6 ms·
HipChat Will Grant Employers Access To 1-to-1 Chat History
- brianpgordon 12y agoDoes anyone know if Google has a similar policy for GMail or Google Hangouts/Google Talk?
- bagels 12y agoI'm curious about this too, and whether 'off the record' does anything with a corporate account.
- trefn 12y agoWith Google Apps for Domains you can take over an email address, for example after you fire someone. Nothing prevents you from seeing old emails.
- bagels 12y agoEven if they're deleted?
- sylvinus 12y agoReally disappointing move. If you don't trust your developers, maybe you shouldn't have hired them in the first place. Our team loves HipChat, and they will probably end up feeling the opposite because of this. Please provide a way for us not to activate that "feature".
- Alex3917 12y ago> If you don't trust your developers, maybe you shouldn't have hired them in the first place. Companies are basically required by law to store all the communications of their employees, it has nothing to do with trust. I forget the entire reason, but basically Bill Clinton cut some crazy deal with radical feminists in order to get reelected whereby he signed some sexual harassment law that basically required employers to monitor all employee communications. Jeffrey Rosen has a book about it called The Unwanted Gaze.
- djur 12y ago> Bill Clinton cut some crazy deal with radical feminists in order to get reelected I had no idea that radical feminists, or indeed feminists in general, had such immense power that they could affect an election where the incumbent won by 9%.
- Alex3917 12y agoThey don't. That was only one of dozens of such deals with various organizations. The Adam Curtis documentary Century of the Self goes into some of the others.
- flurdy 12y agoReading employees email is potentially illegal in some countries in the Europe http://en.wikipedia.org/wiki/Workplace_privacy#Europe http://en.wikipedia.org/wiki/Workplace_privacy#Europe http://www.eurofound.europa.eu/eiro/2005/10/feature/no0510102f.htm http://www.eurofound.europa.eu/eiro/2005/10/feature/no051010... How that relates to chat is unknown but would probably have to abide by the same laws (IANAL)
- nedwin 12y agoThe only question I have is: how good are the emoticons on Slack.com?
- kyleknighted 12y agoFull emoji support and users can upload custom emoticons. It's full of win!
- deleted 12y ago[deleted]
- zacwest 12y agoThis is a pain point for me because HipChat's permissions granularity is really bad: my organization gives everybody admin access so we can configure API tokens, emoticons, etc. Things we want to do pretty often. Now, we'll have to restrict everybody to a normal user and have a single administrator do these very normal operations.
- sukuriant 12y agoTalk to HipChat, that sounds like something they might be able to change in their service. Perhaps have a super-admin or user groups or something that give intermediate permissions. Your circumstances don't sound like they would be rare.
- TheSwordsman 12y agoThey definitely aren't rare. We have the same pain where I work. We just end up having a limited number of HC admins and make them do all our API requests. It'd be nice if you could take a conversation off the record. Is it inconceivable that HipChat may be used for human resource like discussions? I see some risks with this, and not sure I agree. However, I do understand why they would do this. Bummer.
- orbitur 12y agoHR-level discussions should be documented at all times, so that seems like a poor example to use here. I truly feel that if the chat platform is being provided by the employer, then they have every right to disallow you from taking conversations offline. The problem really lies with Atlassian for not offering better permissions.
- olivierlacan 12y agoYep, we have exactly the same issue. This feature decision is a trust-deterrent. Nothing worse when it comes to team communication. To me this is the final straw. By contrast Slack's privacy policy mentions they "plan to allow team owners or administrators to enable an optional feature which would allow them to view anything inside their teams". They add: "When this feature is added, notices will be visible to all members on teams where it is enabled." Keywords: optional & visible. That's exactly the kind of thoughtful consideration made obvious when you first use Slack. The product direction on HipChat during the 6/8 months we've been paying customers has been disappointing. Instead of working on in-app history search or the other dozen of clamored for features (http://help.hipchat.com/forums/138883-suggestions-issues/filters/top http://help.hipchat.com/forums/138883-suggestions-issues/fil...), they pilled on a not really necessary audio/video call feature. I can only hope the HipChat/Atlassian team considers making admin access to private conversations optional and visible as well.
