Live data from Hacker News

What If All Your Slack Chats Were Leaked?

nytimes.com

41–50 of 127 posts

Re: What If All Your Slack Chats Were Leaked?

#42
post #7

Earlier quoted context omitted.

Since when is not encrypting what could be sensitive communication ""isn't a problem here"?

Edit: I should have pointed out that the article doesn't say they don't encrypt the data, it just says they don't end-to-end encrypt it, which by definition would require it to be impossible for Slack or anyone else to read the messages (other than the users who sent them or were in the channel at the time they were sent). Only a handful or recent apps like Signal and Telegram even attempt to do this. Any form of com…

I think the fact that Slack communication isn't encrypted is a valid news article.

I don't think that because the topic is "hot" that makes talking about it "no reason other than".

I feel like there is a surprising volume of "oh man why did the author bring this up" type posts on HN, I don't get it. The topic seems valid.

Re: What If All Your Slack Chats Were Leaked?

#43

The single most terrible thing about Slack is the hostage holding of message archives. You don’t pay? Fine...you get 10k message history, no ability to set retention and Slack still stores all those messages forever, taunting me that they have it all and won’t let me do anything with them. That’s just user hostile. If I don’t pay, I shouldn’t have all that message history stored forever. Either let me set retention o…

It was sort of helpful for us. We (a bootstrapped small business) remained on the free tier for a few years before upgrading and getting access to all history.

We might not have bothered if the history was simply deleted. I was grateful they didn't as there are some great moments in there, i.e. our first invoice, announcement of our first member of staff, prototype renders, etc.

Re: What If All Your Slack Chats Were Leaked?

#44

What if all your search history were leaked? What if all your text messages were leaked? What if all your emails were leaked? I guess those things aren't trendy enough to worry about. For a long time I have noticed what I would call 'ankle biting journalism'. Basically take whatever is trendy, make only the most obvious observations about it (things that someone who only rudimentary knowledge would come up with in a…

> Then Slack is about as secure as IRC, which is exactly what it is trying to be, IRC 'but better'.

Anything I write on IRC I assume is public. Not so with Slack, where much is written in DMs.

The email comparison is more apt.

Re: What If All Your Slack Chats Were Leaked?

#45
once worked for a start-up that went through a high amount of churn and employee turnover. one of the pain points was the know-how being locked inside Slack threads and we had hit the 10K message limit months before I joined. The place was also politically toxic and the CEO was mostly the cause of this. Initially when I had still some passion left I suggested to move Slack to a self-hosted Zulip installation (threaded topics FTW) because the CEO constantly complained about having to pay for Slack subscription and he was totally against this as somebody who believes in FOSS.

After getting this Zulip migration approved the CEO pulled the plug in the last minute because he realized during a discussion about how to handle the import of the original messages - that all the old (toxic) discussions would now be in the hands of his internal employees and they couldn't be trusted not reading all the shit him and everyone else said behind each others back.

This made me aware that Slack has some interesting reasons for why teams are locked into their SaaS platform which may have nothing to do with scalability or uptime. In our case it was fear of libel lawsuits and further turnover. While you might be able to live with the insider-threat at SlackHQ with them being able to read your messages, sometimes the idea that anyone in your IT can read everything management has said shared or discussed in the past may be too risky for most.

Re: What If All Your Slack Chats Were Leaked?

#46
post #26

I mean, the article is generally right but they immediately get a detail wrong: > Right now, Slack stores everything you do on its platform by default — your username and password ... I would be extremely surprised if they store plaintext or even encrypted passwords. Maybe the author means usernames/passwords sent in messages, but that's not unique to slack.

If they don't store the password encrypted or in plaintext, how would they be able to authenticate you? It must be stored somehow, either plaintext or encrypted (preferred).

Hashed.

An encrypted password can be reversed, a hashed password cannot, it can only be verified. An encrypted password is only slightly preferable to a plaintext one because you still need to store the password somewhere, which am attacker would theoretically have access to, so it mostly serves as obfuscation.

Re: What If All Your Slack Chats Were Leaked?

#47
post #7

Earlier quoted context omitted.

Since when is not encrypting what could be sensitive communication ""isn't a problem here"?

So, I think this is a problem and that encryption and data security policies and audits would be a good thing. But your parent's point also resonated with me. This isn't a shocking expose of some giant new problem. Protecting proprietary communication has been a problem for as long as organizations have existed. It was a problem when the solution at Los Alamos was safes in offices, it was a problem with memos, it was…

What qualifies as news?

Does it have to be " a shocking expose"?

All the things you mentioned about communication seem to apply to this article.

Re: What If All Your Slack Chats Were Leaked?

#48
post #16

What if all your search history were leaked? What if all your text messages were leaked? What if all your emails were leaked? I guess those things aren't trendy enough to worry about. For a long time I have noticed what I would call 'ankle biting journalism'. Basically take whatever is trendy, make only the most obvious observations about it (things that someone who only rudimentary knowledge would come up with in a…

"In hindsight, complying with the company's Document Retention Policy (which at Netscape was basically, ``shred anything within 90 days unless you can't get your job done without it'') might have been a good idea." [1] Do companies no longer have Document Retention Policies? That seems like the bigger piece of the story here. [1] https://www.jwz.org/gruntle/rbarip.html

FYI if you're referred from hackernews and have never visited the site before, the jwz links redirect to (somewhat nsfw: photoshopped testicle in an egg cup) http://i.imgur.com/32R3qLv.png.

Re: What If All Your Slack Chats Were Leaked?

#49
post #26

I mean, the article is generally right but they immediately get a detail wrong: > Right now, Slack stores everything you do on its platform by default — your username and password ... I would be extremely surprised if they store plaintext or even encrypted passwords. Maybe the author means usernames/passwords sent in messages, but that's not unique to slack.

If they don't store the password encrypted or in plaintext, how would they be able to authenticate you? It must be stored somehow, either plaintext or encrypted (preferred).

[deleted]

Re: What If All Your Slack Chats Were Leaked?

#50

I've been spending all these years holding my tongue because as a matter of principal I don't write anything I don't want a permanent record of and it would be nice to see all that overhead pay off or more accurately, it would be nice to see people get burned for being sloppy. So no, I wouldn't really stand to lose anything if everything I ever said on company chat was published in an easily searchable format online.

Trust me, you have something buried in there that would make you look less than stellar out of context.
Post reply on HN