Live data from Hacker News

Guide to Slack import and export tools

get.slack.help

471–480 of 529 posts

Re: Guide to Slack import and export tools

#471
post #469

Earlier quoted context omitted.

You pick the law of one of the weakest privacy jurisdictions and argue that Slack should standardize privacy on most invasive level this country's law allows. What is this declaration of rights for corporate eavesdropping?

Why do you feel the need to defend Slack? It was their decision to do this to ensure they wouldn’t be forced out of the corporate market ($$$$$) and, I hate to break it to you, US and EU law are very similar in this regard. Corporations in the EU can listen to your business correspondence just as easily as US ones, and in neither do you have any real expectation of privacy at work.

You are wrong about the EU - the national legislation on right to privacy is stricter in many (most?) countries. EU only sets minimum levels of protection. And even EU law protects more than you imply(1).

I'm defending employee rights and generally the human right to privacy against arbitrary surveillance, not Slack.

(1) https://www.helpnetsecurity.com/2017/09/06/workplace-surveil...

Re: Guide to Slack import and export tools

#472
post #388

Earlier quoted context omitted.

> If two people want to have a private conversation You response is based on a false fact: that anything you use official company communication channels for should be considered private. HR functions can and will access such communication to investigate complaints about behaviour and similar. Compliance and legal functions can and will access such communication to investigate complaints relevant to them. They can, wi…

That is only according to some law systems though. It does not work like that at all in many European countries. For instance in France the employer cannot read any private conversation (mail/message) of the employee, even when using work email. And no internal rule can change that (it is a criminal offense). If the employer suspects a leak of information by the employee, they can read the message in presence of the…

> If the employer suspects a leak of information by the employee

or if they suspect any other illegal activity.

Even in EU countries where arbitrary inspection/monitoring is not permitted wholesale, there are exceptions where regulatory or other legal requirements trump privacy. Though often there needs to be sufficient suspicion of something worth looking for, I still wouldn't count that as a truly private channel (nor would I expect my employer to provide me with one).

Re: Guide to Slack import and export tools

#473
post #469

Earlier quoted context omitted.

Why do you feel the need to defend Slack? It was their decision to do this to ensure they wouldn’t be forced out of the corporate market ($$$$$) and, I hate to break it to you, US and EU law are very similar in this regard. Corporations in the EU can listen to your business correspondence just as easily as US ones, and in neither do you have any real expectation of privacy at work.

You are wrong about the EU - the national legislation on right to privacy is stricter in many (most?) countries. EU only sets minimum levels of protection. And even EU law protects more than you imply(1). I'm defending employee rights and generally the human right to privacy against arbitrary surveillance, not Slack. (1) https://www.helpnetsecurity.com/2017/09/06/workplace-surveil...

From the court case,

In particular, the national courts had failed to determine whether the applicant had received prior notice from his employer of the possibility that his communications might be monitored; nor had they had regard either to the fact that he had not been informed of the nature or the extent of the monitoring, or the degree of intrusion into his private life and correspondence. In addition, the national courts had failed to determine, firstly, the specific reasons justifying the introduction of the monitoring measures; secondly, whether the employer could have used measures entailing less intrusion into the applicant’s private life and correspondence; and thirdly, whether the communications might have been accessed without his knowledge.

There is nothing in that case that prohibits EU companies from monitoring the communications of their employees. Half of that case revolves around legal procedural problems in the original case, and the other half is about whether the company could have fired him over his personal correspondence _without proper notice_. That case, if anything, only upholds corporate EU rights to monitor their employees, so long as they provide some trivial legal notice.

yes, EU law does protect private correspondence more than US law, but almost none of that applies to business correspondence, and the EU is just as liberal in that regard as the US.

Re: Guide to Slack import and export tools

#474

IMHO I don't think this is a fair title change. What is important here is the fact that access to DMs have changed. Not that the general import/export tools have changed. If Google changed their TOS to suddenly make everyone's search history public, would the title read "Google changes TOS"?

I thought this was a totally new item, a lot of the comments don't make sense without the old title

Re: Guide to Slack import and export tools

#475
post #473

Earlier quoted context omitted.

You are wrong about the EU - the national legislation on right to privacy is stricter in many (most?) countries. EU only sets minimum levels of protection. And even EU law protects more than you imply(1). I'm defending employee rights and generally the human right to privacy against arbitrary surveillance, not Slack. (1) https://www.helpnetsecurity.com/2017/09/06/workplace-surveil...

From the court case, In particular, the national courts had failed to determine whether the applicant had received prior notice from his employer of the possibility that his communications might be monitored; nor had they had regard either to the fact that he had not been informed of the nature or the extent of the monitoring, or the degree of intrusion into his private life and correspondence. In addition, the natio…

Workplace communication between coworkers eg on Slack is not automatically business correspondence in this sense.

