Live data from Hacker News

Zulip Cloud security vulnerability with reusable invitation links

blog.zulip.com

11–20 of 38 posts

Re: Zulip Cloud security vulnerability with reusable invitation links

#11

Is anyone using Zulip and has it made a difference to Slack for example?

We use it at work. We first switched over to Mattermost, then to Zulip. Mattermost seemed like a clone of Slack and we were initially "satisfied", but didn't see it get improved that much nor noticed any attempts of it trying to tackle other problems. Then they raised their prices to even higher than Slack's, which we took as a bit of dick move seeing as we were self-hosting it + it has nowhere near the experience of Slack. Push notifications in general didn't seem to be that good.

Zulip has a nice spin on the way discussions work with their concept of "topics". It lends itself well to how we conceptualize the discussions across our development teams, without unnecessarily creating many ad-hoc temp channels (something we'd have done on Slack). We're liking it thus far. That being said I do need to check why it's using about 35 gigs of RAM on our server.

Re: Zulip Cloud security vulnerability with reusable invitation links

#12

Is anyone using Zulip and has it made a difference to Slack for example?

I briefly used Zulip as part of a friend's community, rather than work. My experience with it was that it's great at first, but when you start to get masses of messages and users, the client becomes laggy and unresponsive. Scrolling through messages particularly sucked because of this.

I'm not sure if it was just our setup, because when I checked the official Zulip web chat, I had the same problem.

Re: Zulip Cloud security vulnerability with reusable invitation links

#13
post #11

Is anyone using Zulip and has it made a difference to Slack for example?

We use it at work. We first switched over to Mattermost, then to Zulip. Mattermost seemed like a clone of Slack and we were initially "satisfied", but didn't see it get improved that much nor noticed any attempts of it trying to tackle other problems. Then they raised their prices to even higher than Slack's, which we took as a bit of dick move seeing as we were self-hosting it + it has nowhere near the experience of…

35 gigabytes?! How many people are using that thing?

Re: Zulip Cloud security vulnerability with reusable invitation links

#14

Is anyone using Zulip and has it made a difference to Slack for example?

We use it at our small (15 person) startup. I like that topics are light weight, like git branches, but despite that we struggle to use them effectively (generally dumping thoughts in a select few topics)

One major quirk of the interface is that can be difficult to, at a glance, identify what topic/dm you are actively on, which has lead to a handful of "Oops, what was supposed to be a DM" message deletes.

Re: Zulip Cloud security vulnerability with reusable invitation links

#17

Is anyone using Zulip and has it made a difference to Slack for example?

Personally, I like Zulip way better than Slack because of how it does message threads: _channels_ that have conversations in _topics_ "makes sense" to me.

Pros: Server maintenance is blissfully minimal. Message threading that actually works. No server issues or downtime in the past 4 years. (Every time I see a HN "Slack is down" posting, I smile to myself and continue my work day...) It runs great for ~50 employees on an AWS t3a.large instance. Importing all the company's previous messages from Slack worked perfectly.

Cons: If you have people used to Slack, there will be resistance / a learning curve. Knowing, "when do I create a topic?" takes practice. The mobile and desktop apps are not as polished as Slack's. Not as many integrations as Slack. You have to know enough to manage and secure a server yourself.

The Zulip devs accept Github donations, btw, if anyone cares to support their work. (We do; no affiliation other than we're happy to have a private, self-hosted alternative.)

edits: punctuation and adding that instance was a ".large"

Re: Zulip Cloud security vulnerability with reusable invitation links

#18

Is anyone using Zulip and has it made a difference to Slack for example?

We use it at our small (15 person) startup. I like that topics are light weight, like git branches, but despite that we struggle to use them effectively (generally dumping thoughts in a select few topics) One major quirk of the interface is that can be difficult to, at a glance, identify what topic/dm you are actively on, which has lead to a handful of "Oops, what was supposed to be a DM" message deletes.

We’ve struggled with that in the past as well, but it got better over time. One thing that helps is to aggressively start moving messages to new topics once things go beyond a few in a general topic.

Re: Zulip Cloud security vulnerability with reusable invitation links

#19

Is anyone using Zulip and has it made a difference to Slack for example?

We used Zulip at $job[-1] and it was awfully painful. I’ve used nearly every chat client invented since the BBS days, and Zulip was one of my least favorite. We’re using Slack now at $job and I vastly prefer it (even though I still call it “IRC”).

The biggest selling points of Zulip, from the POV of the people who put it in place and truly loved it, were that it’s free/OS software, it has explicit threads as a first class citizen, and that it’s very configurable. All those things are true.

The day-to-day use was painful, though. It was riddled with UX problems, e.g., forgetting state between restarts, inconsistent hotkey support, multi-action use paths for common cases, frequent full reloads of its web view. I’d much rather use vanilla IRC than Zulip.

Slack is just enough of a shim layer on IRC, and with good usability. It has threads, and in use it’s not a problem that you can’t name them like Zulip. The integrations are nice to have (e.g., type `/zoom` to start a Zoom meeting) but not a big deal. The UX is clear and predictable and (mostly) stays out of my way.

Re: Zulip Cloud security vulnerability with reusable invitation links

#20
post #11

Earlier quoted context omitted.

We use it at work. We first switched over to Mattermost, then to Zulip. Mattermost seemed like a clone of Slack and we were initially "satisfied", but didn't see it get improved that much nor noticed any attempts of it trying to tackle other problems. Then they raised their prices to even higher than Slack's, which we took as a bit of dick move seeing as we were self-hosting it + it has nowhere near the experience of…

35 gigabytes?! How many people are using that thing?

Only about ~40 users, so it's definitely an issue. Haven't investigated yet but this reminded me that we should.

(edit: actually it's now down to 17 gigs)

Post reply on HN