6 ms·
Umm... why do people always assume "hosting it yourself" is more secure and not less? Do you have Slack's security expertise and budget? In my experience when
by dstroot 9y ago
Umm... why do people always assume "hosting it yourself" is more secure and not less? Do you have Slack's security expertise and budget? In my experience when small to mid-size companies attempt to manage security themselves they do a passable job but are convinced they are doing an excellent job - until they get hacked.
Larger companies usually have the budget, tools and expertise. But even then there are lots big companies with mediocre security too.
- falcolas 9y agoCorollary question: Why do you assume that Slack's security expertise and security budget is greater than your own? All we can do is assume that Slack cares about security enough to be sufficient. Last I checked, they didn't have any form of compliance certification, yet HIPPA, PCI, etc. compliant clients use them without reservation.
- nzoschke 9y agoI happen to know a few people on the Slack security team from a prior job. SalesForce, another SaaS business people trust to manage all their data. There's no question that Slack's budget is greater than my own. They have a large, full-time security team. I have a bit of attention from myself or a colleague when setting a system up. There's also no question their expertise is better. These are life long security professionals with direct experience at other SaaS companies.
- count 9y agoYou should look again: https://slack.com/security https://slack.com/security
- falcolas 9y agoOK: Slack is not currently a PCI-certified Service Provider. I was also a bit surprised what they consider out of scope for their bug bounty program: https://hackerone.com/slack https://hackerone.com/slack
- count 9y agoI can't begin to fathom a use case for slack where you would put card data in the system...
- falcolas 9y agoHow about a bug report screen shot? Lots of non-security conscious users don't understand why this could be bad. It's your (making the assumption that "you" in this case is a Slack Administrator) job to protect them from themselves.
- fweespeech 9y agoYou've never met a call center. They've sent bug reports with credit card data they've typed in during a phone call through a variety of insecure methods. They've also written people's credit card info on sticky notes. Trust me, the horror that is card data and a call center is scary.
- bogomipz 9y agoThe use case is user error. I have also seen no shortage accidentally people paste passwords into Slack as well
- oneplane 9y agoHIPPA, PCI, etc. compliancy doesn't actually mean you are secure, it just means you are compliant. Take ransomware attacks for example, most of the bigger companies that get hit and have no working plan to continue their business are compliant to all sorts of things, hell complete governments are in that category... Compliancy only tells a story about management and how many MBA's you have, it doesn't actually mean you have good security. Only being compliant isn't going to help you not get data leaks or data loss!
- falcolas 9y agoYou're correct - it doesn't mean you're secure. It does, however, point out that you're putting some thought and effort into security. PCI requires remediation plans or justifications to pass, as does HIPPA. And, for better or worse, you need your service providers, including chat, to be compliant. If your company were to leak PII via Slack, your company would be in pretty hot water for putting PII on a non-certified service provider. At least if it were certified, you could say "we've done our due diligence to protect people's PII". Perhaps only important to leadership and lawyers, but still important.
- oneplane 9y agoIn this case, however, Slack is certified.
- eropple 9y ago> Why do you assume that Slack's security expertise and security budget is greater than your own? I don't assume it. I know it for a fact; I've met some of their team and I know others by reputation. And I'm not exactly a slouch when it comes to this stuff (I don't eat and sleep crypto but a large part of my business is building secure infrastructure/consulting on the systems running on that infrastructure for regulated as well as non-regulated environments).
- count 9y agoSlack has, publicly, a multi-member security team! That's entirely focused on the chat system that I don't have to put any of my teams time towards.
- fweespeech 9y agoI'm curious... Which is more secure? A) Slack. B) Open source software on a LAN accessible only through physical entry, SSH, and/or a VPN.
- count 9y agoI'd vote slack.
- fweespeech 9y ago> I'd vote slack. Then I suggest you put more effort into securing your LAN situation because that is a vote indicating your belief your workstations are insecure.
- count 9y agoIf you don't assume your user/dev workstations are insecure, you're going to have a rough time in life.
- eropple 9y agoI'm pretty confident in saying that 95% of companies have worse endpoint protection, local network protection, cloud protection, or the intersection of any two or three of those things than Slack does application protection. Maybe more than 95%.
- misterrobot 9y agoBecause when you host it yourself, it can be off of the public internet.
- masom 9y agoThat's not very useful for your CEO/CTO/CFO/sales/etc when they are offsite or traveling.
- KekDemaga 9y agoA VPN resolves this issue and provides encryption and authentication.
- actsasbuffoon 9y agoA VPN is non-trivial to set up correctly. Have you set up an internal DNS to prevent leaking the domains from requests? How about IPv6 leaks? There are many things to consider, and I wouldn't trust a random programmer to do it correctly.
- theossuary 9y agoI wouldn't trust your programmer much at all if they couldn't configure OpenVPN with correct DNS settings, given some time.
- KekDemaga 9y agoMany good resources exist: https://www.linode.com/docs/networking/vpn/set-up-a-hardened-openvpn-server https://www.linode.com/docs/networking/vpn/set-up-a-hardened...
- sgehly 9y agoand what about if your network is compromised? For most small-medium businesses, that's more likely than Slack being compromised.
- deleted 9y ago[deleted]
- etchalon 9y agoI think both options have tradeoffs. If you use a service, you're outsourcing your security to perhaps more competent people, but you're making yourself a larger target. Self-hosting makes you a smaller target, but you're taking all the risk on yourself. Neither is a panacea.
- KekDemaga 9y agoI agree the answer is shades of gray. Personally I prefer self host because I am able to get more visibility on my threat model that way. If you aren't equipped to use that information then I see little benefit to it.
- fweespeech 9y ago> Umm... why do people always assume "hosting it yourself" is more secure and not less? Do you have Slack's security expertise and budget? In my experience when small to mid-size companies attempt to manage security themselves they do a passable job but are convinced they are doing an excellent job - until they get hacked. I'm not exposing it to the WAN, just the LAN. :\ I don't think people really appreciate how massive of a security difference that is. It doesn't matter how big your budget is if you sit on the WAN all day. Someone will _always_ tag you eventually. LAN with hardened VPN/SSH setups are virtually impossible to get into in a software-is-at-fault kind of way. And even if they did, they'd then have to launch the attack from someone's workstation at which point you've already been compromised anyway. Oh, and then to get to the chat service they'd still need to break the security of an open source chat service which is non-trivial.
- tatersolid 9y agoYour LAN is protected Only if you know that no workstation which connects via VPN, WiFi, or cable can ever be compromised elsewhere and then connect. Which is clearly not possible unless your workstations are air-gapped and immobile, with no USB ports, etc. The majority of non-trivial breaches involve some sort of pivot or lateral movement inside the "protected" LAN. These often originate from a workstation.