9 ms·
A former employer bristled at the cost of Slack[1]. Why should we pay for Slack when we already own Teams? Everyone will just use Teams. About a week later I w
by gav 6y ago
A former employer bristled at the cost of Slack[1]. Why should we pay for Slack when we already own Teams? Everyone will just use Teams.
About a week later I was on 4 unofficial Slack workspaces.
They also mandated Teams for meetings, which was both terrible and particularly hostile to external invitees, so everyone just used free versions of Zoom instead.
[1] Less than 0.07% of my base salary
- thinkharderdev 6y agoYeah, the one killer thing that slack has is that there is a free tier which is perfectly usable. Organizations can try and force everyone to use Teams but in practice they can't stop people from just spinning up a free-tier slack account for their team. At the end of the day it's just not worth fighting it anymore if everyone is determined to use slack.
- tharne 6y ago> Organizations can try and force everyone to use Teams but in practice they can't stop people from just spinning up a free-tier slack account for their team. Unless you work for a large corporation or really any business that takes security seriously. Many of these businesses will quickly fire employees for conducting company business on non-approved applications or sites. Major security issues there.
- prepend 6y agoThose companies are bad. There’s ways to train users and secure material on slack. Picking bad tools and firing users for trying to work around IT rules punishes innovation and results in worse employees. I used to work for a company with 200k employees that banned any use of google apps. In 2009. Even working on a different company’s doc was banned. They threatened firing. It was ridiculous. One day a partner was presenting from google drive. One of the IT execs said “you can’t use google drive” during the presentation. The partner asked what he should use and the IT guy said something about opening a ticket with AV and emailing the presentation. The partner kept going and the It guy said “no seriously, you’ll be fired.” The partner laughed, kept going and said “I’ll risk it.”
- dvtrn 6y agoThose companies are bad. There’s ways to train users and secure material on slack. Picking bad tools and firing users for trying to work around IT rules punishes innovation and results in worse employees. If they just capriciously fire someone for deciding to use Slack in their functional team away from everyone else, sure. But if one's org has a security mandated policy to use specific communication programs and services that one presumably agrees to and signs a document asserting their compliance to as a contingency of continued employment, and that person violates it anyway...I'm hard pressed to call the company "bad" when they take disciplinary or corrective action against that individual. Such cavalierness (generally speaking) is how you get ants..I mean data breaches et al.
- prepend 6y agoSlack isn’t some random company, they have enterprise practices and there are third party companies that do data management on slack. An enterprise can adapt to use tools and apply security to the tools used and needed. Also there is really basic “don’t post sensitive data to the wrong places” training. I think there’s a difference between banning posting sensitive data and stopping teams from planning a meeting agenda. A company that can’t stop an enployee posting sensitive data to Slack also won’t be able to stop them posting it all sorts of bad places. I expect that sensitive data is protected in an org. With something more effective than firing people from posting it to Slack.
- JoshTriplett 6y agoSo much of security entails making policies that people want to help enforce, rather than working around those policies to do their jobs. If any substantial fraction of your workforce sees your security policies as an obstacle and IT as an adversary, your policies have already failed and it's just a matter of time before there's a problem. If your policies make sense to everyone, you educate people on why they make sense, and they're so sensible people's first reaction to a breach of those policies is to genuinely understand how doing so might cause a security incident and advocate better solutions person-to-person, you're far less likely to have a security incident. (That doesn't mean every person needs to be happy with every policy all the time; it means that people need to not systematically feel that IT is primarily an obstacle to their job.) Companies where most people think IT is actively awesome (not just "not in the way" but actively good) are 1) rare, and 2) likely to be substantially more secure.
- zigzaggy 6y agoYeah. My security team would really have my hide if I tried that. The other day I had a visitor from security come in and scrub all my addons off of my Firefox installation because they hadn't been vetted through IT. They most certainly wouldn't allow shadow slack rooms.
- freehunter 6y agoA place I worked as an information security analyst about 8 or 9 years ago had a policy against various streaming technologies on the corporate network because it often overwhelmed or blinded the security monitoring technology we used back then. Spotify had just launched in the US right around that time and I had to spend a couple of days visiting various desks and asking the employees to stop streaming on the corporate network. We were just completely and utterly blind as soon as two or three people started streaming.
- gberger 6y ago> The other day I had a visitor from security come in and scrub all my addons off of my Firefox installation because they hadn't been vetted through IT. They can't do that remotely?
- zigzaggy 6y agoI’m compressing time a little for my story. This was last year before the lockdowns. He probably could have done it remotely. But we never missed an opportunity to talk about nerd stuff. He was definitely a talker.
- thinkharderdev 6y agoI'm not sure how much of a security issue there is. What's the threat model exactly? Terminated employees still having access because you don't have SSO? Sure I guess but if there is security sensitive data being posted in any chat app (approved or not) then you've got major problems.
- scarface74 6y agoI logged into an old Google account I hadn’t used since 2009 and realized I still had access to some documents from a company I had worked at back then - and the documents had been updated two years ago. If I send a sensitive document in the approved chat app that uses SSO, once I quit. I don’t have access to it anymore.
- thinkharderdev 6y agoRight, that's a legitimate security concern but the point I was trying to make is that the problem is not so much people using unapproved chat apps but people putting sensitive information in chat apps at all (approved or not). These applications aren't generally designed to have the sorts of access controls required to manage sensitive information. If I post something sensitive in a public slack channel at my work (where we use Slack) then it is available to anyone in the company. I guess it is marginally worse to have it available to everyone in the company plus any former employee who wasn't removed from the slack team, but only marginally.
- scarface74 6y agoExactly this. I’ve taken pictures of whiteboard drawings using my phone for years. But that is completely against my current company’s policy because pictures get synced to iCloud. It makes perfect sense why something I could do at small no name companies would be banned at BigCorp.
- scarface74 6y agoTry that at my company and if you get caught, you would get fired so fast it would make your head spin. Most large corporations are very concerned about which communication platforms you use for official business.