Slack closes account of an Iranian user living in Canada
twitter.com
twitter.com
Using a proprietary protocol that doesn't allow any form of federation is an unacceptable way to build a global community. Please consider using an IRC based service for group chat or an XMPP based service where 1:1, history, rapid reconnects, and other more complex chat features are required (yes, if you're a dev you have to use XML which is annoying, but overall it's a well designed protocol, so get over it). This lets you host your own, and (in the case of XMPP at least) if one person wants to use a U.S. based service and another is in Iran they can just sign up for a Belgian account (or wherever). We can't afford to let he internet splinter off into siloed tiers based on nationality.
I tried to download and run Jitsi a couple months ago for a project and it's voice quality was terrible. Skype just works. I sometimes have weird quirky bugs with Adium, and it's getting harder to justify telling my team to use it.
Get hacking folks. This space needs better tools.
I tend to think that we don't need more small community projects, we need one or two entire services like Slack to build themselves on the base protocols and federate. Even if they only allowed their own clients so that they controlled the entire experience, if they just federated with other servers it would give users a choice and largely solve the Slack problem.
We should start by admitting that Slack beat IRC. Beat it like a cheap hallway rug. IRC was always a terrible experience for novices, and it wasn't a great experience for experts. That it had any users at all is a testament not to IRC, but to what it enabled. Slack found a way to provide the same value but with a much better user experience. And then they rapidly iterated on that experience, making it better and better.
They started out with IRC and XMPP bridges. But they eventually shut those down because they were a drag on improving the product. When faced with the same choice, IRC kept the original protocol and shut down improving the product. This was an understandable choice, but one that set up the situation where commercial developers could come in and do something radically better. Open source needs to figure out how to compete with that, or things like this will keep happening.
I guess it lacks persistence and access to history? But there are surely ways to solve that.
Yep.
> there are surely ways to solve that
Most common solution is to use something else.
persistence, history, search, rich formatting, image previews, synchronization between devices, usable mobile clients, group/here/channel mentions, channel directory/search, channel descriptions, file upload/sharing (XDCC is not this), multi-line/expandable messages (eg, paste code or logs without flooding the channel), user status (away/DND).
Some of this can be approximated with bots, of course, but there's a lot of extra work then required to make that work (namely, setting up, writing and maintaining the bot). Some of this can be done client-side, but then you have inconsistent experience.. you don't know if the other user is going to get the image preview or if their client understands markdown or some other formatting, or is going to interpret and display your message using some other markup format. Some of this you can also work around with one of those persistent IRC connection proxies, provided each user gets one and that is also maintained by somebody.
Eventually someone packages this stuff all together for simple deployment.. and basically creates a bad clone of Slack, but with 10x maintenance requirement and so many more things that can break.
For example my app https://quasseldroid.info/ which requires you to run the https://quassel-irc.org/ bouncer, but provides all that. As well as IRCCloud and Weechat-Android, which are also very awesome and provide a similar amount of functionality.
The other features are atm a work in progress.
I wish I could do more, but in the end, I’m just a single developer improving the usability of a single app in my free time.
For open source non-centralized solutions to compete with the proprietary options, you need lots of devs and even more funding. Matrix/Riot.im has that, and even they aren’t close to where Slack is. Most of us IRC devs are either getting nothing, or, as e.g. in my case, the donations don’t even cover the server costs.
In the end, if people want open solutions to grow, they need to put their money where their mouth is.
Are we complaining about price or are we complaining about proprietary services?
I hate Slack for open communities as much as the next person, but IRC or fixes on top of it aren't really the solution.
And re IRC, I gather that Sabu got doxed based on EFnet logs from the late 90s.
You could say IRC could do anything any other chat program does, but it doesn't.
Doesn't IRC file sharing involve directly connecting to individual users to transfer the file, instead of those users choosing to download it at their leisure? And if you happened to be offline at the moment the user shared the file, can't you never download it unless you ask them to resend? For large, asynchronous groups, that is untenable. Slack's file sharing works because Slack hosts the file.
Also, basic messaging features are indeed missing from IRC. How do you do a private group chat? Like an SMS group thread? Doesn't it only support channels and then individual 1:1 DMs? Slack has ad-hoc group DMs. On IRC you'd have to make a new channel every time. It's like getting a conference room every time you want to talk to more than one person at once.
Slack also does voice and video calls, and screen sharing, and it's really quite good at it (feels light, not bloated). Sometimes talking with someone needs to turn into a face-to-face call.
Google SSO/SAML
Threads
But mostly access to history and search. (Note that it's not coincidence that this is what differentiates the free from paid Slack.)
We can talk about all the other issues around persistence and UX but just getting started is something beyond the vast majority of computer users.
It’s really hard for us to remember and empathize with this.
That being said, I wish there was a better open source alternative.
If we want people to use principled technology, then we need to be able to honestly advertise products as "it's just as good as X, and also doesn't violate [your privacy|human rights|the environment|etc.]" If we have to say, "It's not quite as good, but..." then we're dead in the water. (Side note: I switched to Firefox out of principle and I'm hopeful it will hold the line on market share, since it really is just as good as Chrome.)
The issue is that we're dealing with corporations who aren't just rich and powerful, they are also innovative, agile, and laser-focused on providing consumer value. Slack is doing an amazing job at serving their users!
You wrote, "we have to find ways to make better apps built on top of open protocols." It's a really interesting dilemma and I suspect it's one that isn't solved by better technology, better design, etc., but rather by addressing the base economics of the situation. We need a scenario where principled, open-source, ethical technology is generating the kind of investment we're seeing in Silicon Valley unicorns so they can innovate the same way.
What I find a lot of people miss when comparing Slack to IRC, is that not everyone using Slack is a developer. The world doesn't consist solely of developers - and if your company is 30% of engineers, and the other 70% doesn't have the reserve to wrestle with XML, then your company is using Slack. Otherwise, you are simply choosing to sell out your friends and family in the name of "principle" as well.
Personally, I'm tired of the comparisons to IRC and XMPP. Both are garbage - time and time again its been show how difficult it is to create greate software on these protocols. Contrary to your final statement, there have been better open source applications - gitter and riot come to mind.
I know plenty of non-technical people who chatted on IRC who were not developers. They just used the mIRC client on windows to do that. They also managed to configure their email and news clients to send and read email and browse usenet.
I simply don't understand where the idea of needing a technical background came from for using something like IRC.
You don't have to be a developer but you do need a level of technical background higher than that of the average computer user. There are plenty of tech-savvy, non-developers who can get up and running with things like IRC. There are plenty more non-technical users who can't. Or at least wouldn't given the learning curve time commitment.
I'm the only person in my family who would be able to sign on to IRC in under an hour whereas they'd all be able to have slack up and running in a matter of minutes.
Unless the technical skill of the average computer user has decreased substantially in the last 10 to 15 years, that shouldn't really be the case.
Disclaimer - A FLOSS dev here.
If you were talking about using these protocols over a telnet session, then I would be more inclined to agree with that statement, but just installing an application, entering a server name and account credentials (the latter of which aren't needed for IRC), and connecting isn't any more difficult than creating an account on slack and connecting by entering the address in the browser.
Regular users have amazing blind spots. Also you’re not giving slack enough credit for their smooth onboarding process.
Of course, but I don't think that Slack has done a better job with this compared to previous solutions. In a lot of ways, it's worse given its performance issues. For example, I never experienced UI lag in a chat application until I used Slack (comparing it with UIs like a GUI IRC application, AIM, ICQ, MSN messenger, Yahoo messenger, Skype, etc). Second, auto-completion and search do not work like they do in previous chat applications (or other applications in general) due to infinite scroll and the default of doing a global search instead of just limiting it to the chat or group. Third, the fact that you're forced to join some channels because you were invited or can't leave a channel because you're the last one in it are other issues that come to mind.
As much as it annoys me too, it appears that people actually using it have enough tolerance for it that it doesn’t matter.
It's amazing that when it comes to computers, it is somehow acceptable to be dumb. It's acceptable to not learn new stuff. It's acceptable to not read in order to understand stuff. As can be read in the comments here.