In any case, you repeat the oft debunked myth of corporate right to surveillance. It does not exist. There is just partial lack of EU level protections. The national laws can and do say otherwise in many cases. As can/do binding collective bargaining agreements.

Re: Guide to Slack import and export tools

#476
post #320

Earlier quoted context omitted.

> There is no such thing as a "private conversation" that takes place over a corporate network. It's a tech issue, cultural issue, and a legal issue, but it's harmful that we seem to be forgetting the wisdom of discretion as life become more digitized. If the law or culture says "no expectation of discretion", they're just wrong and likely hypocritical. It's healthy, normal, and appropriate to tell specific things to…

Discretion still has its place, but that's different from privacy and compliance. Most admins aren't going to spend all day reading other people's conversations, and good companies have explicit policies as to when they will do so. The thing we're discussing here isn't whether companies should spy on everything their employees do- it's about what happens when an issue does occur where they do need to look into things…

Does Sarbanes-Oxley require an audit trail whenever an admin views private communications?

Re: Guide to Slack import and export tools

#478
post #319

Earlier quoted context omitted.

I think the bigger problem that the OP pointed at is that whatever adjectives you attach to this, surveillance is almost always the wrong way to change behavior, unless your desired outcome is to make everyone suspicious of everyone else. What's stopping these folks from creating an out-of-company channel to do the bullying and attacking in coordination via that means, or tricking the victim into joining them in the…

You realize this has far more to do with than workplace harassment, right? Have you never heard of employees using a competitors proprietary information? Or arranging fraudulent financial transactions to cover losses? Or discussing how to mislead investors or watchdog agencies? What do you expect this company to do when they are involved in a legal dispute like this, and have to explain to the court why they have com…

I suppose my experience in large corporations is limited. But I'm going to hazard a guess that for all but the biggest corps "company sanctioned" is a not an official term, and that most have given little-to-no thought about all the various ways they need to keep track of the way their employees communicate.

Keeping in context with the OP, Slack allowing admin access to all conversations is a cover-your-ass corporate move, not a solid new tool to combat workplace cultural issues. Perhaps once in a blue moon employee surveillance and bad culture might intersect and prove useful. But that should in no way be used to justify corporate surveillance.

As an elected government official, I understand the importance of papertrails and record-keeping. But the mere fact that so many companies USED SLACK WITHOUT THIS FEATURE, means most had no qualms about side channels being un-auditable before. And now this is just sweet sweet honey to corporate overlords.

Re: Guide to Slack import and export tools

#479
post #320

Earlier quoted context omitted.

> There is no such thing as a "private conversation" that takes place over a corporate network. It's a tech issue, cultural issue, and a legal issue, but it's harmful that we seem to be forgetting the wisdom of discretion as life become more digitized. If the law or culture says "no expectation of discretion", they're just wrong and likely hypocritical. It's healthy, normal, and appropriate to tell specific things to…

Discretion still has its place, but that's different from privacy and compliance. Most admins aren't going to spend all day reading other people's conversations, and good companies have explicit policies as to when they will do so. The thing we're discussing here isn't whether companies should spy on everything their employees do- it's about what happens when an issue does occur where they do need to look into things…

> Discretion still has its place, but that's different from privacy and compliance.

It should be, but often digital tools obliterate discretion in the service of compliance or even just monitoring employee work habits.

> I would not refuse to work for a company just because they could look into my conversations if I was accused of wrongdoing.

A healthy workplace needs to solve the underlying issue, here. But there are simple ways (i.e., asking or ordering the employee to send you conversation transcripts) to get the information needed. Managers and compliance officers are reluctant to let the investigated employees know they're being investigated, which I understand, but I don't think throwing out discretion-oriented communication is worth the benefits there.

Re: Guide to Slack import and export tools

#480

As head of IT for a company using Slack: FINALLY. Don't get me wrong--it's not like I want to read your messages and very likely won't. But there are times when I have no choice. A few years back, a group of interns started privately harassing other interns via Slack. Only way to see it was to boot an offending intern from his work station and go into his Slack to see what was happening. We had to make all intern acc…

Given that your are advocating for lying to your employees to invade their privacy, I'm not surprised you had issues with interns given what you think is a good work culture.

A workplace that has respect for employees would have turned on 'Compliance Exports' on Slack to begin with. Employees would have understood DM were full searchable.

To advocate for (what seems to be, Slack is currently a bit vague) a retrospective retraction of privacy that was told to employees is pretty awful.

You are also advocating for the ability to browse employees DM's. You could at anytime reset their Slack passwords and read a individuals DM's (but it would also have made you accountiable)

Post reply on HN