Original email sent to Slack users:
https://gist.github.com/anonymous/a26e3279dd57be3363b3What the email might sound like if Slack was being completely forthright:
---
Dear User,
We are writing to inform you that our servers have been broken into and that the personal information of our 500,000 users (including you) has been stolen. This information was likely swiped by either the bad guys (thieves) and will be sold on the darknet, or by the bad guys (NSA) and will be used in their efforts to build a global surveillance state.[1] We have since tried to block this unauthorized access and made additional (but nebulous) changes to our technical infrastructure in an attempt to prevent future PR headaches. No specific action is required of you - nor is there anything you can do to reverse your lost privacy.
However, our PR department is extremely worried that this news might damage our 2.76 billion dollar valuation.[2] Since we have been working on a sexy (but completely unrelated) security feature for a while, we decided to release it early. We intentionally conflated the fact that our servers got hacked with a new user-space security feature in an effort to obfuscate how badly we screwed up.
The breach happened in February but it has taken us till the end of March to get this new feature usable.[3] (If you are asking yourself why we would release a half-baked security feature, just remember, we are the company that just accidentally released personal information belonging to you and half a million other people.)
We are hoping that by making just the the paragraph about this new feature BOLD many users might miss what really happened. We also hope that by "strongly recommending" that you enable this feature, the blame for this security blunder is shifted to our customers, as if this could somehow be prevented by enabling this feature. Additional misdirection is available in our help center.
[1] https://www.eff.org/nsa-spying
[2] http://blogs.wsj.com/digits/2015/03/26/slacks-valuation-more...
[3] http://slackhq.com/post/114696167740/march-2015-security-inc...