Your Slack DMs aren’t as private as you think - Vox (www.vox.com)
from Five@slrpnk.net to privacy@lemmy.ca on 08 Feb 2024 08:23
https://slrpnk.net/post/6510360

Pocket Link

#privacy

threaded - newest

autotldr@lemmings.world on 08 Feb 2024 08:25 next collapse

This is the best summary I could come up with:


But the popular messaging platform — which boasted more than 12 million daily active users as of last year — is definitely a promising medium for employers, regulatory agencies, the government, and even hackers seeking a trove of data about a company and its workers.

“Clearly, the adage of ‘Don’t write anything in an email that you wouldn’t want to see on the front page of the Wall Street Journal’ applies to your use of Slack too,” Harris told Recode in March of this year.

Companies may need to consistently preserve electronic communications for review by regulatory agencies, such as the Securities and Exchange Commission (SEC) and the Financial Industry Regulation Authority.

In its most recent transparency report (which covers 2020), Slack says it received 38 requests from US government entities for both content and metadata, including through search warrants, subpoenas, and court orders.

Keep in mind, those numbers are pretty small; the company said in its last earnings report that it had more than 150,000 organizations paying for its service, and customers can also use the platform for free.

In 2019, Slack granted one request for non-content, user data stored in the US from an unnamed foreign government as part of following a mutual legal assistance treaty.


The original article contains 1,737 words, the summary contains 208 words. Saved 88%. I’m a bot and I’m open source!

Max_P@lemmy.max-p.me on 08 Feb 2024 09:00 next collapse

That really shouldn’t come as a surprise to anyone that’s used enterprise software. There are all sorts of industries where auditable communications are legally required and of course it’s stored for a long time and of course it’s all exportable. Not having the ability to do that is a legal dealbreaker for a good chunk of the bigger companies.

You shouldn’t expect any privacy on the company’s premises or any of their computer systems. It’s theirs, not yours, you’re a guest and you should assume everything is recorded.

NightAuthor@lemmy.world on 08 Feb 2024 09:24 collapse

Though slack does require legal justification iirc for them to give private chat records to the company.

I realized this when I went to make channel MyChannel on my student orgs slack, but couldn’t bc the name was already in use. But I couldn’t find said channel, and my account was now the primary owner of the workspace. So I read through some of their documentation, and yeah… it’s made with some concept of privacy for employees.

huginn@feddit.it on 08 Feb 2024 12:59 collapse

Only if you’re on the free plan.

Enterprise plan? Enterprise audit logs. You can see anything and everything whenever you want if you’ve got high enough access levels.

Obi@sopuli.xyz on 08 Feb 2024 09:17 next collapse

I always assumed anything I put in slack could be read by the overlords.

LemmyIsFantastic@lemmy.world on 08 Feb 2024 12:07 next collapse

Because you apparently aren’t a moron. I can’t believe some poor bastard was forced to write this garbage.

Duamerthrax@lemmy.world on 10 Feb 2024 06:06 collapse

Assume anything that doesn’t have point to point encryption to be read either by a human or an algorithm that doesn’t understand context and will put you on a list.

LemmyIsFantastic@lemmy.world on 08 Feb 2024 12:07 next collapse

Who the fuck is this stupid? And they wasted time writing an article?

It’s a fucking enterprise communications tool. Of fucking course it’s monitored.

aniki@lemm.ee on 08 Feb 2024 13:24 next collapse

This article is outdated. The status page has been removed. As well as the blog post that outlines advanced analytics. I stopped reading at that point.

DebatableRaccoon@lemmy.ca on 08 Feb 2024 17:08 next collapse

I would like to know who’s stupid enough to think the service would be private. Mostly so I can avoid them.

scytale@lemm.ee on 09 Feb 2024 03:53 next collapse

My employer literally notifies employees regularly that slack messages aren’t private.

spez_@lemmy.world on 09 Feb 2024 04:03 next collapse

We’ve used Slack DMs to fire someone

Lemmchen@feddit.de on 09 Feb 2024 22:29 next collapse

I’m still looking for an open-source, self-hostable, E2EE alternative to Slack. My last attempt to find something basically only brought up Matrix: feddit.de/post/8502516 (Does Jerboa have a way to copy the correct !syntax of a post?)

jenny_ball@lemmy.world on 10 Feb 2024 02:37 next collapse

i also looked and found nothing.

aodhsishaj@lemmy.world on 10 Feb 2024 03:26 collapse

Mattermost

Encrypted in transit and at rest

docs.mattermost.com/…/encryption-options.html

Lemmchen@feddit.de on 10 Feb 2024 13:31 collapse

No E2EE

aodhsishaj@lemmy.world on 10 Feb 2024 14:20 collapse

docs.mattermost.com/…/encryption-options.html

Lemmchen@feddit.de on 11 Feb 2024 11:37 collapse

I repeat: No end-to-end encryption

LillyPip@lemmy.ca on 10 Feb 2024 04:18 collapse

‘Your [literally everything connected to the internet] is not as private as you think.’

Fixed that for them.