- bredren 12y agoAt least it isn't retroactive. I suppose workers need to assume any communication system that is provided by the company may be read at any time by management. The bummer about this is probably many people use private communications expecting them to stay that way. They don't realize companies like Hipchat do not have architecture to support data impermanence or encryption between parties. Nor do these companies go out of their way to highlight this, as people probably did not understand the distinction until recently.
- sorahn 12y agoMy friends and I are all using gitter.im to chat now. I just made a private repo on my github account and made them all contributors. Easy peasy. Also then we're already in the right program to paste code bits around when we need.
- samstave 12y agoGitter looks awesome - thanks
- eli 12y agoI get what you're saying, but we use HipChat and it's really obvious that it's "your company's chat system." At least, that's how our employees think of it and how it's marketed. I'd be really surprised if someone thought it was more private than their company email address.
- MetaCosm 12y agoIndeed. I suspect companies being started now will opt out of logging more and more. My companies employees work from home the majority of the time. We use Hipchat, Trello, Github, Google Drive, and Email for most of our communications. We limit what we log technically (auto deleted after X days email, no logging on most hipchat channels) and by corporate policy. We made an active decision to not store / log Hipchat and Email for a few reasons. We have a specific logged Hipchat channels -- but the rest just keep 75 lines for context and that is it. We also never have logged (nor ever will) the 1 on 1 conversations. Employees in a physical location can go outside and rant about a boss, family issue or other random noise -- and this isn't unhealthy, it is normal. We want to encourage open communication and straightforwardness -- and having communications "forgotten" is an important part of that. It also had additional benefits. 1. It limits the nightmare of discovery if we ever get sued, ever word every employee ever said won't be painstakingly scrutinized. Because we want the legal protection, we clearly spell out this privacy in our corporate documents so it is crystal clear to our employees. 2. It allows stuff to be discussed in context and in time and not being picked apart or misunderstood at a later point by other employees. Which encourages honesty and "getting it done". 3. It creates a "separation" of ephemeral communication that have a lower signal to noise ratio (our Hipchat today had many pictures of new desk layouts)... the important data leaves email or Hipchat and makes its way to Trello, Github or Google Drive.
- dccoolgai 12y agoThe forced arbitration seems a bit odious... general mills just got dinged for that and had to apologize...I wonder if the same thing will happen here. For those who don't know, forced arb basically gives them carte blanche to harm you and have the case handled by their "friends" instead of the justice system.
- debt 12y agoForced arbitration is a terrible policy and terrible for consumers[1]. I remember when Al Franken fought to amend the "forced arbitration" policy in the Department of Defense Appropriations Act[2]: "Jamie Leigh Jones is a courageous woman who stood up to KBR and Halliburton when they tried to force her into arbitration after she was allegedly gang-raped by fellow employees in 2005." It's a way for corporations to avoid being held legally liable for criminal behavior against consumers and employees. So if Atlasssian screws you, either as an employee or a consumer, you're forced into arbitration instead of being able to challenge them in court. [1]http://www.franken.senate.gov/?p=issue&id=211 http://www.franken.senate.gov/?p=issue&id=211 [2]http://www.naca.net/issues/forced-arbitration http://www.naca.net/issues/forced-arbitration
- ams6110 12y agoArbitration is not applicable in criminal behavior. It's for civil disputes.
- debt 12y agoI'd say gang-rape by fellow employees and KBR/Halliburton attempts to cover it up both fall under criminal behavior; at least it seems criminal to me. Who knows how many untold "civil" cases like that one have never seen the light of day due to forced arbitration.
- frankydp 12y agoJurisdiction would be the pressing issue in that specific case. I do not believe bases were sovereign at that time, and as the parties are not military they would not be prosecutable under the UCMJ. I am not certain on the process to charge someone with a crime while in a different country and outside US jurisdiction. I am not making excuses for KBR, but I do not know how else a corporation can protect itself from the actions of its employees in a scenario where jurisdiction is not enforceable in its host country. In other words what court would have heard this case, presumable it would have been Iraqi, in which case she would have had a much more difficult case. Sorry if this was a ramble, but the issue is very complex and has little to do with arbitration requirements, and more to do with vague international prosecution policies inside a war zone.
