4 ms·
I am not sure slack can ever meaningfully become encrypted while having persistence. All it takes is for a admin (or hacked admin account) to change the passwor
by ds 8y ago
I am not sure slack can ever meaningfully become encrypted while having persistence. All it takes is for a admin (or hacked admin account) to change the password of the target slack user and login as said user to view all their private messages. The encryption is mostly pointless as far as I can tell when all of it is circumvented by a changed password.
- marcinzm 8y ago>All it takes is for a admin (or hacked admin account) to change the password of the target slack user and login as said user to view all their private messages. An admin cannot change a user's password. You can enable an account wide feature which allows admins to view all messages but that's separate and costs money. Also not what you described.
- geofft 8y agoIf you're using SSO, which almost every big customer does, you can usually do a password reset in the SSO itself. Also I'm pretty sure a Slack admin can change a user's email address, at which point they can trigger a password reset.
- ds 8y agobingo. The admin just changes the email address than does a forgot password recovery. This works without SSO/special integrations. You can do this on a vanilla slack install to any user.
- ec109685 8y agoIt does email the person you made the change though. If you control the email system, then you could do it silently.
- jrockway 8y agoI don't think that's true. In the corporate world, Slack is authenticated with AD/SAML/etc. and Slack has no idea who is changing passwords on that backend system. The reality is that IT administrators are the root of trust at all organizations. This new feature doesn't change that.
- bookofjoe 8y ago>The reality is that IT administrators are the root of trust at all organizations. Is this true?
- ryukafalz 8y agoFrom a technical perspective, yes, though of course not a legal perspective. Take certs signed by an internal CA for example; as far as end user devices are concerned, the root of trust is that CA, which is presumably configured and managed by your IT staff. (Or sysadmins or whatever the role happens to be at your company.) It’s of course possible to limit administrators’ access to certain systems, but ultimately the mechanisms to do so are themselves probably set up by your IT administrators in the first place, so in that sense they’re still the root of trust.
- mistrial9 8y agoIT administrators may handle the root of trust, but IT administrators are closely subservient to management. Management, in the business of control, knows this, and pushes at many opportunities. In the US courts, management whim controls any asset, not de-facto key holders.
- ds 8y agoThe admin just changes the email address than does a forgot password recovery. You dont need SSO/special integrations. You can do this on a vanilla slack install to any user.
- exabrial 8y agoI thought it was rather difficult for an admin to view private messages on Slack? Last I checked you had to apply for this kind of access, on your own account.
- erichurkman 8y agoThey are only secure so far as everyone in the DM or private channel is employed. The company can always take over old accounts and get access to DMs that way.
- morpheuskafka 8y agoIf everyone has to use corporate email addressees they could just take over the emails temporarily to reset the password. If they really cared they could do so without the user ever knowing. They could also put language in their employee handbook or contract saying that you have to give them your password and fire for refusing... however, I fail to see how any of this is an issue since this is the company Slack and they have the right to see how people are using it.
- brazzledazzle 8y agoThey used to require that you enable it and it would send a notification out to all users of your Slack instance ( they also wouldn’t have access to data prior to that without a legal request) but now they just let you enable it silently.
- gregoriol 8y agoIf you really want encryption with only access by the people in the room, you can use Matrix: it's not based on your password, but on the keys. If you have your keys (and encryption has been enable in the room), you and only you/your devices can read the messages.
- giancarlostoro 8y agoSo if someone else changes the password it doesnt show them? What if you legitimately chang your own password how does that work? I think I like the proof concept from Keybase unfortunately their name makes it sound like an SSH key repo and not an all in one chat and file sharing service. Also not quite as open as Matrix in the sense that people can choose other servers.
- miloignis 8y agoRight, the encryption isn't based on the password, but on encryption keys that are only on your devices. If you want to add a new device, you share the keys from one of your other devices to that new device. But just being able to log into an account (say by having the password) on a new device doesn't give any way to get the keys/read the encrypted messages.
- giancarlostoro 8y agoSo how easy is it to transfer between devices? This sounds like your keys could wind up in untrusted sources like if e.g. someone emails their keys to themselves, pretty sure then all bets are off that those keys are even secure?
- miloignis 8y agoQuite! If you don't have them backed up to your homeserver Riot asks you if you want to share the keys with the new device, you check that the device ID and key match, and then hit ok and it happens. If you have them backed up to your homeserver, you just hit download from server then put in the password you encrypted them with.
- 420codebro 8y agoI wonder if just using standard OTR over slack for sensitive stuff is viable.
- baby 8y agoThat is not what the encryption they are using is for, you are confusing end-to-end encryption with encryption at rest. What they are most likely doing is encrypting their database transparently, so that if someone breaks in and just dump the database, nothing worth would have been stolen. This is typical, and often required by different regulation bodies when you deal with personally identifiable information (PII).
- paxys 8y agoDepends on what you mean by "meaningfully encrypted". If E2E encryption is what you are going for, then yes. Companies that use Slack specifically don't want that, though, since they want to be in control of all communications (due to industry regulations or whatever other reason). So it is still encrypted, but the company holds the keys.