The whole ethos of startups and Silicon Valley has been around finding a market for your product. If people don’t want to use it then you can’t blame anyone but yourself.
Feel free to chat with yourself using an ideologically pure system... it’ll be lonely though.
Granted, I have not used IRC for a while, but last time I checked, the story for getting message history was "start a irc client inside a screen session on a server you own". And there were no mobile at all.
(I remember writing a script which exported chat logs from my desktop client to text files available over HTTP... I'd then visit those pages from cell phone to see if I had any more messages. This is not the experience I would wish on anybody)
It was pretty much the same thing with newer chat services like ICQ, AIM, MSN messenger, etc. (though I think they started offering offline messages in later versions).
As for mobile, my older Nokia phone had a Symbian IRC/XMPP client that I could use without any issues.
In the same breath though, saying, "I'm not willing to sacrifice convenience in the name of principle" is also a privileged position, because Iranians who live in the US/Canada are currently being banned. Convenience is something we can address in the future, but bans aren't.
The concerns people raise about Slack -- that until very recently it wasn't blind-friendly, that it takes away control of user data, that it can arbitrarily ban companies and users for any reason; none of those are theoretical deontological postering. They are entirely practical in the sense of, "there are people who are affected by this who can't join your community because you're not using a tool that's accessible to them."
I think that it's easier and preferable to teach my friends and family members to use open tools than it is to use something that blocks people of Iranian descent from participating in my community. Yes, that means my communities will be less accessible to tech-unsavy people. But that's a problem I can try to address in the future. I'm OK making their life harder for right now if it means not permanently banning people based on a random company's whims.
That is selling people out, in the sense that it's making a calculated decision about which people are most important to support right now. But if the Go community is using Slack, they're making the same exact same decisions to prioritize accessibility for some people. They're just choosing different people.
An example of how it might be possible to push this in the right direction is LEED. It didn't matter what the individual environmental ethics of people manufacturing electronics and designing houses was. Environmentally efficient building practices cost more, and there was no way for all the companies involved to form an opaque conspiratorial cabal to secretly impose the cost on consumers who would rather not pay it. Instead, they created LEED and used marketing to teach end consumers that LEED stood for more environmentally responsible practices.
Right now computer privacy and security are huge in the headlines, and a large number of people in the public and in industry want to do the right thing. But consumers don't know how to make the right choices, and companies aren't going to spend extra on the right thing if users are just as likely to choose something horrible. What companies need in order to invest extra capital in privacy and security is a plausible story of how to get users to choose the right thing and pay a bit more for it, if the industry builds it. They need a LEED standard for privacy and security. Then they can promote it and use it as a way to justify their investment in better, more ethical software. Corporations, schools, nonprofits, and other organizations can be pressured to make public commitments to use, or at least prefer, software that meets the standard. This won't drive horrible software out of the market, but it will create a sub-market where good software can survive.
Obviously laws and regulation are the bedrock, but in areas where consumers have a choice, we need to make it easy for them to make the right choice if they want to.
More to the point, there is always going to be some value-added service a profit-seeking enterprise is going to be able to provide over what's freely available. If we built IRC 2.0, then Slack 3.0 will provide what everyone hates about IRC 2.0 and then the dynamics of profit seeking will drive Slack 3.0 to divorce from the free alternative.
We see this pattern over and over and over again. It doesn't happen necessarily because businesses are being ruthless, but because there's always going to be a market space, even in the face of a fantastic free service. That's just how a market economy works.
A good example here is Firefox. When it started out, it was better than the competition. Chrome pulled ahead for a while, but Mozilla responded and now it's competitive again. And Firefox has done this while advocating energetically for an open web.
Another one that interests me is WhatsApp. They built a messaging product that was clearly superior to the alternatives. They eventually sold out for billions. But there's no reason they couldn't have done that as a nonprofit. And Signal has shown that a nonprofit can still jump into the space and do good things.
In which world does it beat IRC? Number of users? That's not even sure, since there are dozens of thousands of IRC servers worldwide. And that's not even counting the private, self-hosted IRC servers.
IRC runs everywhere and does not need a fat browser or a RAM-and-CPU hungry application to enable "chat".
As for the user experience, this would merit a whole post in itself, but Slack sucks in many ways: threads are completely unusable, channels are hard to discover unless you know about them, and now Slack makes you pay for searching thru your past messages.
I'd say there is a lot more to this topic than "Slack beat IRC".
As far as I can tell, Slack has an order of magnitude more users. They were at 8m DAU back in May: https://techcrunch.com/2018/05/08/slack-hits-8-million-daily...
IRC was in long-term decline even before Slack: https://royal.pingdom.com/2012/04/24/irc-is-dead-long-live-i...
So my best guess is that Slack has at least an order of magnitude more users.
But users is not exactly the metric I'm thinking of. It's when people say, "We need some way for us to communicate," Slack is the popular option. Even though I'd rather not use it, I'm in 8 right now. If you look through this thread, you'll find plenty of people concerned about how prominent it is in the open-source world, IRC's home ground.
> IRC runs everywhere and does not need a fat browser or a RAM-and-CPU hungry application to enable "chat".
I get this in theory. But RAM and CPU power are fantastically cheap. Conserving them to get a worse user experience is optimizing for the wrong thing.
> but Slack sucks in many ways
Sure. There are no perfect things. But Slack doesn't have to be perfect. It just had to be better than the competition. And for most people it manifestly is.
The obvious advantages versus classic IRC clients: it's always online and the connection happening through their servers you get good push notifications on mobile.
The obvious advantage versus Slack: they don't own the IRC networks you're connecting to, so if you have issues with IRCCloud you can just change to another client.
It has some missing features, most notably search in archives, but they are working on it.
>> "admitting that Slack beat IRC"
Sure but are we talking about a fundamental limitation of the IRC protocol, or are we simply talking about implementation details that can be fixed?
Who the hell cares? I figured out IRC when I was about 12 and I'm no genius. If that bar is too high for people in tech then we have serious problems.
Our school had nothing blocked, and the computers weren't locked down at all.
But Slack isn't solely used by technical people. Where I work, everyone is on slack - product people, lawyers, tech people, etc.
I too figured out all sorts of computer things at 12. By standardized tests, I'm also in the top 1% of ability for things like that. And my dad was a programmer then, so I had a leg up.
At some point, I realized I had a choice. I could feel smug about my (narrow) genius and focus on tools for my (narrow) cohort. While grumping, of course, about how stupid everybody else was. Or I could recognize my luck and use it to make things that were good for everybody.
You know what helped me make this choice? Realizing how bad I was at so many other things. And how generous other people were in not only putting up with that, but helping me along.
Honestly, at this point, I can't really tell the difference between Slack and most "Slack clones" -- the interface of Slack has basically been copied by most people and to be honest it really wasn't that hard. Mattermost and Rocket.chat both look exactly like Slack to me.
Matrix could have done the same thing, but they chose to waste time and money reinventing the wheel (and doing a bad job of it) instead of focusing on the service and the clients.
If you have legitimate grievances with the protocol and feel you can see flaws in it, make an issue on the tracker now while its still a 0.x release, doesn't have the broad adoption you describe, and while the team (knowingly) can make breaking changes simultaneously released to matrix.org and riot.im and cover 95% of the users still.
There are no stable servers.[1] The reference server is being completely rewritten.
Matrix bridges work about as well as XMPP bridges in my experience.
[1] https://matrix.org/docs/projects/try-matrix-now
Pure-XMPP simply would not have worked.
(I have my issues with the matrix protocol, mind, but they had good reasons to create a protocol even so)
Edit: I also wouldn't be surprised if this is why facebook messenger switched from XMPP to a custom MQTT-based system.
I run an ejabberd server and for example the Client State Indicator (XEP-0352), which is one of the extensions that improve battery life for mobile clients, was experimental for a long time but at the same time also available for major servers (e.g. community edition of ejabberd) and mobile clients like Conversations (open source too).
So in my experience, the battery consumption of a modern XMPP client is quite good. When people are complaining about the bad mobile experience they are mostly referring to the time before the mobile extensions were built.
