Re: Slack enables customers to control their encryption keys in enterprise version

#38
post #14

I am not sure slack can ever meaningfully become encrypted while having persistence. All it takes is for a admin (or hacked admin account) to change the password of the target slack user and login as said user to view all their private messages. The encryption is mostly pointless as far as I can tell when all of it is circumvented by a changed password.

>All it takes is for a admin (or hacked admin account) to change the password of the target slack user and login as said user to view all their private messages. An admin cannot change a user's password. You can enable an account wide feature which allows admins to view all messages but that's separate and costs money. Also not what you described.

I don't think that's true. In the corporate world, Slack is authenticated with AD/SAML/etc. and Slack has no idea who is changing passwords on that backend system.

The reality is that IT administrators are the root of trust at all organizations. This new feature doesn't change that.

Re: Slack enables customers to control their encryption keys in enterprise version

#39
post #15
post #2

Reads more like "Hands over control to any customer that will pay for it." [1] I wonder if the UI shows the employees that their employers have the keys. [1] Edit: as opposed to only regulated customers. Also, there's an upcharge...you don't automatically get control.

Are you saying you had some sort of presumption of privacy on a corporate Slack account? If you did, you had it in error. If I am reading this right, this actually reduces your exposure as an employee. Instead of your employer and Slack having full access to everything you do on that account, now your employer has full access but Slack's access is reduced substantially. (If the setup is working as I expect, Slack wil…

> Are you saying you had some sort of presumption of privacy on a corporate Slack account?

Slack grew because employees like me convinced their employers to start using it. The same people can also convince their companies to drop Slack and use something else.

> If I am reading this right, this actually reduces your exposure as an employee. Instead of your employer and Slack having full access to everything you do on that account, now your employer has full access but Slack's access is reduced substantially. (If the setup is working as I expect, Slack will still get metadata.)

It kinda sounds like you're saying that the employee has responsibility for data on Slack if there is a security breach at Slack. Either way, Slack has little interest in spying on employees and sowing discord.

Re: Slack enables customers to control their encryption keys in enterprise version

#40
post #31
post #15

Earlier quoted context omitted.

Are you saying you had some sort of presumption of privacy on a corporate Slack account? If you did, you had it in error. If I am reading this right, this actually reduces your exposure as an employee. Instead of your employer and Slack having full access to everything you do on that account, now your employer has full access but Slack's access is reduced substantially. (If the setup is working as I expect, Slack wil…

I don't know slack internals. but I assume the employer having the key means that they now have a way to rewrite history in a way that looks cryptographically correct.

Ok, lets just make this clear:

Slack is not the tool you'd want to use for anything but the most innocent work-related messages.

For that it is kind of usable, not good but one of the better that will get approved by management.

Post reply on HN