Live data from Hacker News

Guide to Slack import and export tools

get.slack.help

521–529 of 529 posts

Re: Guide to Slack import and export tools

#521

As head of IT for a company using Slack: FINALLY. Don't get me wrong--it's not like I want to read your messages and very likely won't. But there are times when I have no choice. A few years back, a group of interns started privately harassing other interns via Slack. Only way to see it was to boot an offending intern from his work station and go into his Slack to see what was happening. We had to make all intern acc…

This is ridiculous. If one is harassed in private they have all the evidence they need to expose the harassment to whomever they want.

So now they are not private messages and shouldn't be called as such.

Re: Guide to Slack import and export tools

#522
post #320

Earlier quoted context omitted.

Discretion still has its place, but that's different from privacy and compliance. Most admins aren't going to spend all day reading other people's conversations, and good companies have explicit policies as to when they will do so. The thing we're discussing here isn't whether companies should spy on everything their employees do- it's about what happens when an issue does occur where they do need to look into things…

> Discretion still has its place, but that's different from privacy and compliance. It should be, but often digital tools obliterate discretion in the service of compliance or even just monitoring employee work habits. > I would not refuse to work for a company just because they could look into my conversations if I was accused of wrongdoing. A healthy workplace needs to solve the underlying issue, here. But there ar…

> But there are simple ways (i.e., asking or ordering the employee to send you conversation transcripts) to get the information needed.

Are you serious? So, someone accuses an employee of abuse and you casually stroll by and ask them to send relevant conversations your way? And you expect them to comply without cheating? Why don't we try this approach with other misdeeds, for example, when someone complains about theft, we just ask thieves to come by the police station with the stuff they stole. Do you think that would work?

Re: Guide to Slack import and export tools

#523
post #456

Earlier quoted context omitted.

I'd argue that it isn't. I'm not a legal expert, but it seems that it could be argued that direct messages are implied private conversations, and that laws around recording audio implies that private spoken conversations can occur in offices. The fact that direct messages leave a history is merely a side effect that does not suggest that they are any less private than a spoken conversation behind closed doors. Howeve…

Well, as you said, you aren't an expert on this and apparently haven't ever been briefed by your company's legal team, and presumably have never been in charge of compliance. So your arguments about how the law works are in this situation pretty useless. Jumping away from that angle though, there's still a lot of issues with what you are presenting. For one thing you keep referring to "authorities" without defining w…

You are correct in all of that.

I simply would have hoped that Slack wouldn't give too much control to employers when there are already viable ways of providing message history without resorting to copy-paste. It makes for a lousier product, and it would have prevented me from having candid conversations that involved no company secrets or harassment of any kind.

Re: Guide to Slack import and export tools

#524
post #388

Earlier quoted context omitted.

That is only according to some law systems though. It does not work like that at all in many European countries. For instance in France the employer cannot read any private conversation (mail/message) of the employee, even when using work email. And no internal rule can change that (it is a criminal offense). If the employer suspects a leak of information by the employee, they can read the message in presence of the…

> If the employer suspects a leak of information by the employee or if they suspect any other illegal activity. Even in EU countries where arbitrary inspection/monitoring is not permitted wholesale, there are exceptions where regulatory or other legal requirements trump privacy. Though often there needs to be sufficient suspicion of something worth looking for, I still wouldn't count that as a truly private channel (…

But as I said even in those cases the employee needs to be present when the employer accesses private messages, in addition to a union member. So as an employer you cannot just sneak in and check what has been said, it has to be public. Which I think greatly mitigates the risk. It is not a secret conversation like you would have between lawyer and client but it is rather private.

Re: Guide to Slack import and export tools

#525
post #513

Earlier quoted context omitted.

You're right! The log can be easily viewed or accessed later. This of course occasionally requires an annoying amount of screwing around with reactivating old accounts, resetting passwords, and so on. Irritating, but of course a price well worth paying for employee privacy. With that said, is it perhaps possible that direct access is preferable for reasons other than sheer laziness? Chain of custody and provenance bo…

Reactivating accounts would only need to happen if the accuser had left immediately, which doesn't seem likely. I think it is just that big companies have a way of doing things, are paying the bills, and employee privacy is close to last on their priority list—far behind CYA. They don't care that there is another potential solution.