So apparently not everybody shares your definition of 'solved' - I appreciate the alternative opinion, but simply declaring it a myth is, I suspect, unlikely to convince remaining skeptics.
simply declaring it a myth is, I suspect, unlikely to convince remaining skeptics
It's hard to provide specific counter-arguments to anecdotal evidence repeated since back when gtalk was a thing.
[0] https://gultsch.de/xmpp_2016.html
[1] https://wiki.xmpp.org/web/index.php?title=Myths#Myth_Three:_....
The Matrix developers are familiar with XMPP, and have it covered in their FAQ: https://matrix.org/docs/guides/faq#what-is-the-difference-be...
Finally someone gets it! A chat service should value each message and it should never lose messages due to connectivity problems.
Thank you for sharing that link, I learned something new today.
- Person-to-person chat system. This requires offline messages: "when you get to work, please take a look at ABC-1234". Some people have cell phone as well, so this needs multi-delivery to all the clients (so you can read the message on the phone, then read it again from work PC)
- Support system: one person posts "I cannot run TOOL_Z", people who know reply. This requires offline history -- if I maintain TOOL_Z and I come in late, I was to see the question asked, answers, and maybe I want to contribute an answer as well. By the way, slack threads are super helpful for this.
- Knowledge archive: next person to have TOOL_Z problem would search the channel history, and find previous answers.
- Announcement with discussion: someone posts "New version of TOOL_Z is released! New features: ...". People might respond by discussing the new features.
All of those basically require "global database" -- those messages are not volatile things; it is not OK if the announcement is lost, or if you did not see the help request because there was something wrong with the system.
And I know that XMPP does not work for that because back when my workplace used to use XMPP (a few years ago), I went to https://xmpp.org/software/clients.html , installed "gaijim", and found out it has no offline message history, no message searching, and half-broken multi-delivery.
So we ended up building scaffolding - set up our own search engine, archive system, use different methods for communication. This was a lot of pain and very little gain. So when we had to re-do infrastructure from scratch, we went with Slack.
(Note that you can't just say: "I don't need those features". As long as there is a single person in the company who does not have history, the whole company cannot use pure XMPP for support system or knowledge archive anymore -- or that person would be excluded.)
As you said in other messages, things are better now -- there are compliance suites. So "XMPP Advanced Client 2018" does do what you want. Unfortunately, I cannot find a list of clients which support "XMPP Advanced Client 2018".
Also, there are people who confuse matters by saying that "XMPP does everything Slack can, and has tons of clients". No. "XMPP Advanced Client 2018" does everything Slack can but has very few clients. Regular XMPP has tons of clients but does not support everything that Slack can. It is very important to distinguish between the two.
The FAQ skirts around the fact that it doesn't matter if they're slightly different: you shouldn't make up your own new thing to force adoption of your commercial product. Use and improve the existing technologies that are "good enough" and stop splitting effort and making yet another standard that everyone has to try and support or run bridges for. This is unacceptably bad engineering. Saying "this is subjective" is true, but just an excuse for "we have not-invented-here syndrome".
Even Comic Chat was based on IRC, and that's as far from "user-unfriendly" as you can get https://en.wikipedia.org/wiki/Microsoft_Comic_Chat
No. They shut it down because they want people to use their (crappy) UI.
[1] https://datatracker.ietf.org/wg/mls/about/
Wire is open-source today and usable by regular people, with E2E encryption and email-only accounts.
Why not just use XMPP? Yes, everyone hates XML, but the protocol is well designed, has sustainable funding (via the IETF and XSF), and there's lots of experience out there, and it's flexible enough to develop services like Slack on top of.
https://signal.org/blog/the-ecosystem-is-moving/
"XMPP is an example of a federated protocol that advertises itself as a “living standard.” Despite its capacity for protocol “extensions,” however, it’s undeniable that XMPP still largely resembles a synchronous protocol with limited support for rich media, which can’t realistically be deployed on mobile devices. If XMPP is so extensible, why haven’t those extensions quickly brought it up to speed with the modern world?
Like any federated protocol, extensions don’t mean much unless everyone applies them, and that’s an almost impossible task in a truly federated landscape. What we have instead is a complicated morass of XEPs that aren’t consistently applied anywhere. The implications of that are severe, because someone’s choice to use an XMPP client or server that doesn’t support video or some other arbitrary feature doesn’t only affect them, it affects everyone who tries to communicate with them. It creates a climate of uncertainty, never knowing whether things will work or not. In the consumer space, fractured client support is often worse than no client support at all, because consistency is incredibly important for creating a compelling user experience."
But I do tend to agree in general that we need fewer features and less complexity and to push more for basic profiles that everything should implement and that have a clear compliance label.
Now we have uncertainty around which networks people use, which devices they use them on, and which features each network supports.
You cannot just tell people "go choose any XMPP client, and it will work fine". Instead, it is more like "get XMPP client, but make sure it supports XEP-1111, XEP-2222 and XEP-3333". And if you have multiple platforms (Android, iOS, Win, Linux), let's hope you can find a client for each.
For example, I used to use Mcabber with HipChat at work. Mcabber doesn't support even basic modern XMPP things (history, for example), but it was plenty good enough for me to chat with my coworkers.
For your work: Are you connecting Mcabber to HipChat server? Do you use native HipChat client as well?
From your link.
How did Slack figure out this guy's ethnicity / citizenship / status? Why are they allowed to access that information and unilaterally act on it? Sounds like there's a valid question being asked here to me.
Slack is protecting their multi-billion dollar business and their investors which are both based in the U.S. If they do not, they could run into trouble and put far more at risk. This does not only affect Iran, it affects other countries too which the U.S. has active sanctions against.
Now, I admit that visiting the countries on the list aren't on my to-do-list, but if for example I decided to make a vacation trip to Cuba I really shouldn't lose my account at any US-based service just because of that.
So you would make people suffer and think that they would blame their own government for that and not the US?
Don't you think that makes you and your country evil?
If true, it is definitely the worst way to do. It doesn't take into account any circumstantial evidence that could explain the use of such an IP address (vacation, VPN, BGP or a mistake in the geolocation data used) and Slack doesn't seem to offer any way to appeal or even inform other users about what happened to their contacts.
Slack should offer a configurable notification that could contain other contact methods to the banned user. Slack could also give those users at least sth like 48 hours to inform their contacts about what is going to happen. And it could offer banned users a downloadable archive of all content created to make sure no data is lost.
But the way Slack is doing it right now means that you can't trust them and one should really think about relying on their services in the future.
I am still on IRC and XMPP (Jabber) for good reasons ;)
I only discovered this because I was trying to use Google's CLI tools and got blocked, with the shocking message that access from embargoed countries was not allowed. I was utterly confused given that my server, myself, and anything to do with my hosting was all contained completely within the US. After studying the message and finally figuring out after some time the problem, I reported it to my host and they promptly submitted a correction to that, and the issue was resolved.
But had I somehow used this host to access Slack, I would find my own account deleted, if what is being deduced here is correct.
Deleting or disabling accounts is completely the wrong approach. The absolutely maximum that could be done is BLOCKING ACCESS (i.e., actually embargoing) from these restricted IPs. Disabling or deleting accounts is stupid and shows that Slack has a profound MISUNDERSTANDING of how the Internet works, i.e., it's not perfect. This is exactly akin to using an IP address for identification. IP addresses, and hostnames, are not identification of people and cannot nor should be used for these kinds of heavy-handed, punitive punishments.
The government could argue that any of these options is "doing business with" an identified, sanctioned individual.
I'm not saying it's right, I could just see a company attorney wanting to minimize potential federal liability.
She created the account while traveling in Cuba (legally) years ago and hasn’t been back to Cuba or any other sanctioned country since.
She is a cofounder of an org that uses Slack heavily and has now lost access to all her messages and files from the past couple years of work.
There appears to be no appeal process here.
If not, I am totally confused about how your response connects to what I wrote.
It's not completely arbitrary. Plus there're notions of estoppel potentially at play.
Two, they may have to at least return the data: if I let you use a desk at my place and you start doing business there, I am pretty sure I cannot legally refuse you entry and hold on to your papers.
