Live data from Hacker News

How 18F handles information security and third party applications

18f.gsa.gov

11–16 of 16 posts

Re: How 18F handles information security and third party applications

#11
post #5

The world needs a self-hosted Slack.

Check out Mattermost. Sadly missing some enterprise-friendly features like SAML auth as yet.

+1 on Mattermost, pretty easy to get setup. It's not quite a slick on the integration side but still pretty solid.

Re: How 18F handles information security and third party applications

#12
post #2

This does not address the core complaint from the breach[1]: > 18F’s use of both OAuth 2.0 and Slack is not in compliance with GSA’s Information Technology Standards Profile, GSA Order CIO P 2160.1E. The order allows information technologies to be approved for use in the GSA IT environment if they comply with GSA’s security, legal, and accessibility requirements. Currently, neither OAuth 2.0 nor Slack are approved fo…

From what I have seen the government has approved and prefers SAML over OAuth intentionally.

Re: How 18F handles information security and third party applications

#13
One of the huge risks of using multiple cloud services is that you can't firewall between them effectively. If Slack and Google Docs were in-house applications, they never would have been allowed to talk to each-other without an explicit review and firewall rule.

We are giving up defense in depth for ease of use SaaS.

Re: How 18F handles information security and third party applications

#16
post #5

The world needs a self-hosted Slack.

Check out Mattermost. Sadly missing some enterprise-friendly features like SAML auth as yet.

Rocket.Chat comes with SAML out of the box, and it is not an enterprise only feature.
Post reply on HN