Live data from Hacker News

Slack enables customers to control their encryption keys in enterprise version

techcrunch.com

61–70 of 178 posts

Re: Slack enables customers to control their encryption keys in enterprise version

#61
post #33

This is a good thing for computing freedom: it puts more control in the hands of customers instead of requiring them to outsource encryption to Slack. It's a small step, since it's Amazon KMS and since presumably Slack still sees cleartext in transit. But it goes in the direction of restoring the security profile that a customer did when they ran their own internal IRC server, and that's a good thing.

The article says it’s only open to enterprise customers. Computing freedom you have to pay a ton for is not really freedom. It’s really not even close to the control of IRC.

It's pretty clear many customers don't want control, they want features, and irc lacks those.

Re: Slack enables customers to control their encryption keys in enterprise version

#62

Earlier quoted context omitted.

If you really want encryption with only access by the people in the room, you can use Matrix: it's not based on your password, but on the keys. If you have your keys (and encryption has been enable in the room), you and only you/your devices can read the messages.

So if someone else changes the password it doesnt show them? What if you legitimately chang your own password how does that work? I think I like the proof concept from Keybase unfortunately their name makes it sound like an SSH key repo and not an all in one chat and file sharing service. Also not quite as open as Matrix in the sense that people can choose other servers.

Right, the encryption isn't based on the password, but on encryption keys that are only on your devices. If you want to add a new device, you share the keys from one of your other devices to that new device. But just being able to log into an account (say by having the password) on a new device doesn't give any way to get the keys/read the encrypted messages.

Re: Slack enables customers to control their encryption keys in enterprise version

#63

Earlier quoted context omitted.

I thought it was rather difficult for an admin to view private messages on Slack? Last I checked you had to apply for this kind of access, on your own account.

They are only secure so far as everyone in the DM or private channel is employed. The company can always take over old accounts and get access to DMs that way.

If everyone has to use corporate email addressees they could just take over the emails temporarily to reset the password. If they really cared they could do so without the user ever knowing. They could also put language in their employee handbook or contract saying that you have to give them your password and fire for refusing... however, I fail to see how any of this is an issue since this is the company Slack and they have the right to see how people are using it.

Re: Slack enables customers to control their encryption keys in enterprise version

#64

Only available for an "additional fee" for Enterprise users. Cheeky. Also, Slack, I'd like a native MacOS app please.

It's only needed by large, highly regulated businesses, and it only works for self-hosting obviously.

Re: Slack enables customers to control their encryption keys in enterprise version

#65
post #48

The most surprising thing about this article isn't the article; its the comments in here, and the surprising number of people who have no clue how Slack works or how corporate/enterprise regulation & compliance works.

I have no idea how corporate/enterprise regulation & compliance works in relation to Slack. Could you elaborate?

I would suspect it is something along the lines that don't expect any privacy at work unless you are in the restroom typing on your phone and not using the company's WiFi.

Re: Slack enables customers to control their encryption keys in enterprise version

#66

Earlier quoted context omitted.

If you really want encryption with only access by the people in the room, you can use Matrix: it's not based on your password, but on the keys. If you have your keys (and encryption has been enable in the room), you and only you/your devices can read the messages.

So if someone else changes the password it doesnt show them? What if you legitimately chang your own password how does that work? I think I like the proof concept from Keybase unfortunately their name makes it sound like an SSH key repo and not an all in one chat and file sharing service. Also not quite as open as Matrix in the sense that people can choose other servers.

Correct, it won't show if you change your password. For legitimate uses, you export your session keys prior to changing your password.

In Riot (the most prominent Matrix client), you need to log out to change your password. In the current version, you're warned to export your keys if you want to maintain the logs from any encrypted conversations.

Re: Slack enables customers to control their encryption keys in enterprise version

#67
post #56

Earlier quoted context omitted.

As opposed to the headline, which implies it might be available to only regulated entities, yes.

it actually says "regulated customers"

Yes. It says:

"hands over control...to regulated customers"

It hands over control to ANY customer, not just regulated ones. And only to those that pay the upcharge.

Just seems oddly worded.

Re: Slack enables customers to control their encryption keys in enterprise version

#68
post #48

The most surprising thing about this article isn't the article; its the comments in here, and the surprising number of people who have no clue how Slack works or how corporate/enterprise regulation & compliance works.

I have no idea how corporate/enterprise regulation & compliance works in relation to Slack. Could you elaborate?

Mostly just a very simple point: If you're an employee at a company, you have practically no right or expectation of privacy (applicable to this conversation).

There are a few people in these comments saying things like "but the employer can still read your messages" or "companies should adopt matrix because it can do true E2E encryption of DMs between just the people in the room." That'll never happen in a typical corporate setting.

Re: Slack enables customers to control their encryption keys in enterprise version

#69
post #48

The most surprising thing about this article isn't the article; its the comments in here, and the surprising number of people who have no clue how Slack works or how corporate/enterprise regulation & compliance works.

"Bro, just write the app, let me worry about the rest!"

Re: Slack enables customers to control their encryption keys in enterprise version

#70
post #54
post #48

The most surprising thing about this article isn't the article; its the comments in here, and the surprising number of people who have no clue how Slack works or how corporate/enterprise regulation & compliance works.

"the surprising number of people who have no clue how Slack works or how corporate/enterprise regulation & compliance works" Why would this be surprising? Most of us have probably never cared to think about these subjects. Your comment would be a lot more useful it contained some information about these subjects instead of just expressing your shock that some people don't know things that you do. edit: I guess this i…

Many corporate/enterprise environments, in particular those involved in regulated activities (e.g. finance) require visibility of all work-related communications, to ensure employees aren't committing any crimes.

This isn't limited to, but includes monitoring of all activities when on work properties. Video cameras, desktop monitoring, HTTPS interception, IM logging and phone recording, and more.

EDIT: as other comments have pointed out, this essentially boils down to "do not expect any privacy at work" (you have no privacy on employer owned devices) and "do not do any work on devices you expect privacy on" (your employer will install their middleware on your devices, or you may be violating laws)

Post reply on HN