Three, even if they are, we're also legally entitled to call Slack incompetent losers, and to tell our employers that we should not switch to Slack if we wish to continue being co-workers with Iranians. I will be telling my employer that shortly. (One fascinating aide effect of using Slack is thst the entire company must conform to Slack's policies. You cannot hire someone whom Slack won't create an account for, nor someone who won't agree to Slack's ToS, because if they're not on Slack they can't get work done.)
That’s not what the parent comment said, you’re twisting it with an assumption. Slack is not legally obligated to provide Slack accounts to anyone, that was the point.
> they may have to at least return the data: if I let you use a desk at my place and you start doing business there, I am pretty sure I cannot legally refuse you entry and hold on to your papers.
Your analogy is rather confused. The data Slack has isn’t equivalent to your papers that you dropped on their desk. When you sign up for Slack, you enter into a contract outlined in their Terms of Service that detail explicitly what they agree to be responsible for. In particular, here’s the agreement relating to your data:
“Following termination or expiration of a workspace’s subscriptions, we will have no obligation to maintain or provide any Customer Data and may thereafter, unless legally prohibited, delete all Customer Data in our systems or otherwise in our possession or under our control.”
Slack is legally obligated to provide Slack accounts to people who pay, with 30 days notice for termination in most cases. There is this stipulation:
> We may terminate the Contract immediately on notice to Customer if we reasonably believe that the Services are being used by Customer or its Authorized Users in violation of applicable law.
However, if they are terminating accounts based on ethnicity that doesn't seem like a reasonable belief they can use to justify applying export controls.
Rather, Slack agrees to provide accounts to people who pay and agree to the contract in return.
That little stipulation is exactly what is in effect here. Slack believes the users are in violation of the agreement, and under the legal rules that Slack established and controls, they enforce immediate termination.
> if they are terminating accounts based on ethnicity
This defending of the argument based on wild assumptions that Slack is ethnically profiling is a bad place to start from. That hasn't been shown, nor is it very likely.
On the other hand, Slack is legally obligated to block traffic to Iran, and it's within reason to assume an account that ever had any traffic in Iran broke the law. It's certainly possible that Amir forgot that he used an Iran proxy, or traveled there. It's possible that someone on his team broke the rule without his knowledge. It's also possible that Slack made a mistake, which can and does happen from time to time at many companies when trying to enforce international laws using only IP traffic logs. None of that points at Slack intentionally terminating accounts based on ethnicity.
And this point is untrue. As long as Slack provides accounts to the general public, they are required by law not to discriminate when doing so on the basis of race or national origin. They can stop serving everyone. They can firewall access from Iran, or identify actual persons covered by the sanctions. But they are legally obligated to serve Iranians as much as they serve anyone else.
> Following termination or expiration of a workspace’s subscriptions
One, this is an individual account, not a workspace. The workspace remains active.
Two, terms of service don't override law. There may or may not be law that overrides this and says that certain rights cannot be signed away. (For instance, if you're subject to the GDPR, my understanding is it would override it.)
Correct, agreed!
> As long as Slack provides accounts to the general public
Slack does not provide accounts to the general public, in any legal sense. Slack is a private business, not a public service. Please read the terms of service to understand the terminology.
> they are required by law to not discriminate
Well, they are required by law to discriminate against traffic to Iran.
But, again, you've twisted my meaning to make your own separate point. I wasn't talking about discrimination. Slack is not compelled by law to provide accounts to someone. They can legally refuse service to someone who lives in Iran, or connects to Slack from servers located in Iran.
> But they are legally obligated to serve Iranians as much as they serve anyone else.
That statement is true in the sense that Slack is under no legal obligation to provide their service to anyone, outside of the agreement they created. That is separate from and irrelevant to whether or not they're allowed to discriminate against the people Slack agrees to provide service to, under their terms of service contract.
> they are required by law not to discriminate
BTW, what law are you talking about specifically? I'm aware of civil rights for US citizens, and anti-discrimination employment law in the US, but not of a specific law that bars online discrimination. I personally believe discrimination online would be wrong and bad, but are you certain that it's illegal?
Keep in mind we're talking about someone in Canada connecting to a US service, with a plausible decent chance that he connected from Iran or through an Iran server and just forgot about it. I'm not aware of specific US anti-discrimination or civil rights laws that would protect Amir in this case.
Of course that argument has an opposing side as well, but it seems prima facie plausible as a cause of action.
I have to admit that this case (and some others I read in recent days, e.g. MailChimp account deleted: https://news.ycombinator.com/item?id=18715866 ) made me aware that the terms of some popular services can be much worse than I would expect. I should really start reading those terms. Thank you for helping me reduce my naivety.
> Generate a Slack “Export” file from Slack > Administration > Workspace settings > Import/Export Data > Export > Start Export.
If not maybe everyone can consider that maybe Slack’s actions for the Iranian guy have some basis other than “his ethnicity.”
Yes, it harms their customers, but that harm and the resulting damages to Slack' reputation (and maybe legal costs), is what they must pay for being negligent in the past.
Your analogy about grocery stores doesn't really work because logging into Slack isn't the same thing as walking into a grocery store, because buying from a grocery store isn't the same thing as exporting food across a national boarder, and because neither food nor medicine is embargoed.
In this case, if the account was actually opened from Cuba ... that could be a problem.
What they should do is offer recourse and a way to have this resolved.
So they are absolutely offering recourse and resolution, but only where it is in their power to do so.
TLDR: Don’t expect Slack to be responsive to arguments that contain “please ignore US law for my individual circumstances”.
This causes me to think about the metadata records they have held onto in addition to all the data.
I understand the complex legal frames that this exists in, but they appear to have the data to be way more precise here.
Or they did an IP to country lookup back then and kept the result of that rather than keeping the IP.
Companies should be made accountable for such blatant abuse of user data.
I am pretty certain I have logged into my mail, PayPal account and Digital Ocean account from countries embargoed in the regions my providers operate. PayPal I could lose without much fuzz, but jeez how I'd hate to lose access to my email.
This is absolutely ridiculous. I've opened up Slack while in Cuba to check on work things at my American company who does no business there. I don't have anything to do with our Slack bill and I'm a US citizen. So if someone goes to see their family in Iran/etc and just happens to open Slack they'll get banned? That's hamfisted as all hell.
[EDIT] to be on the safe side, I've also created a new workspace from said IP.
Lesson: keep backup of everything in multiple jurisdictions even if you are innocent like Jesus. You know what happened to him.
- Is this all made up to prove some point?
- Is this just how the US ticks right now?
- Is Slack just completely gone mad?
- Is this what companies believes is acceptable nowadays?
- Is this the future of the web?
The fact that I am not sure what to believe and that I wouldn't be surprised if this is all true or equally all made up is what really scares me. Ten years ago I would have had a lot more confidence and faith in the world that this must be either a big mistake or something fishy, but today I feel like anything goes and in a week's time nobody will care again :(
Unfortunately centralized silos also allow unprecedented convenience and ease of use. Nobody's figured out yet how to duplicate that in a decentralized or federated system.
> Is this just how the US ticks right now?
Yes.
Any sufficiently advanced technology is indistinguishable from magic.Add to that the dark side of being "data driven," which is that stories like this one are just part of the 1% of edge cases. These companies also try to move away from actual customer service as much as possible because human labor doesn't scale as well as automation, so you'll fall through the cracks as long as the news that it happened to you doesn't get enough press to make it worth an engineer's or VP's time.
I know that sounds extremely cynical, but having been on the inside in situations like this, I saw how these dynamics converged despite good intentions. Stuff like this is why sending engineers through front-line customer support rotations tends to dramatically motivate engineering teams to make quality of life improvements. Once you lose the detachment that indirection from the user gets you, suddenly those 1% cases feel more important.
This sort of thing is a temporary blip before everybody figures out decentralised solutions for everything.
Decentralisation is clearly the end game as long as politics causes problems like this. A decentralised solution will continue to "just work", while centralised solutions continue to boot people off. It's pretty obvious which one is going to win.
The distributed system does not stop to work then, but the user might risk punishment for using it, which might be even worse than not being able to use it.
The fact that you can't decentralize legislation and physical governance is not insignificant. You can't block the influence of preexisting powerful actors. Those factors do have the power to destroy the decentralization movement, and most likely will.
