Live data from Hacker News

Ask HN: If your company cares about security, why does it use Slack?

news.ycombinator.com

1–10 of 71 posts

Ask HN: If your company cares about security, why does it use Slack?

#1
It's insane to me how many "security conscious" companies use Slack purely out of convenience.

The fact is, it's an enormous, centralized application written in PHP (not always a bad thing, but certainly not a language that keeps you from shooting yourself in the foot), with a massive target painted on its back.

How is it acceptable to you to use a chat solution hosted by a third party? Why not use an alternative you can host yourselves? It's just a matter of time before there's a huge incident.

Re: Ask HN: If your company cares about security, why does it use Slack?

#3
Umm... why do people always assume "hosting it yourself" is more secure and not less? Do you have Slack's security expertise and budget? In my experience when small to mid-size companies attempt to manage security themselves they do a passable job but are convinced they are doing an excellent job - until they get hacked.

Larger companies usually have the budget, tools and expertise. But even then there are lots big companies with mediocre security too.

Re: Ask HN: If your company cares about security, why does it use Slack?

#4
The usual answer is "the self-hosted options are worse to use and make people hate them". Mattermost is a prime example, it's really clunky and uncomfortable to use. I like Rocket Chat and have hosted an instance of it myself, but it's shot through with inconsistencies and annoyances that Slack just doesn't have.

The notion that self-hosted is more secure is curious, though. Slack's security team is almost certainly better than yours, for most--not all, but most--values of "yours". You might be the rare exception (I'm certainly not, and I build reasonably secure systems by habit, if only because I don't have the time or money to focus solely on a chat service), but I doubt it.

Re: Ask HN: If your company cares about security, why does it use Slack?

#7
post #3

Umm... why do people always assume "hosting it yourself" is more secure and not less? Do you have Slack's security expertise and budget? In my experience when small to mid-size companies attempt to manage security themselves they do a passable job but are convinced they are doing an excellent job - until they get hacked. Larger companies usually have the budget, tools and expertise. But even then there are lots big c…

Corollary question: Why do you assume that Slack's security expertise and security budget is greater than your own?

All we can do is assume that Slack cares about security enough to be sufficient. Last I checked, they didn't have any form of compliance certification, yet HIPPA, PCI, etc. compliant clients use them without reservation.

Re: Ask HN: If your company cares about security, why does it use Slack?

#8
post #3

Umm... why do people always assume "hosting it yourself" is more secure and not less? Do you have Slack's security expertise and budget? In my experience when small to mid-size companies attempt to manage security themselves they do a passable job but are convinced they are doing an excellent job - until they get hacked. Larger companies usually have the budget, tools and expertise. But even then there are lots big c…

Because when you host it yourself, it can be off of the public internet.

Re: Ask HN: If your company cares about security, why does it use Slack?

#9
post #3

Umm... why do people always assume "hosting it yourself" is more secure and not less? Do you have Slack's security expertise and budget? In my experience when small to mid-size companies attempt to manage security themselves they do a passable job but are convinced they are doing an excellent job - until they get hacked. Larger companies usually have the budget, tools and expertise. But even then there are lots big c…

[deleted]

Re: Ask HN: If your company cares about security, why does it use Slack?

#10
Hosting shit yourself != more secure, and only someone with a highly naive view of their capabilities as an organization would make that assessment. Facebook is written in PHP too, but you don't see that being a huge secure vulnerability, do you?

Slack has an entire security organization dedicated exclusively to securing its stuff. My security team is focused on securing our operational systems.

Do you run your own bank? How could you outsource something so critical (literally all your money and financial details!) to a 3rd party who doesn't even let you audit their stuff?! It's just a matter of time before there's a huge incident.

Do you run your own electrical generation facility? How could you outsource something so critical to a 3rd party? I bet they don't even have an SLA!

etc. etc.

Post reply on HN