- nedwin 12y agoWe trust our employees. I don't feel the need to access personal communications between employees. We also give some oef our senior guys admin access so they can manage other users - I don't particularly want them to read my private communications with other employees either. I love Atlassian (go aussies!) and Slack is expensive. Bummed.
- coolsunglasses 12y agoWe use Slack at my company (switched to it from Kato) and we're very happy with it.
- fidlefodl 12y agoSame. Though, it seems a tad overpriced. It is a very nice platform though
- eli 12y agoWere non technical staff able to grok it? I recently went with HipChat over Slack mainly because Slack just seemed too confusing, but now I'm kind of regretting it. It took me a minute or two to figure out how to change rooms in the Slack Android app (it has menus that slide from the left AND the right).
- coolsunglasses 12y agoNobody I know has found it confusing, it's a mix of technical faculty. I've only used the desktop app.
- joshmn 12y agoYou mean the website-in-an-app-looking-frame right?
- coolsunglasses 12y agoYeap, but people like seeing the notifications when they cmd-tab and being able to remove a tab from their browser.
- ultimoo 12y agoThe title reads as though HipChat are releasing previous chat history to administrators although the ToS clearly states that this is not retrospective and only future 1-to-1 conversations will be impacted by this.
- espinchi 12y agoI tried my best not to word the title in a misleading way. Sorry if it still mislead you, though.
- shravan 12y agoSomewhat tangential to this story, but we recently moved our team over from HipChat to Slack [1]. I initially thought that we'd miss the sheer number of integrations HipChat offers, but Slack seems to cover almost all of the ones we use regularly and some HipChat doesn't yet offer, like Asana. [1]: https://slack.com/ https://slack.com/
- lobster_johnson 12y agoOur team tried out Slack, but the Mac app isn't native, just a rather weak wrapper around the normal web page. And the web experience just isn't as good as HipChat. Also, no in-app voice/video integration that I could find. HipChat's one-on-one video is great, although waht I really wish for is conferencing built in. Google Hangouts is just too annoying to set up (first it pesters me about signing up for Google Plus, which I don't want, then it shows a blank screen with a "start a hangout" button, then it opens a GH video in a separate window, which is just stupid), and doesn't have a desktop app.
- epayne 12y agoAll they had to write was "It’s been two years since HipChat joined the Atlassian family"... the rest is obvious. IMHO Atlassian is a company focused on helping enterprises control users of their software, not help them. JIRA's maddening UX is Exhibit A.
- samhoggnz 12y agoHow is JIRA's UX maddening? It's so highly configurable that it really depends on how it is set up, and what the patterns of use are within your organisation.
- liquidise 12y agoI would argue that "maddening" is an understatement. JIRA' ui tries to do so much and allows such granular customization that it takes an age of expertise in the tool to simply properly configure it to your organization. In fact, one of my college buddies job's is exactly that.
- 1stop 12y agoHipchat should have stuck gone the opposite, and made their policy explicitly: "1-to-1 is private". Mimic the real workplace, I have a 1-1 meeting with someone, it isn't recorded (usually). It's annoying, because it puts up barriers to communication, people talk differently when they know they are being recorded. I hope they implement this as an option (like they do room history). EDIT: Thinking more, it should be an option, and when enabled/disabled, all users should receive an email explaining the change. (If you are reading bitbucket devs, do it! Please!)
- seanmcelroy 12y agoI'd expect an organization who pays for the service should have access to their data in it. If you fear the change, you really fear the people who are or will someday become a service administrator. If you fear that, perhaps you should consider if you're really happy where you are. I'd suspect you either have trust issues with your corporate or IT management, or you work at a place that moves too slow for IT to have anything better to do than troll through private chats. In many cases, IT can already do a lot of other things like span your port, read your e-mail, shadow your terminal, capture all printer output, etc. But in practice, this kind of permission is usually used when someone is stuck and an employee unreachable or out on vacation, or an employee is terminated and you need some critical piece of information they might have in their chat history.
- nedwin 12y agoI pay for the service for my company. I trust my employees. I don't want them to think I'm snooping on their personal conversations between each other.
- teacup50 12y agoYou also control the routers, the email server, any other form of digital communications, and possibly even the software in their desktop. What's the difference? Just because an employer can snoop -- and might be legally obligated to snoop -- doesn't mean your company can't have a clear policy regarding when and how you will exercise that ability inherent in owning infrastructure.