Maybe those "powerful actors" could prevent decentralization from becoming mainstream, but they can't kill it. Consider marijuana, for example. Use has been demonized for decades by the US and its allies. But that didn't stop an appreciable fraction of the US population from using (or at least, trying). And now it's becoming legal in more and more states.
For Internet decentralization, the driving factors will almost certainly be porn, gambling and prostitution. To the extent that they're driven off the clearnet, demand for them will fuel growth of alternatives. Freedom of expression is essential, of course, but it will be just a side benefit.
The more decentralization is suppressed by "powerful actors", the more it will be dominated by other "powerful actors". That is, by organized crime.
Maybe this trend will reverse eventually but I don't really see the signs yet. The Cryptocurrency crowd keeps shouting "decentralization" but they still fail to create applications that can compete with the centralized alternatives in terms of usability, performance and cost. There have been many attempts at making decentralized social networks but they failed to gain mainstream adoption. IPFS works pretty well but again, hardly anybody uses it.
I'm all for decentralization but there's no denying that there seems to be a path of least resistance towards centralized solutions. They're easier to develop, easier to maintain, easier to upgrade and often easier to use.
So for me decentralization is the objective, but unfortunately it's not "clearly the end game".
Regarding torrents, many game clients will use torrents for their downloads, the user simply doesn't see and deal with the torrenting.
Don't confuse self-hosted with decentralised, not the same :)
Again, this is looking at things backwards IMO. You seem to imply that there's a slow momentum from a centralized web to a decentralized one when in fact there's been a rather fast momentum in exactly the opposite direction over the past decades.
To me what you're saying sounds like "horses are about to become a very common way of moving goods". Maybe you're right but merely looking at the trend it's clearly not going that way at all.
>The backend is basically figured out at this point and we need to focus a bit more on UX.
You'll have to tell me more specifically what you have in mind there because that sounds very optimistic to me. We've had decentralized "backends" for as long as we've had the internet. The web is mostly decentralized by design. Even DNS is distributed across plenty of authorities for the various TLDs (even if each of them is effectively centralized and not anybody can become an authority).
Email is decentralized. BitTorrent is decentralized. IRC is decentralized. We're collectively moving away from these technologies, not towards them. I'm personally still a heavy user of all three of these things but it definitely feels niche now (email obviously isn't but self-hosted email is).
>Regarding torrents, many game clients will use torrents for their downloads, the user simply doesn't see and deal with the torrenting.
Which is pretty much irrelevant in this conversation then. It's about the technology people use to share content with each other, not about how Blizzard chooses to update your WoW client. It's a locked-down, vendor-approved way of distributing software from a centralized authority.
>Don't confuse self-hosted with decentralised, not the same :)
It's not the same but it's related. In general if something is truly decentralized then it becomes self-hostable otherwise it's more distributed than decentralized. Anybody can host their Bitcoin node, their Bittorent peer or their email server. I can't host a Facebook node.
Even on the technical side, most tech products have convenience as a selling point to being more productive/effective/agile, etc.
Even most of the very technically competent people I know are gradually moving toward central services. I'm part of a co-op of people with collocated servers. We started in 2000. We haven't had a new member in years, and we are gradually losing them. I'm at the point where I should replace my server, and I'm having a hard time coming up with reasons to justify the large capital expense and significant time cost versus moving it to somebody's cloud. And that's not even considering the benefits of moving to hosted services. Not worrying about spam, email deliverability, security patches, et cetera, ad nauseam.
I think part of the problem is that the "decentralize!" crowd is willing to put up with a lot of practical inconveniences as long as something conforms to their ideological desires. Their ideology may be perfectly correct, but until it has practical consequences, most consumers won't shift. So they're going to need to come up with competitive services that are better than the existing ones. Better not just to them, but to regular users.
Regarding your note on the path of least resistance leading to centralized solutions---Glowing Bear/WeeChat is definitely more work to set up than just signing up for Slack. You need a machine that runs WeeChat and get a TLS certificate so that the browser will let you connect securely. That definitely limits it to a somewhat nerdy demographic, even among the HN readers ;)
(Personally, I’m ofc biased, as I’m the dev of https://quasseldroid.info/).
But I think for these solutions to gain more mainstream appeal, we’d need to make the setup much simpler, and work on ideally making it a single-click solution for an organization to set this up for their members. And maybe even provide hosted services (similar to IRCCloud) for the many users that would rather pay than run their own servers.
Now I suspect we'll start seeing clones of facebook / slack etc but with a decentralized backend while offering all the features users care about seamlessly. This might take a while but it'll eventually come.
This is the future of a centralized web with products, services and companies that people salaries to develop products and services.
The decentralized internet utopia is dead. Stick a fork in it. It is a fringe populated by the modern equivalent of the grey beards of 1990s.
It will never happen, at least not on a scale that will affect significant web traffic.
There is another model, not decentralised but a practical middle-ground: the WordPress model.
Consider the following: Wordpress is an example of a profitable open source app that can easily be installed on countless shared hosting platforms or on a VPS. It's easy to switch hosting providers when you want to (and to take your data with you). It's popularity means that one-click installs are widespread.
Unfortunately, there is no common standard for software installation on the server side, and this lack of an easy installation process for everyone else severely limits self-hosting websites and apps.
Many developers think deploying a server-side web app is a non-issue, or they erroneously think that installing Cloudron/providing Docker instances/typing command line instructions are all "easy". Have you seen the server deployment instructions for "web friendly" languages like Ruby and Python? It's ludicrously complicated. And still developers seen nothing wrong in such install procedures. It's so frustrating.
I wish there was some momentum or traction in making server-side web app installation as universally simple as a one-click Wordpress install. It would also unlock countless opportunities for developers to reach more users or customers. But maybe some developers secretly prefer the complexity? It certainly makes selling a SaaS solution much more attractive over the stupidly complicated self-hosting option.
Only techies care about decentralization. Most people would rather follow a Twitter feed rather than an RSS feed. Most would prefer a mega forum like Reddit rather than multiple, standalone forums with separate accounts. There are also network effects that give centralized platforms more of a competitive advantage.
I keep hearing people talk about the need for decentralized social media, but nobody knows how to make it an attractive, viable option for the masses...especially when such a solution wouldn't be as profitable (or as frictionless) as Facebook, Twitter, etc.
What this all really does in the end is create a technical caste system and obfuscation of ownership. People fortunate enough to have access and be up to speed on the latest technology (or hire people who are) will reap the rewards of decentralized systems which still belong to authoritarian actors, yet it will be extremely difficult to prove that ownership--especially to laymen. It will always have a nice hazy deniability, and it will be almost impossible to hold anyone accountable for their actions, or prevent or even identify exploitation.
This is absolutely the future of the web. Perpetual and stealthy non-neutral manipulation by the technically advanced and financially powerful is here to stay. I think that as engineers our tunnel vision and intellectual hubris have given us a false sense of security as we developed this hideous system, because we thought it was some kind of purely digital realm where we have real control and real comprehension of what we are doing. But nothing is purely digital. Everything is built on top of the real, analogue world where strong actors have already divvied up and taken ownership of everything.
Iran has sanctions against it right now. Slack, and other companies that have done this sort of thing with Iran, Cuba, etc the past few years, are trying to stay on the right side of the law. To avoid imprisonment, fines, etc. If you think what they did is wrong, start a company and risk serving prison time to stand up for your what you believe in by creating a similar product and offering it to customers that have direct geographical ties to sanctioned and embargoed countries. I'm serious, imprisonment is a very real risk with dealing with sanctioned and embargoed countries.
Doing business with Iran, or a citizen of Iran, can open the door for all sorts of government investigation from fines, to being shut down for an investigation, to having data from other users compromised, to criminal prosecution of employees/officers of the company.
It's a lot easier to just immediately sever ties with anyone that has had dealings with an IP geographically connected to Iran than to go one by one "hey, you an enemy of the state? You sure you aren't? Promise? Cross your heart and hope to die? Ok, we believe you, we'll just hope you're telling the truth!"
Then there's the fact that Slack uses encryption at rest and in transit, there may be a LEGAL REQUIREMENT not to allow users with ties to Iran to use the product under CFR title 15 chapter VII, subchapter C. Or they may at least suspect they are at risk of running afoul of the cryptography export laws as they stand and simply decided, they don't want to risk it to protect the company and other users.
