Live data from Hacker News

What If All Your Slack Chats Were Leaked?

nytimes.com

121–127 of 127 posts

Re: What If All Your Slack Chats Were Leaked?

#121
post #117

I worked at a company that uses Slack as its main casual communication medium. One day, I walked into a meeting to learn that I was being fired without warning, and would have absolutely no opportunity from that moment forward to log in to any of my business-related accounts. That sudden unexpected contextual change really puts the lack of privacy control into perspective. Suddenly, all the conversations that I had h…

I don't think the firing changed anything, though. You have to assume your employer had access to your chats already. And emails, etc. Your net privacy didn't change.

Two things changed drastically:

1. My access to that record. I can no longer audit or edit that information. Even though I made a constant effort to preserve my privacy, I am left with a worrying lack of certainty. After all, I can't be expected to remember many months worth of communication, or what out of that I may find concerning in this new context.

2. My relationship with my (ex) employer. Sure I could have assumed an eventual change in that relationship from the beginning, but it's still drastic to have that change come suddenly and without warning.

I realize those are subtle, and that - hopefully - they do not become an issue. I only want to highlight my experience, because I found it eye opening.

The real issue is that there is an informal expectation of privacy without the user having permanent control over his/her information.

Re: What If All Your Slack Chats Were Leaked?

#122

Anonimnity is fake. Assume your conversations in Slack are reviewed, don't be mean and sneaky, and you're all set. If you're a true dick irl, Slack will only serve to magnify that fact.

> and you're all set

Except the desire for privacy isn't limited to the rude things you say.

None of us truly wants to live in a world where a third party can secretly review a permanent record of our communications.

Re: What If All Your Slack Chats Were Leaked?

#123
post #66

Earlier quoted context omitted.

> What if all your search history were leaked? What if all your text messages were leaked? What if all your emails were leaked? But I can directly go into all those things and delete at least my copies of them. Even with as many problems as Google and Facebook have, it's relatively straightforward to see the entire history of what I have on their sites and delete it. > As usual, it's not that serious, and there isn't…

No, you absolutely can't delete your search history, which Google stores in perpetuity, and you can't delete the copies of your SMS messages that sit on some server somewhere, probably forever. All you can do is make it inaccessible in the app or web page you as the user can view it from.

Everything they have published shows that you can delete search history, among other things. They recently released a feature which is effectively a TTL on searches, for retention purposes.

Re: What If All Your Slack Chats Were Leaked?

#124
post #40

Earlier quoted context omitted.

They could, but I don't think it would really add much benefit. One of the main features of Slack vs IRC is that Slack has persistent and consistent chat history. If you look at apps like Signal, when you log on from a new device your history isn't available, because of the end to end encryption used to store the messages. To view the history you would have to be able to decrypt it, but that means there has to be som…

In iMessage this was possible but all combinations of pairs of your devices had their own keys. When a new device was added you needed to allow it from a device already registered and they would then sync messages device-to-device. This has resulted in quite a lot of mangled histories. Now with iMessage in iCloud, I do not know how the E2E encryption is done.

>Now with iMessage in iCloud, I do not know how the E2E encryption is done

It isn't done. Apple holds the master keys. The trust is that the iCloud server is not compromised.

Re: What If All Your Slack Chats Were Leaked?

#125
post #40

Earlier quoted context omitted.

In iMessage this was possible but all combinations of pairs of your devices had their own keys. When a new device was added you needed to allow it from a device already registered and they would then sync messages device-to-device. This has resulted in quite a lot of mangled histories. Now with iMessage in iCloud, I do not know how the E2E encryption is done.

>Now with iMessage in iCloud, I do not know how the E2E encryption is done It isn't done. Apple holds the master keys. The trust is that the iCloud server is not compromised.

I've read some discussions and key base articles and it seems that at least the master key is encrypted using your pin code. Not much, but I guess one could use a complex password.

Re: What If All Your Slack Chats Were Leaked?

#126
post #125

Earlier quoted context omitted.

>Now with iMessage in iCloud, I do not know how the E2E encryption is done It isn't done. Apple holds the master keys. The trust is that the iCloud server is not compromised.

I've read some discussions and key base articles and it seems that at least the master key is encrypted using your pin code. Not much, but I guess one could use a complex password.

Care to cite? I'm curious

Re: What If All Your Slack Chats Were Leaked?

#127
post #125

Earlier quoted context omitted.

I've read some discussions and key base articles and it seems that at least the master key is encrypted using your pin code. Not much, but I guess one could use a complex password.

Care to cite? I'm curious

https://support.apple.com/en-us/HT202303

> Messages in iCloud also uses end-to-end encryption. If you have iCloud Backup turned on, your backup includes a copy of the key protecting your Messages. This ensures you can recover your Messages if you lose access to iCloud Keychain and your trusted devices. When you turn off iCloud Backup, a new key is generated on your device to protect future messages and isn't stored by Apple.

https://pxlnv.com/linklog/improving-imessage-encryption/

> During an interview with Apple blogger and Daring Fireball’s owner John Gruber, Federighi said that the company has figured out a way to do syncing while still remaining unable to read your iMessages.

Post reply on HN