- nedwin 12y agoWell most of the team is remote and we use Google Apps which doesn't allow email access (as far as I can tell, at least not without changing passwords and a few other tricks). There is a difference between having a feature which allows someone to view your private chat logs (something Google Apps doesn't have) and what it sounds like HipChat are implementing - though maybe they're going to make it just as difficult?
- ajsharp 12y agoSlack tho.
- codemac 12y agoThe binding arbitration clause is predatory and an unfortunate addition to their terms.
- vodo 12y agoI guess that's one way to lose your customer base. We have a team of 50 that will be switching to another platform shortly. Good bye HipChat...
- teacup50 12y agoWhy do you care? If you ran the chat server locally, you'd have the ability to snoop already. Atlassian themselves could snoop on your traffic; the only thing stopping them is their terms of service. All you have to do to protect your employees is publish clear guidelines on when and how your company will access employee communications on company-owned infrastructure -- bingo, problem solved.
- vodo 12y agoBecause this isn't communist Russia/China. There is a certain level of implied freedom and privacy here in America. That's why I fucking care.
- balls187 12y agoWhile this is probably helpful in some situations, my expectation is that like monitoring interwebs traffic, most tech companies don't care and won't bother. This is really only something that probably matters if company has to take legal action and needs the CYA.
- eli 12y agoProbably true, but I think a lot of Atlassian customers (maybe most) aren't tech companies, but tech departments within big enterprises. I think most big companies actually do have web and email monitoring in place.
- balls187 12y agoAgreed they have monitoring in place, but I'm curious how many actively review it on a day to day basis. I know my company has web monitoring in place, because we got a note about people using their cell phones to access raunchy sites while on corp-wifi.
- leetrout 12y agoI don't see much positive coming from this. At a previous company a round of firings were commenced with evidence contributed from HipChat logs... That was followed by a rash of everyone using the XMPP interface so they could encrypt their chats- I thought that was a bit much but now their paranoia has been proven wise...
- eli 12y agoPeople were typing incriminating things in a chatroom on your company's HipChat server? I could believe that they were surprised management decided to track what they were saying, but I can't believe anyone thought HipChat would protect chatroom logs against the account administrator.
- leetrout 12y agoThat's what we were told at an all hands meeting to squelch the morale decline after a handful of people were sent packing... That they were being poisonous in a group room and it backed up allegations about their behavior. I was surprised at the same foolishness. But it's inline with the story we were told about their rather cavalier attitude about coming to work inebriated and abusing substances on company time. I didn't know any of them at take the information at face value- the message was don't come to work high and you won't get fired. The takeaway was don't brag about your activities on the company HipChat...
- matthewcford 12y agoI don't see how this is relevant, if it was bad enough to warrant being fired, logs or lack of them wouldn't have helped. Sure they might have acted as evidence but there was probably other evidence of the actual action?
- KillerRAK 12y agoWill have to give hall.com another serious look...
- alexnking 12y agoI wish there were more companies that were more worried about doing the right thing than serving their paying customers. Especially when those customers are businesses who want to snoop on their employees, or ad agencies that want to sort through your mail. I'm tired of constantly being screwed over by any company that I'm not paying directly.
- jypepin 12y agoDoes this applies even if no chat history is being saved?
- mullethunter 12y agoThis is garbage. We have over 250 people using Hipchat and we use the 1:1 as the way to vent outside of the rooms that we're also part of. Better? I'm an admin and I'm so pissed that they decided to change a feature that I sung praises of for so long. Just like another company tool, we'll start to use another outlet to "really" communicate to each other while the HipChat rooms will be relegated to PMs and business owners fishing for updates.
- cjbarber 12y agoWell, it was great while it lasted. I'm working on compiling a list of alternatives right now, and will edit this comment in the next few minutes. Edit: https://github.com/cjbarber/hipchat-alternatives https://github.com/cjbarber/hipchat-alternatives
- Zigurd 12y agoI don't know if you can blame Atlassian for being "anti user" here. In some businesses and government settings data retention is a regulatory requirement. It's not ideal. It doesn't fit human patterns of communication. There are obvious back-channels. So systems like that catch only the dumbest violators. But Atlassian probably has customers who are required to specify communication systems that can be monitored.