I highly doubt this is some Islamaphobic/Iranaphobic move on Slack's part, this is simply a cover-our-ass move so we can stay in business and not risk prison time.
See:
- 15 CFR chapter VII, subchapter C.
- 31 CFR Part 560 and Appendix A to Chapter V
- Public Law 115–44 (the CAATSA)
You may disagree with the policy, but ryaymercer isn't wrong. Living in startup land where everything is light, you move fast, and things get broken, it's very easy to overlook that there is this 500 lb gorilla in the corner just waiting to smash you into pulp for doing the wrong thing.
My guess is that something internally at Slack has triggered this. It seems likely that they're in the midst of contracting with a Federal agency, or something of the sort. When you do business with the Federal government, all manner of hell is unleashed on you in the form of paperwork and due diligence. "Negotiation" boils down to litigation, and litigation is god damned expensive.
I am not saying what's happening is right. I'm simply pointing out that this is the culmination of decades of policy and momentum within our government. Wagging our collective fingers at Slack isn't going to change a thing. What can Slack do? Let's say they pass on whatever opportunity is driving this ridiculous witch hunt. So then what? Some Federal agency doesn't get to use their messaging platform? Who cares? Nothing changes.
It all starts with asking the right questions, and ryanmercer's post likely contains the answers to a number of questions that few people are asking: what's motivating this change, who is responsible for the policy, and how can our community affect change to prevent it in the future?
[1] https://www.law.cornell.edu/uscode/text/47/230
> It is the policy of the United States— (1) to promote the continued development of the Internet and other interactive computer services and other interactive media; (2) to preserve the vibrant and competitive free market that presently exists for the Internet and other interactive computer services, unfettered by Federal or State regulation; (3) to encourage the development of technologies which maximize user control over what information is received by individuals, families, and schools who use the Internet and other interactive computer services;
Penalties for noncompliance are stiff and there are no safe harbour provisions.
(IANAL but I have implemented systems to check OFAC lists at other companies and seen it result in similar situations)
(a) the objectives of laws prohibiting large commercial flows to sanctioned countries and
(b) the objectives of laws encouraging many tiny information exchanges on the internet, taking place outside of sanctioned countries
Is it worth burning down Internet commerce in the hope of catching a few individuals? Did Congress intend to create a Do-Not-Speak list, or one such list for every Internet company? Should Internet UGC platforms now relocate outside the USA, when Congress is also encouraging companies to repatriate assets to the USA?
What's happening here isn't an attempt to catch a few individuals. The goal is to put pressure on the entire government of Iran. This is done by making doing business hard for large businesses, as well as individuals, so that pressure to change is put on the Iranian government from above (businesses) and below (the people).
But they don't know that. They have IP addresses. And they do geolocation. But IP-based geolocation isn't reliable enough for that.
They have information from which they conclude that; this information is fallible and conclusions are not certain, but that's true of virtually all “knowledge” about the material world.
Iran does not recognize changes in citizenship.
The U.S. government doesn't care what Iran recognizes. The correct quotation would be "anyone who is legally an Iranian citizen in the eyes of the U.S. government."
When an Iranian citizen becomes a naturalized U.S. citizen, their Iranian citizenship is no longer valid in the U.S.
There is a limited number of nations that have dual citizenship agreements with the United States, and Iran isn't one of them.
Established businesses simply block connections/signup/login from sanctioned countries. It's part of the checklist for new apps. It's really basic.
Slack is just another startup to discover that there are regulations to follow. They did very poorly on the interpretation though.
When a company starts thinking this way, you know there's no turning back, and more such (censorship/surveillance-friendly) actions will be taken in the future.
We were very convinced it was name/ethnically based as I hadn't been to Iran for a few years before. The general counsel at my last job sent a strongly worded email suggesting they may have been using names to do this (thanks AA!). The email quickly resulted in my account being reinstated without any commentary on their methodology.
Why not give the user even a few days notice so they can communicate with support to try and clear things up? Taking the OP's story at face value, Slack should easily be able to verify with him that he lives in Canada. Instead, they simply block it and bye. I find this extremely hostile.
Actually, if you look at the image, Slack is beholden to US law, export regulations and economic sanctions - companies doing business with countries they shouldn't are in big trouble. See also: Huawei, who despite sanctions continued to do business with Iran, which caused the US to give them a huge fine. I don't know how that works given how Huawei is a Chinese company, but there you go.
To clarify: private companies are not and should not be above the law.
But to clarify, they gave a service to people/teams who maybe they shouldn't have. Did the people signing up/using Slack know that? Maybe. Who's responsible to ensure it's enforced?
Slack.
This isn't about Slack, it isn't about US sanctions law. It is about any private entity creating closed sourced, remotely hosted software. Everyone knows that APIs can be pulled at any time (Twitter, Facebook, etc.) Spying can be mandated whether it is the US government, China, or anyone else.
As end users it is never clear what is going on behind the curtain. It is never certain the product will be here tomorrow - whatever the reason. No one would build a high rise where all of the elevators could suddenly vanish, yet we are increasingly putting the critical pieces of our businesses and our lives in the hands of entities that only need to flick a switch and everything instantly vanishes.
You also wouldnt build a highrise where all elevators are built by a random Joe, who you arent even sure if thats his real name
Governments of the Industrial World, you weary giants of flesh and steel, I come from Cyberspace, the new home of Mind. On behalf of the future, I ask you of the past to leave us alone. You are not welcome among us. You have no sovereignty where we gather.
We have no elected government, nor are we likely to have one, so I address you with no greater authority than that with which liberty itself always speaks. I declare the global social space we are building to be naturally independent of the tyrannies you seek to impose on us. You have no moral right to rule us nor do you possess any methods of enforcement we have true reason to fear.
If Huawei didn't care about doing business with American companies or companies that adhere to American regulations, it wouldn't matter at all.
When the law is as clearly wrong as this one is, it should be violated.
What trade sanctions have been applied to Canada?
And something doesn't have to be morally good for stopping it to be morally bad. For example, playing chess is morally completely neutral, but it would be morally bad to attempt to ban chess.
Likewise, Iranians using slack isn't obviously morally good, it seems morally neutral, but enforcing a slack ban against Iranians is obviously morally bad.
How is that an 'obvious wrong'? That's how sanctions work. Sanctions are laws that prevent companies in one region from doing business with companies from another region.
>Taking the OP's story at face value, Slack should easily be able to verify with him that he lives in Canada. Instead, they simply block it and bye. I find this extremely hostile.
That I agree with. Slack should do better. But doing better means doing more investigative work and you probably don't want to delegate that to your frontline tech support worker, so it means it's expensive and not particularly scalable.
EULAs already sometime shad rules to excluded people based on the country they were a national of. Those one could simply ignore. With SaaS this is a different story.
until someone targets your host and gets it shut down.
We have seen cases where domain registries or hosting providers suspend accounts for violating their ToS, which is totally legal.
But in all honesty, there are hundreds of registrars and thousands of hosting providers around the world. Not all of them fall under US jurisdiction. But if you’re really really paranoid of getting shut down, there’s also .onion sites or distributed systems like IPFS.
You can not prevent people from communicating on the internet any more than you can prevent people from writing letters.
Also, there are not a lot of places where you can find data centers that rent servers out for personal uses.
We have those restrictions in the UK but I've never once known any ISP act upon them. But in any case, I did also list other options that wasn't reliant on your ISP as well.
> Also, there are not a lot of places where you can find data centers that rent servers out for personal uses.
Sure there are. Hosting providers don't care if you're a business or private individual - they just want your cash. There's even serval places in Europe where you can send them a Raspberry Pi and they'd host that for you (obviously for a monthly fee). There really isn't a shortage of places to host bare metal nor VMs.
what happens when ISPs do start acting on them? they do in india.court ordered blocks on whole ranges of IPs
> I did also list other options that wasn't reliant on your ISP as well.
However that aside, you could nitpick solutions until the cows come home but it’s unproductive because self hosting is still more resilient from takedowns than a SaaS solution. And that’s what matters. Self hosting gives you options that you simply don’t have with SaaS.