A person leaving a company after filing a harassment complaint strikes me as very likely. I personally know people who have very precisely that. It's a very common scenario in large companies.

Having personally dealt with some of those companies and situations, I can tell you quite simply that people are definitely aware that there are other potential solutions. Such approaches are seen as not adequate for purpose. The reasons for this judgment are not merely arbitrary or capricious. They are broadly quite sound and reasonable, and I touched on them above in an effort to give you an opportunity to grow in your understanding of those you disagree with.

And yes, as you say, companies are far more interested in limiting liability than they are in employee privacy on company-controlled systems. It's not, as some might suggest, that employee privacy is not valued. It's a question of priorities, and companies tend to place being able to defend themselves and control their risks adequately over an employee's right to leverage their privacy and incur liability for the company.

Though I understand why some might prefer to dismiss the above and think of it as just another example of big, stupid, corporate laziness and refusing to consider alternatives.

Re: Guide to Slack import and export tools

#526
post #525

Earlier quoted context omitted.

Reactivating accounts would only need to happen if the accuser had left immediately, which doesn't seem likely. I think it is just that big companies have a way of doing things, are paying the bills, and employee privacy is close to last on their priority list—far behind CYA. They don't care that there is another potential solution.

A person leaving a company after filing a harassment complaint strikes me as very likely. I personally know people who have very precisely that. It's a very common scenario in large companies. Having personally dealt with some of those companies and situations, I can tell you quite simply that people are definitely aware that there are other potential solutions. Such approaches are seen as not adequate for purpose. T…

Here's where you made a detour, agreeing and disagreeing with a side order of condescension.

A significant portion of folks stick around for a long time in a poor situation as it isn't so easy leave a job at a moment's notice. For those that don't there is the simple matter of not deleting everything. Nothing is actually deleted any more anyway. Brave new world.

Big, stupid, and corporate are synonyms, government too. It goes with the territory of any large group of humans. As they grow they get dumber and further out of touch until they are overturned by a smaller, nimbler version where the process is repeated in Innovator's Dilemma fashion.

Re: Guide to Slack import and export tools

#527
post #463

Earlier quoted context omitted.

This isn't exactly true. Employees do have a higher right of privacy even when using company resources than they do in the US, but monitoring is allowed within certain parameters, and that can include searching email or other "private" storage spaces. Companies must still be able to comply with eDiscovery and data preservation requests from various police agencies (such as Økokrim), and these may be performed without…

>Compare that to our email, where I can go into anyone's messages immediately if need-be The only opening for reading employees' communications that I can find by some quick googling, are (1) if there is good reason to believe that information contained there is required to keep the concern going or (2) if there is suspicion of serious dereliction of duties. And even then, there is a significant checklist required in…

Datatilsynet's statement actually does give quite a bit of leeway, but I do agree that you can't just monitor without reasonable suspicion that the employee is acting improperly.

Re: Guide to Slack import and export tools

#528

Earlier quoted context omitted.

These are all the sorts of things that you would ideally want management to know about so they can make better informed decisions. Assuming of course that you have competent and trustworthy managers.

>Assuming of course that you have competent and trustworthy managers. You're begging the question. "Competent and trustworthy" people won't abuse their power by definition . Anyone who abuses their power intentionally is untrustworthy, and anyone who abuses their power unintentionally is incompetent. In the real world there are many incompetent and untrustworthy leaders. Slack has no choice but to operate in the real…

Which question am I begging? I wasn't talking about abuse of power.

Re: Guide to Slack import and export tools

#529
post #503

Earlier quoted context omitted.

If the employer had physical access, what would prevent them installing a rootkit? Then you couldn't detect a fake certificate no matter what you tried. Or deeper, if you distrust the provided software, what makes you trust the hardware? It's turtles all the way down ;)

Yes, but assuming partial good faith (this does sound like an oxymoron, but humor me) - how would I go about checking for cert misuses?

The OS should have a trusted CA list somewhere (not sure where OSX does); checking that it matches a fresh install should be the first step. Note that there might be multiple lists - Firefox, for one, tends to keep their CA list separate.
Post reply on HN