- Maxious 12y agoeg section 802 of the Sarbanes-Oxley Act https://en.wikipedia.org/wiki/Libor_scandal https://en.wikipedia.org/wiki/Libor_scandal shows the value of logging private IM in a financial context.
- eddieroger 12y agoThis seems like an appropriate time to remind everyone that your work email belongs to your boss, not to you. Don't send private emails from your work account. Likewise, your work laptop isn't yours, it's your employers. Don't do personal work on it. My team tested out HipChat, and it's rad, but I had trouble convincing anyone it was worth the cost over terrible Lync, which we already have, despite it's complete lack of stability on the Mac. We're now secretly using Slack, and enjoying it pretty well. The "native" client is also really nice, bringing just enough native experience to a web view.
- lchengify 12y agoI wonder if they will implement a "off the record" feature similar to Google Chat. Even if the company has access to private chats, some legal departments recommend their employees not use chats or emails for certain correspondence.
- etchalon 12y agoI sent the following email to HipChat: As an employer, and account holder, I am not a fan of this feature. My team must feel free to use our internal communication tools to have private, perhaps critical, conversations between each other without worrying about me, or other members of management, from reviewing them. If the tools cannot be trusted, employee will not use them. If they don’t use, they’ll revert to other methods of communication, which will consume their attention. This should be an option, and one whose affect is in plain view of users. Lacking such an option, or clear disclosure, I will be canceling our account, as well as reviewing my companies use of other Atlasssian tools. Please reconsider this feature, or at least, reconsider its implementation. Thank you.
- awicklander 12y agoI completely agree with you on this. I can't imagine continuing to use hipchat with this change in place. This was pretty stunning at first, but after thinking about it my guess is simply organizations that use Jira are the kind of organizations that want/need to keep tabs on all employee communications. Which hey, I get that for some companies they need that for one reason or another. What it says to me more clearly than anything though, is that Hipchat's core customer isn't small teams any longer. It's large enterprises with lots of seats.
- jsmeaton 12y agoThanks for doing this, please keep us updated if you get a response that you can share. Our team has just switched back to HipChat as we have more and more remote workers. I'm the current owner of the account, and I don't want the ability to be able to read private chats. I don't want anyone else taking over as owner being able to read my private chats. By all means, allow it as an option for customers that feel the need to spy on their employees, but let us turn it off.
- teacup50 12y agoI don't get your concern at all. We run local e-mail and IM servers; the only thing that protects user communications on company owned infrastructure is our company policy. How is this any different? What I find far more alarming -- and quite hypocritical from SaaS users seemingly suddenly concerned with privacy -- is that when I communicate with companies and individuals that use SaaS providers like Google Apps, the party with which I'm communicating implicitly shares my private correspondence with a SaaS company that engages in massive cross-internet data collection. By comparison, employers having access to data that flows over employer-owned infrastructure is barely worth mentioning, has been the status quo for decades, and I'm absolutely stunned that anyone is shocked by this.
- bowmanb 12y agoWe use Flowdock. We're happy with it and it's actually quite fun (custom emojis are a blast). I would never consider using a chat client with this limitation and strongly consider not working for anyone who does.
- powdahound 12y agoHey everyone - Garret from HipChat here. I'm sorry for the way we presented this information. We definitely should have explained these changes more clearly, because they do NOT mean that admins can browse your 1-1 chats. Our blog has been updated with a better explanation: http://blog.hipchat.com/2014/04/25/hey-were-changing-our-terms-of-service/ http://blog.hipchat.com/2014/04/25/hey-were-changing-our-ter... If you still have questions or concerns, feel free to email me directly (address in profile here) and I can answer them or put you in touch with someone who can.
- officialjunk 12y ago"Under the Atlassian Privacy Policy, HipChat administrators will have the right to access all information in the HipChat account they manage, including 1-to-1 chat history and files shared in those 1-to-1 chats." I'm still reading this as admins have access to our 1-1 chats...
- powdahound 12y agoIf you've signed a policy with your employer giving them access to data in the services they pay for, we will have access to provide them, just like they can with the email account they provide you (if they do). They won't be casually browsing your chats, as that is not a feature we provide.