Live data from Hacker News

Slack enables customers to control their encryption keys in enterprise version

techcrunch.com

121–130 of 178 posts

Re: Slack enables customers to control their encryption keys in enterprise version

#121
post #103

The title of this post makes it sound like a bad thing, but in regulated industries like Finance, firms are required to produce chat transcripts of the traders to regulators. Slack would be unusable in this industry if the firms could not capture all of the chat logs.

Funny because I know large financial companies that have been using Slack for years.

I believe you can still provide chat transcripts from Slack without managing keys yourself.

Re: Slack enables customers to control their encryption keys in enterprise version

#122

Earlier quoted context omitted.

The article says it’s only open to enterprise customers. Computing freedom you have to pay a ton for is not really freedom. It’s really not even close to the control of IRC.

It’s still their product. You have the freedom to not pay for it and use whatever alternative you want or build your own.

It should be noted that once the Network effect [0] takes place, it becomes less about freedom to build your own software and more about the cost (including - maybe especially - intangible) and viability of doing so.

If the problem is "this user is unsatisfied with this product', the solution is not necessarily to tell them to build their own [1]. We, as people, are allowed to criticize (hopefully constructively) products that have flaws in them even while using said software.

[0] https://en.wikipedia.org/wiki/Network_effect

[1] https://en.wikipedia.org/wiki/False_dilemma

Re: Slack enables customers to control their encryption keys in enterprise version

#123

Earlier quoted context omitted.

Sure, but that fixes it for you, not anyone else. What's the point when the person you're talking to went offline because they went through a tunnel or momentarily closed their laptop when you sent the message? This classic HN idea that people only use Slack over IRC because it looks better/easier is a reminder of nerd hubris that prevents one from understanding people and products.

Not sure I follow. The first to options I provided fix it for everyone.

What I mean is that everyone you talk to has to opt in to it too.

I personally pay $50/year to irccloud.com for these features. Nobody else does. Every day I get the pleasant IRC experience of sending someone a message after they've parted or "hey I got d/c, what did you say again?"

Slack and Discord coming out of the box with a fix for this for everyone is one of their fundamental community-building advantages over IRC.

Re: Slack enables customers to control their encryption keys in enterprise version

#124

Earlier quoted context omitted.

Not true, Slack is actually pretty far behind on terms of features. It is true that people like the better looking, easier to use technology however.

IRC doesn't even have the only feature I care about: the native ability to see messages sent while I was logged out. And no, I don't want to run my own bouncer, and I don't want people running their own insecure bouncers across my company. Yes, I could use something like IRCCloud but that requires another account and I'm tied to their client unless I pay[1] https://www.irccloud.com/faq#faq-bnc

If you want those features but are unwilling to run a bouncer or use irccloud, you’re correct, Slack is the best offering for you. But I’m wondering: why Slack and not IRCCloud if that’s the feature that matters to you?

Re: Slack enables customers to control their encryption keys in enterprise version

#125

Earlier quoted context omitted.

Not sure I follow. The first to options I provided fix it for everyone.

What I mean is that everyone you talk to has to opt in to it too. I personally pay $50/year to irccloud.com for these features. Nobody else does. Every day I get the pleasant IRC experience of sending someone a message after they've parted or "hey I got d/c, what did you say again?" Slack and Discord coming out of the box with a fix for this for everyone is one of their fundamental community-building advantages over…

If they implemented one of the first two front-ends I linked, you would know what the message was and would not have to ask your friends to repeat The only people that opt-in are the IRC server infrastructure engineers. End users just connect to the web front end. The first two links turn your IRC servers into a Slack clone, except with more or less features. This is certainly non-trivial to set up and maintain and end users would not implement this. They are just consumers of it.

Re: Slack enables customers to control their encryption keys in enterprise version

#126

Only available for an "additional fee" for Enterprise users. Cheeky. Also, Slack, I'd like a native MacOS app please.

It's only needed by large, highly regulated businesses, and it only works for self-hosting obviously.

Is that obvious? Using AWS you delegate access to KMS keys to other accounts.

Re: Slack enables customers to control their encryption keys in enterprise version

#127
post #103

The title of this post makes it sound like a bad thing, but in regulated industries like Finance, firms are required to produce chat transcripts of the traders to regulators. Slack would be unusable in this industry if the firms could not capture all of the chat logs.

Funny because I know large financial companies that have been using Slack for years.

Not all roles require the same level of audit. In general for simplicity, an entire firm will use one system that just applies the same policies for everyone, but a dev building a web interface for an internal risk tool will not be under the same requirements as a sales trader talking to clients and taking orders to execute in the market on their behalf.

Re: Slack enables customers to control their encryption keys in enterprise version

#128

Isn't this just shifting partly your trust from Slack to Amazon?

Enterprise customers want the ability to pull their keys and walk away from a platform, sometimes with very little notice.

A made-up example: assuming Brexit occurs, EU customers of a London-based SaaS chat service may no longer wish to keep that data outside of the EU. The easiest way to wipe it out quickly? Pull the key. Or perhaps your government is trying to compel you to produce data that you believe they have no right to. Some companies would rather have the option to destroy it and face the consequences, whatever they may be.

Re: Slack enables customers to control their encryption keys in enterprise version

#129

Earlier quoted context omitted.

What I mean is that everyone you talk to has to opt in to it too. I personally pay $50/year to irccloud.com for these features. Nobody else does. Every day I get the pleasant IRC experience of sending someone a message after they've parted or "hey I got d/c, what did you say again?" Slack and Discord coming out of the box with a fix for this for everyone is one of their fundamental community-building advantages over…

If they implemented one of the first two front-ends I linked, you would know what the message was and would not have to ask your friends to repeat The only people that opt-in are the IRC server infrastructure engineers. End users just connect to the web front end. The first two links turn your IRC servers into a Slack clone, except with more or less features. This is certainly non-trivial to set up and maintain and e…

Now I don't understand. I'm clearly talking about other people (everyone else but you), not the nerd running irssi on a VPS nor thelounge.

In other words, IRC isn't worse than Slack/Discord in this regard because you have to opt-in to these things. It's worse because everyone else has to, and they clearly don't.

For example, that I pay $50 to irccloud but nobody else does still makes IRC a poor experience for me because IRC is about communicating with other people, not masturbating over my irssi config.

Re: Slack enables customers to control their encryption keys in enterprise version

#130

Earlier quoted context omitted.

Funny because I know large financial companies that have been using Slack for years.

I believe you can still provide chat transcripts from Slack without managing keys yourself.

and you can still intercept all the SSL if you just roll out your own certs to all the workstations and the firewall opens everything..
Post reply on HN