4 ms·
Would IRC even work in that nameless enterprise?
by deberon 5y ago
Would IRC even work in that nameless enterprise?
- singron 5y agoIRC might be run by engineering there for themselves. 3rd party chat would got through procurement and be provided by IT for the whole company, and after the last SOC2 audit, they had to lock it down.
- lloeki 5y agoTechnically, yes. In real life, no. I don't even blame such enterprises because most of the time it comes from regulations or outside policies that customers mandate, something like all enterprise data (and thus communication) has to be firmly under control of the enterprise with hard guarantees, otherwise you just don't get to work with those customers. So you get a locked down Slack/Teams, and the email+calendar system disallows any native app unless the device is MDM'd, and even that is only with first party clients such as the Gmail app or Outlook. TBH I think most companies are trying to do their best there, but they're stuck with some kafkaesque liability system.
- franga2000 5y agoWhat's more "under control of the enterprise" than a self-hosted IRC server?
- u801e 5y agoIt doesn't prevent clients from logging communications in that server. I know the same is possible in slack or teams, but they don't consider that from a legal perspective.
- franga2000 5y agoFrom a legal, practical and technical perspective, any window displayed on any screen is equally succeptible to logging. I can't imagine the fact that the company disabled ctrl+c in the policy settings making any difference in a liability case.
- jethro_tell 5y ago*print screen and phone cameras.
- oarsinsync 5y ago> I can't imagine the fact that the company disabled ctrl+c in the policy settings making any difference in a liability case. Taking reasonable measures absolutely does absolve the company. At that point, it becomes a rogue employee who’s deliberately circumvented policies and technical enforcements, who is now potentially personally liable. It’s garbage, but hey ho.
- franga2000 5y agoFair enough, they did "try", but still feels equivalent to putting sensitive documents in a glass frame with a "no photos please" label on it and then claiming you did everything you could to protect them. I can't imagine that would fly in court, but I guess as soon as computers are involved, all common sense is lost.
- lloeki 5y agoAlso legal: doing it in house it's on you vs being a Slack feature means it's on them. CYA by outsourcing. And consider this also: "hey we're quite sure pur homegrown system is as leak proof as it can be, trust us or fire up an audit team for 5 sprints to asses compliance" vs "Slack has the box checked already" The fact that folks can e.g technically fire up a headless browser and programmatically interact with the app via capybara or whatever to rebuild a makeshift API, or just take pictures with their phones because the compliant system is inconveniencing them daily is immaterial.
- deknos 5y agothat's really funny. because i did this for CYA reasons.. with different methods, but mostly with screenshotting or autohotkey stuff.