Frankly, I’m amazing anyone is even arguing against that point in the first place.
Obviously this is a less than ideal solution, but my point is you're not reliant on AWS / OVH / Digital Ocean / whoever you choose for hosting.
/s
Incremental improvements are still improvements, even if you still rely on some people for some things.
There is a technical workaround for any form of censorship - the real question is how difficult it is for ordinary folk to us.
As someone mentioned in the twitter thread, this could happen to any product: Google, Facebook, even taking the bus!
I'm not familiar with other countries as neutral as Switzerland which has a successful track record of staying neutral during two world wars on their borders, but I suspect there should be actually quite some. I _think_ that for example Kazakhstan is currently trying to follow a similar neutral political path.
https://sanctionsguide.eversheds-sutherland.com/countries/sw...
I get the impression that neutral in this case is being confused with some libertarian / anarchist / lawless utopia.
My favorite gripe with it is that quickly typing half a username and auto completing will select the first (or some random) user that's doesn't have anything to do with what you typed. It's a real pain if you're a fast typist.
Can't compare it to Slack though, since I never used it.
You have no rights, you have no intrinsic human valuu and you have no means to fight for yourself.
Or if it gets them out of a flash-in-the-pan PR issue fomented by the latest political outrage mob, or a couple 'woke points' to score with their ideological allies.
The tech community had its chance to stand firm and demand openness and liberty of use when it comes to accessing communication services provided by mega-corps. They instead let themselves be seduced by "it's a private company they can do whatever they want go build your own platform" when it was being wielded against less sympathetic targets.
If you don't hold it, you don't own it. HN types seem to not get this, at all, they think companies should indefinitely preserve all their data and make it available on demand, no matter what, in-perpetuity. The MailChimp thread yesterday now this one and the gods help you if you suggest people backup their data regularly instead of relying upon a 3rd party to always have it available for them.
If you don't hold it, you don't own it.
Beyond that I find it outrageously unethical.
What, complying with national and international sanctions and erring on the side of caution? Losing part of your customer base is preferable over getting fined to the tune of hundreds of millions of USD.
What's the alternative? Just hide your Iranian/Persian colleagues and friends under the digital rafters? It's plain wrong, and I refuse to be on that side of history. If Slack needs to risk a massive fine then that's their duty, so yes, face the fine, take it to the Supreme Court. To be honest, doing anything else is unpatriotic as well as unethical.
I wouldn't put Canada in the same company as the EU or especially Switzerland, Canada is generally very happy to play ball on these matters.
No, it's definitely not. What's with the hyperbole? Do you consider every single person and company in the US unpatriotic and unethical then because these sanctions exist?
We need less corporate involvement in politics. If you don't like the laws then you are free and welcome to participate in the government to change them but expecting a private company to go to the Supreme Court (!) over sanctions is just ridiculous.
Yes.
As someone else pointed out: if anything is unethical here, it is the sanctions. Ensuring your company operates within the law is a business decision and not everyone has the ability to go toe to toe with the government.
If it were my company and the potential downside of not closing accounts was personal jailtime, I'd absolutely err on the side of caution and close any account that seemed like it might land me in jail. Yes, people would get pissed off. But I'm not going to jail for them.
The real problem here is that Slack's support is horrible and there's no way to talk to them about an account closed in error.
EDIT: I don't understand why they ban/block the account rather than "simply" block access from IPs from the country. This seems really strange and overreaching.
This doesn't excuse anything. People in Syria are people too.
This is similar to how people were calling for websites to block access to Europe over the copyright thing. The internet is a place where you don't even need to have a nationality. It is a place where we can all exist as pure thoughts. Why are we letting politics fuck it up?
https://www.treasury.gov/resource-center/sanctions/Programs/...
It is a place where things happen that aren't just transfers of information between physical places. For example, Hacker News is a place within the wider place that is the web.
You can argue that it is something other than a "place" (maybe "community"? or "society"?) but then you can just substitute "community" or "society" where I wrote "place" in my previous comment and everything still holds.
Right now, it means revendicating parts of that place that is internet as waving their flags, and holding accountable individuals and companies powering those parts.
You can argue that there are no nationalities on the internet, bust most nations beg to differ.
Hacker News isn't a place because you're just requesting data from their servers with a well-known DNS name. In fact everyone who "visits" is technically getting a private copy sent to them, and it's all data being transferred between borders. You can clearly see it reflected in internet routing where transit is defined by political and business connections, and things like the Great Firewall of China.
Calling it a community fits better sure, but that just describes a group of individuals and doesn't create any political sovereignty. People still live in physical locations which are bound by laws, there's no way around that.
- 31 CFR Part 560 and Appendix A to Chapter V
- Public Law 115–44 (the CAATSA)
Yes why?
Fight back: use Tor, have proxies, Tor nodes, bridges, gateways. Use ZeroNet, help crypto projects. Make it hard to discriminate on IP.
Edit: In the US, UK, and EU.
It seems the harder restrictions were lifted in 2014 in the EU due to member state disputes.
https://www.gov.uk/guidance/sanctions-on-syria
https://www.gov.uk/government/publications/financial-sanctio...
Well, there is nothing about restricting general employment of Syrians in there.
I wound be careful of you or your company reside here. The company I used to work for was fined for continuing services in Syria.
I think your are in Germany and the EU might have lifted restrictions based on certain industries.
https://www.ajc.com/business/investigation-into-syria-accusa...
In the US there's OFAC (https://www.treasury.gov/about/organizational-structure/offi...) which lists individuals and entities that companies cannot do business with. Implementing these rules is a nightmare for companies so they use a 3rd party services which produce a huge number of false positives. Middle eastern names tend result in many false positives.
My guess is that Slack is scrambling to clean house ahead of the IPO and they don't have a user friendly way of dealing with this. In fact most companies don't. This is the same crap that bites people who inadvertently end up on no-fly lists with no way to get off.
Don't like this? Call your representative. Build a better way to implement OFAC and similar laws.
It seems most likely that Slack has geolocated IP addresses from account access logs, and closed accounts with hits from sanctioned countries. Perhaps going back years.
That in itself seems over the top. But it doesn't constitute ethnic profiling.
But if someone has a counterexample, that would be OK too.
When people violate actual law, we know which specific sentence in the written law was violated. We have a chance to defend ourselves. We have (supposedly) impartial judges and juries to help determine the truth.
Tech companies are building parallel institutions for judgment and execution, but building it for themselves and they have no plans to let their users have any say or transparency. It's a digital version of "rule of men" rather than "rule of law" -- "you're condemned because I, the King, say so."
This will continue until external powers (regulation) force the quasi-digital-fiefdoms to open up. Hemming and hawing about "gee, this is kinda harsh" won't have an effect on them.
I'll leave it to the mods to change the description accordingly, if they feel inclined to do so.
UPDATE: The mods have changed the description to "Is Slack shutting down accounts of those ethnically associated with Iran?"
It's a lot less data and it's very useful to help with some customer issues, or legal matters like this.
But the focus ought to be on banning based on access logs from years ago. With potentially unreliable geolocation. And IPv4 addresses that may have been announced from many different autonomous systems, over the years.
Slack was the exception because it's the tool people use when developing, so I somewhat blindly expected them to be alright with it. Especially since there are public answers to VPN issues on Twitter (https://twitter.com/slackhq/status/510137942296518657?lang=e...).
Focusing on intent can help us feel better about ourselves when we unintentionally contribute to these problems, but if we actually want to fix them, we can't focus only on the intentional racism or intentional ethnic profiling. We have to understand and find ways to avoid the unintentional stuff too.
If the removals are automated, then the most vulnerable accounts would be those of slack employees - or slack investors?
In this case no, because fixing that bug in your project doesn't benefit him specifically.
I suppose the argument is that the person in question visited Iran and presumably had to pay for food at some point and thus "did business with Iran" -- and that would cover the American vacationing in Cuba as well. And that's probably why they're not just banning IPs originating in the small set of sanctioned countries, and instead dropping users. But I don't like it.
https://www.computerworld.com/article/2467444/open-source-to...
