5 ms·
No one should be using slack at all. I understand that it fills use cases that email and irc don’t, but that is no excuse for letting all of your communications
by gnu8 8y ago
No one should be using slack at all. I understand that it fills use cases that email and irc don’t, but that is no excuse for letting all of your communications be owned by some other company. What if slack accidentally or deliberately denies access to your data? What if they choose to use it for their own purposes or disclose it to some third party? What if they get hacked by Russia?
- Shank 8y ago> What if they choose to use it for their own purposes or disclose it to some third party? I appreciate the sentiment, but Slack has a privacy policy and a known system for how they make money (they charge customers). Companies don’t just, on a whim, decide to start giving away data, especially when they know that it’s valuable and they have a business model of trust. Slack has this. So does basically every other corporate geared SaaS. Being worried about data security is a real problem. That’s understandable. But companies don’t just “decide” how to use data on a whim — it’s a business after all. When you pay for a product, that direct monetary exchange is the one that firmly identifies who the product is — and it’s not you.
- mmt 8y ago> But companies don’t just “decide” how to use data on a whim Their acquirers do, however.
- adrianmonk 8y agoThe risk you're talking about definitely exists. It's interesting how people treat that risk, though. You could make a similar argument to say you should never rent office space. Your stuff is stored in a building you don't own, and the landlord could deny you access either accidentally or deliberately. (This actually does happen sometimes with incompetence or landlord/tenant disputes.) But few people really feel like it's a big issue. In practice, most companies will rent office space without batting an eye. I suppose one difference is there are some explicit tenant protection laws, but it still feels like a similar calculated risk thing. You outsource because the risks are low enough, trust is high enough, and the alternative of doing it yourself takes away too much from focusing on your business.
- mmt 8y ago> the landlord could deny you access ..or grant themselves access. That's the other risk that the parent comment pointed out. > In practice, most companies will rent office space without batting an eye. Presumably, though, they also put in security cameras and don't leave the "crown jewels" (source repo?) exclusively accessible from that office space and needing nothing more than the landlord's key to do so. > it still feels like a similar calculated risk thing It certainly feels like it, but is it actually? Is anyone actually even pausing to think about it, let alone calculate the risk? > the alternative of doing it yourself takes away too much from focusing on your business I can't help but wonder if the effort required isn't routinely over-estimated. Some of these things aren't that hard, and, when they're critical to the business, there's an argument to be made that doing it oneself is focusing on the business. I can personally attest to repeatedly running into labor/effort over-estimation in the cloud-vs-hardware decision. This, like (at least rudimentary) chat is a well-enough understood problem that an accurate estimate is actually possible.
- LinuxBender 8y agoI am not a lawyer and this is not legal advice. But it could be. It's actually worse than what you described. By default, users can install integrations and applications that extend legal contract of your company to fly-by-night third parties that can obtain access to all public channels that any user of their integration is a member of. We locked this down, but most companies don't realize the legal, privacy and security risks they are accepting. So Slack itself does not need to get hacked by anyone. The framework by design facilitates this and removes Slack from legal responsibility. Your organization takes on this legal risk and the users in your org decide your legal fate (unless you lock down integration / third party apps). I mention legal fate, as many companies are using Slack for ChatOps, automation, discussing customer issues and much more.
- Rjevski 8y agoI’m not sure how is this different from an employee copy/pasting confidential data in an email and sending it off to a third-party. Will you also blame email clients for making it “too easy” to leak data to third parties?
- LinuxBender 8y agoThis is not about me blaming anyone. This is about educating folks that the shiny new "app" they installed is relaying data to a 3rd party and it may not be clear to people the legal and privacy ramifications of doing so. They must also be made aware that the 3rd party has no legal agreement with them so they are dealing with 3rd party data processors. I can assure you that most legal and HR departments have no idea that Slack does this.
- bachmeier 8y agoAt this very moment, there is a story on the front page about Twitter shutting down Smyte. One commenter writes: "We had 20 minutes notice, and then everyone was kicked out of the Slack support channel and API responses simply died." If someone says "they would never do that" you can discard it as wishful thinking.
- saltcured 8y agoFor me, Slack already did that when they reneged on their XMPP gateway sales pitch. It was an instrumental feature for getting consensus in my group, precisely because it promised we could use our existing chat clients and ignore the Slack-only features we don't care about.
- isostatic 8y agoLosing communication is a pain, you'd have a couple of weeks of pain while you moved to using email or IRC or phone or whatever. What happens if AWS gets hacked by Russia? Or use your stuff for their own purposes? How many people -- especially startups -- throw all their eggs in the AWS basket, rather than building a system that runs across multiple VPSes from multiple providers.