First thought: who the hell would be interested to read thousands of lines of discussions like how to name a field in REST response or notifications of someone making a build xD
What If All Your Slack Chats Were Leaked?
41–50 of 127 posts
Re: What If All Your Slack Chats Were Leaked?
#42Earlier quoted context omitted.
Since when is not encrypting what could be sensitive communication ""isn't a problem here"?
Edit: I should have pointed out that the article doesn't say they don't encrypt the data, it just says they don't end-to-end encrypt it, which by definition would require it to be impossible for Slack or anyone else to read the messages (other than the users who sent them or were in the channel at the time they were sent). Only a handful or recent apps like Signal and Telegram even attempt to do this. Any form of com…
I don't think that because the topic is "hot" that makes talking about it "no reason other than".
I feel like there is a surprising volume of "oh man why did the author bring this up" type posts on HN, I don't get it. The topic seems valid.
Re: What If All Your Slack Chats Were Leaked?
#43The single most terrible thing about Slack is the hostage holding of message archives. You don’t pay? Fine...you get 10k message history, no ability to set retention and Slack still stores all those messages forever, taunting me that they have it all and won’t let me do anything with them. That’s just user hostile. If I don’t pay, I shouldn’t have all that message history stored forever. Either let me set retention o…
We might not have bothered if the history was simply deleted. I was grateful they didn't as there are some great moments in there, i.e. our first invoice, announcement of our first member of staff, prototype renders, etc.
Re: What If All Your Slack Chats Were Leaked?
#44What if all your search history were leaked? What if all your text messages were leaked? What if all your emails were leaked? I guess those things aren't trendy enough to worry about. For a long time I have noticed what I would call 'ankle biting journalism'. Basically take whatever is trendy, make only the most obvious observations about it (things that someone who only rudimentary knowledge would come up with in a…
Anything I write on IRC I assume is public. Not so with Slack, where much is written in DMs.
The email comparison is more apt.
Re: What If All Your Slack Chats Were Leaked?
#45After getting this Zulip migration approved the CEO pulled the plug in the last minute because he realized during a discussion about how to handle the import of the original messages - that all the old (toxic) discussions would now be in the hands of his internal employees and they couldn't be trusted not reading all the shit him and everyone else said behind each others back.
This made me aware that Slack has some interesting reasons for why teams are locked into their SaaS platform which may have nothing to do with scalability or uptime. In our case it was fear of libel lawsuits and further turnover. While you might be able to live with the insider-threat at SlackHQ with them being able to read your messages, sometimes the idea that anyone in your IT can read everything management has said shared or discussed in the past may be too risky for most.
Re: What If All Your Slack Chats Were Leaked?
#46I mean, the article is generally right but they immediately get a detail wrong: > Right now, Slack stores everything you do on its platform by default — your username and password ... I would be extremely surprised if they store plaintext or even encrypted passwords. Maybe the author means usernames/passwords sent in messages, but that's not unique to slack.
If they don't store the password encrypted or in plaintext, how would they be able to authenticate you? It must be stored somehow, either plaintext or encrypted (preferred).
An encrypted password can be reversed, a hashed password cannot, it can only be verified. An encrypted password is only slightly preferable to a plaintext one because you still need to store the password somewhere, which am attacker would theoretically have access to, so it mostly serves as obfuscation.
Re: What If All Your Slack Chats Were Leaked?
#47Earlier quoted context omitted.
Since when is not encrypting what could be sensitive communication ""isn't a problem here"?
So, I think this is a problem and that encryption and data security policies and audits would be a good thing. But your parent's point also resonated with me. This isn't a shocking expose of some giant new problem. Protecting proprietary communication has been a problem for as long as organizations have existed. It was a problem when the solution at Los Alamos was safes in offices, it was a problem with memos, it was…
Does it have to be " a shocking expose"?
All the things you mentioned about communication seem to apply to this article.
Re: What If All Your Slack Chats Were Leaked?
#48What if all your search history were leaked? What if all your text messages were leaked? What if all your emails were leaked? I guess those things aren't trendy enough to worry about. For a long time I have noticed what I would call 'ankle biting journalism'. Basically take whatever is trendy, make only the most obvious observations about it (things that someone who only rudimentary knowledge would come up with in a…
"In hindsight, complying with the company's Document Retention Policy (which at Netscape was basically, ``shred anything within 90 days unless you can't get your job done without it'') might have been a good idea." [1] Do companies no longer have Document Retention Policies? That seems like the bigger piece of the story here. [1] https://www.jwz.org/gruntle/rbarip.html
Re: What If All Your Slack Chats Were Leaked?
#49I mean, the article is generally right but they immediately get a detail wrong: > Right now, Slack stores everything you do on its platform by default — your username and password ... I would be extremely surprised if they store plaintext or even encrypted passwords. Maybe the author means usernames/passwords sent in messages, but that's not unique to slack.
If they don't store the password encrypted or in plaintext, how would they be able to authenticate you? It must be stored somehow, either plaintext or encrypted (preferred).
Re: What If All Your Slack Chats Were Leaked?
#50I've been spending all these years holding my tongue because as a matter of principal I don't write anything I don't want a permanent record of and it would be nice to see all that overhead pay off or more accurately, it would be nice to see people get burned for being sloppy. So no, I wouldn't really stand to lose anything if everything I ever said on company chat was published in an easily searchable format online.