Reads more like "Hands over control to any customer that will pay for it." [1] I wonder if the UI shows the employees that their employers have the keys. [1] Edit: as opposed to only regulated customers. Also, there's an upcharge...you don't automatically get control.
Are you saying you had some sort of presumption of privacy on a corporate Slack account? If you did, you had it in error. If I am reading this right, this actually reduces your exposure as an employee. Instead of your employer and Slack having full access to everything you do on that account, now your employer has full access but Slack's access is reduced substantially. (If the setup is working as I expect, Slack wil…
Slack enables customers to control their encryption keys in enterprise version
31–40 of 178 posts
Re: Slack enables customers to control their encryption keys in enterprise version
#32I am not sure slack can ever meaningfully become encrypted while having persistence. All it takes is for a admin (or hacked admin account) to change the password of the target slack user and login as said user to view all their private messages. The encryption is mostly pointless as far as I can tell when all of it is circumvented by a changed password.
I thought it was rather difficult for an admin to view private messages on Slack? Last I checked you had to apply for this kind of access, on your own account.
Re: Slack enables customers to control their encryption keys in enterprise version
#33Re: Slack enables customers to control their encryption keys in enterprise version
#34Isn't this just shifting partly your trust from Slack to Amazon?
Re: Slack enables customers to control their encryption keys in enterprise version
#35Re: Slack enables customers to control their encryption keys in enterprise version
#36I am not sure slack can ever meaningfully become encrypted while having persistence. All it takes is for a admin (or hacked admin account) to change the password of the target slack user and login as said user to view all their private messages. The encryption is mostly pointless as far as I can tell when all of it is circumvented by a changed password.
>All it takes is for a admin (or hacked admin account) to change the password of the target slack user and login as said user to view all their private messages. An admin cannot change a user's password. You can enable an account wide feature which allows admins to view all messages but that's separate and costs money. Also not what you described.
Also I'm pretty sure a Slack admin can change a user's email address, at which point they can trigger a password reset.
Re: Slack enables customers to control their encryption keys in enterprise version
#37Earlier quoted context omitted.
Are you saying you had some sort of presumption of privacy on a corporate Slack account? If you did, you had it in error. If I am reading this right, this actually reduces your exposure as an employee. Instead of your employer and Slack having full access to everything you do on that account, now your employer has full access but Slack's access is reduced substantially. (If the setup is working as I expect, Slack wil…
I don't know slack internals. but I assume the employer having the key means that they now have a way to rewrite history in a way that looks cryptographically correct.
Re: Slack enables customers to control their encryption keys in enterprise version
#38I am not sure slack can ever meaningfully become encrypted while having persistence. All it takes is for a admin (or hacked admin account) to change the password of the target slack user and login as said user to view all their private messages. The encryption is mostly pointless as far as I can tell when all of it is circumvented by a changed password.
>All it takes is for a admin (or hacked admin account) to change the password of the target slack user and login as said user to view all their private messages. An admin cannot change a user's password. You can enable an account wide feature which allows admins to view all messages but that's separate and costs money. Also not what you described.
The reality is that IT administrators are the root of trust at all organizations. This new feature doesn't change that.
Re: Slack enables customers to control their encryption keys in enterprise version
#39Reads more like "Hands over control to any customer that will pay for it." [1] I wonder if the UI shows the employees that their employers have the keys. [1] Edit: as opposed to only regulated customers. Also, there's an upcharge...you don't automatically get control.
Are you saying you had some sort of presumption of privacy on a corporate Slack account? If you did, you had it in error. If I am reading this right, this actually reduces your exposure as an employee. Instead of your employer and Slack having full access to everything you do on that account, now your employer has full access but Slack's access is reduced substantially. (If the setup is working as I expect, Slack wil…
Slack grew because employees like me convinced their employers to start using it. The same people can also convince their companies to drop Slack and use something else.
> If I am reading this right, this actually reduces your exposure as an employee. Instead of your employer and Slack having full access to everything you do on that account, now your employer has full access but Slack's access is reduced substantially. (If the setup is working as I expect, Slack will still get metadata.)
It kinda sounds like you're saying that the employee has responsibility for data on Slack if there is a security breach at Slack. Either way, Slack has little interest in spying on employees and sowing discord.
Re: Slack enables customers to control their encryption keys in enterprise version
#40Earlier quoted context omitted.
Are you saying you had some sort of presumption of privacy on a corporate Slack account? If you did, you had it in error. If I am reading this right, this actually reduces your exposure as an employee. Instead of your employer and Slack having full access to everything you do on that account, now your employer has full access but Slack's access is reduced substantially. (If the setup is working as I expect, Slack wil…
I don't know slack internals. but I assume the employer having the key means that they now have a way to rewrite history in a way that looks cryptographically correct.
Slack is not the tool you'd want to use for anything but the most innocent work-related messages.
For that it is kind of usable, not good but one of the better that will get approved by management.