Larger companies usually have the budget, tools and expertise. But even then there are lots big companies with mediocre security too.
Larger companies usually have the budget, tools and expertise. But even then there are lots big companies with mediocre security too.
All we can do is assume that Slack cares about security enough to be sufficient. Last I checked, they didn't have any form of compliance certification, yet HIPPA, PCI, etc. compliant clients use them without reservation.
I was also a bit surprised what they consider out of scope for their bug bounty program: https://hackerone.com/slack
They've sent bug reports with credit card data they've typed in during a phone call through a variety of insecure methods.
They've also written people's credit card info on sticky notes.
Trust me, the horror that is card data and a call center is scary.
Compliancy only tells a story about management and how many MBA's you have, it doesn't actually mean you have good security. Only being compliant isn't going to help you not get data leaks or data loss!
And, for better or worse, you need your service providers, including chat, to be compliant. If your company were to leak PII via Slack, your company would be in pretty hot water for putting PII on a non-certified service provider.
At least if it were certified, you could say "we've done our due diligence to protect people's PII". Perhaps only important to leadership and lawyers, but still important.
I don't assume it. I know it for a fact; I've met some of their team and I know others by reputation. And I'm not exactly a slouch when it comes to this stuff (I don't eat and sleep crypto but a large part of my business is building secure infrastructure/consulting on the systems running on that infrastructure for regulated as well as non-regulated environments).
Which is more secure?
A) Slack.
B) Open source software on a LAN accessible only through physical entry, SSH, and/or a VPN.
Then I suggest you put more effort into securing your LAN situation because that is a vote indicating your belief your workstations are insecure.
There's no question that Slack's budget is greater than my own. They have a large, full-time security team. I have a bit of attention from myself or a colleague when setting a system up.
There's also no question their expertise is better. These are life long security professionals with direct experience at other SaaS companies.
If you use a service, you're outsourcing your security to perhaps more competent people, but you're making yourself a larger target.
Self-hosting makes you a smaller target, but you're taking all the risk on yourself.
Neither is a panacea.
I'm not exposing it to the WAN, just the LAN. :\
I don't think people really appreciate how massive of a security difference that is. It doesn't matter how big your budget is if you sit on the WAN all day. Someone will _always_ tag you eventually.
LAN with hardened VPN/SSH setups are virtually impossible to get into in a software-is-at-fault kind of way. And even if they did, they'd then have to launch the attack from someone's workstation at which point you've already been compromised anyway.
Oh, and then to get to the chat service they'd still need to break the security of an open source chat service which is non-trivial.
The majority of non-trivial breaches involve some sort of pivot or lateral movement inside the "protected" LAN. These often originate from a workstation.
I'm not saying it's safer to self-host. There are a ton of foot-guns with operating your own IRC server.
If your network and/or workstations are compromised, it is _over anyway_ because they have all your data. This is one of those situations where you are saying "What if they decapitated me? Slack might still be secure."
I mean, technically, you are correct but it isn't relevant because you are dead.
If you think such a business can survive a pentest from an employee workstation...XD