Seems they might want to tone down their bans starting from the moment the policy came to be vs doing it from the dawn of Slack's time, not sure how the policy is written and I'm not a lawyer so maybe they went off from legal advise.
That's misleading. It might be more accurate to say "if any IP you have ever used matches these countries..." but there seem to be other cases where even that doesn't explain the bans.
We know people reuse passwords. I'm sure there are a lot of weak accounts known, or at least suspected. So... if you had a large number of compromised slack accounts, and a complete lack of morals, you could log in with each of them to Slack through Iranian/Syrian proxies.
If Slack are indeed shutting down all accounts that have ever logged in from Iran or Syria, the above could be a brutal denial of service. Followed by a massive PR s##tstorm.
Disclaimer: I don't advocate doing anything like that. I just point out that there might be a way to weaponise the backfire...
For example, the guy in the Tweet, who doesn't even live in Iran and is merely ethnically Iranian.
Not to mention anyone in the US (or, just ethnically North American?) who takes the ethical stance of ignoring the sanction and gets punished for it.
Iran has not really stage any offensive wars since 1856 (and most of the XIXe century wars were in fact to recover/maintain control over the Persian Empire which was slowly eaten by the Russian and the UK).
Since 1940, Iran was constantly meddled with by foreign powers, first being invaded during the WW2 by the Allies and the Soviets, with the Soviet reluctantly leaving the country after 1945.
Then the democratically elected Mosaddegh was deposed by the MI6 and the CIA because of "precious Oil". A "Pro-Western" dictatorial government was was put in place. This regime was of course brutal but also at odds with the population and its traditions, leading to a revolution in 1979.
In the midst of this revolution, Irak, another "Western backed" dictatorship tried to profit from the chaos to invade the country which lead to costly a 8 years war leaving ~1 Million people dead. This war is probably the last high intensity conventional war between 2 roughly equals and relatively developed countries to date.
And then in the 2000, it has seen two countries at its borders being invaded by historically hostile powers. And then these countries collapsed into chaos (And I'm even forgetting the Soviet invasion of Afghanistan in the 80ies).
And lately, after lengthily and complex negotiations, an international accord was signed, just to be thrown out of the window 1 year later by the US, the US then bullying other signatories into not abiding by said accord.
No wonders Iran government stance can be a bit tense at time and that they want the Bomb to be at peace.
Mossadegh was not democratically elected. He was appointed by a dictator. The only part of that process that was even slightly democratic, was indirectly via Majlis vote. The people of Iran never specifically elected Mossadegh.
> No wonders Iran government stance can be a bit tense at time and that they want the Bomb to be at peace.
How does being at peace square with constantly calling for the genocide of Israel across decades and very aggressively funding terrorism & militias? The Iranian people have been protesting their military adventures in Syria as one recent example. Iran is every bit as dirty as the US and Russia when it comes to such activities over the decades in the Middle East.
I do agree that the successive Iranian governments and the Iranian regime is far from a saint in this story, specially since the Islamic revolution.
Calling Israel a "cancer" or a "little satan" (with the US as the "great satan") is an atrocious way to do diplomacy...
The Iran hostage crisis was a really bad starting move. with long lasting consequences.
Iran is also quite active militarily, but the goal is more to maintain security at its border (Iraq), or maintain the few allies it has in the region (Syria, Lebanon). There are reasons behind these adventures, even if that doesn't excuse them.
The Shah carried out the appointment, only after the democratically elected parliament members nominated Mossadegh in an overwhelming majority vote).
This could be considered "slightly more democratic", only if you consider the Australia to be "slightly more democratic" than a dictatorship such as North Korea.
I'm not going to attempt to untangle your final paragraph, only to say you have made some very large claims without any sources to back up your claims.
Tough choice.
I'm not defending slack or practices like it (hell, I have a blank phone I use whenever I leave the country) but it's not quite the choice you're making it out to be.
The problem is "which app?". Short of a factory reset on both my phone, laptop and kindle it seems I would be in danger of tripping a switch somewhere.
It's very, very high on my list. But if you have an American or British passport you currently can't go without an escort.
(I'm an Overlander, I drove AK-Argentina and am now driving right around Africa. I've met 200+ people that have been to Iran)
I extended in Angola when getting a visa there was hard, I extended it in Mali, Zimbabwe, just looked into it in Ethiopia, etc.
Of course, as Overlanders we have our own vehicles are I'd say 50% of us are not time limited [1], so we just stay as long as we want in countries we like.
[1] NOTE: Many of us - me included - are money limited, not time limited.
My country people treat foreigners nicer than their own people because for some reason they believe that foreigners are rich and foreigners might give them reward or smth.
It's a common belief that foreigners are rich and locals aren't.
Same way if you are rich in Iran being a local isn't a problem people treat you extra nice
Once one foreigner brought an iPad for my friend.
It might seem odd to foreigners that in East simply looking rich/ or having money can earn you their nice behaviour.
This worked even in Iran, and she met up with a Norwegian-Iranian family; but her government assigned minder/'translator' wouldn't let her sleep in their house. She counted as a journalist and there's no way Iran would let a loose journalist float around their society interviewing unsupervised ordinary people for the TV.
Pity, it does look like an interesting place to visit.
Also, from what I've gathered, visiting Israel may impact your ability to visit Iran.
(a) Effective February 7, 2014, to the extent that such transactions are not exempt from the prohibitions of the Iranian Transactions and Sanctions Regulations, 31 C.F.R. Part 560 ("ITSR"), and subject to the restrictions set forth in paragraph (b), the following transactions are authorized: (1) Fee-based services. The exportation or reexportation, directly or indirectly, from the United States or by a U.S. person, wherever located, to Iran of fee-based services incident to the exchange of personal communications over the Intemet, such as instant messaging, chat and email, social networking, sharing of photos and movies, web browsing, and blogging.
https://www.treasury.gov/resource-center/sanctions/Programs/...
Americans in general aren't well educated about the ME and the ethnic and religious differences there -- even the past 17 years of war there haven't tipped the education system to give them better knowledge about it.
Yeah -- agree, most Americans simply aren't able to identify the differences between the ME countries.
SA is a marriage of convenience, nobody likes them even though we have a somewhat tenuous alliance.
Because of the fairly harsh anti-US rhetoric circulated by the Iranian government to its citizens since the revolution (itself because of our previous support of the Shah and current support of Israel) for purposes of maintaining power, it's easy to say "Look, Iran hates America."
The Shia / Sunni distinction is largely lost on the average American.
And just as a personal note, almost every Iranian I've met in the US has been an awesome person. They've got a fascinating history and culture.
Yeah because most of the ones here are the kids of the high-level government officials from before the revolution.
Also relevant: https://www.google.com/url?sa=i&source=web&cd=&ved=2ahUKEwiM...
Non-representative sample, self-selected according to dominant migration obstacle (e.g. financial or educational).
Kind of ironic when you consider the leaders of a country using patriotism for their personal gain. It’s so weird seeing all the flag toting, national anthem singing population in the US tow the line when they can’t even be bothered to learn their country’s history or participate in the civic process and hold its leaders accountable.
But I think the defiance is why the US elite hates Iran. They successfully kicked out a US-backed leader, humiliated Carter's rescue plan, fought off a US-backed Iraqi invasion, defied the US over nuclear proliferation. Refusing to follow US orders enrages the US.
Ironically there has been extensive on-the-ground cooperation between the US and Iran while fighting ISIS in eastern Syria.
Could you possible share a source for this?
They also from time to time threaten oil supplies and threaten Europe with restarting their missile programme. They’ve been quite nettlesome.
However, with more energy independence the present US administration seems to be disengaging from the ME, in contrast to the last two admins,
As does the USA. So?
But unfortunately with the weapons they’re willing to use against each other it may be hard to just sit on the sidelines.
Any case OP was painting them as being “innocent”.
Someone's got to keep selling them those weapons, right?
Trump's "muslim ban" nations includes Iran: https://en.wikipedia.org/wiki/Executive_Order_13780
Active US involvement in the war in Yemen continues. The only difference of having Trump in power is that the news is full of his twitter remarks and news about prosecution of his accomplices, rather than what's actually happening elsewhere.
I think people are talking past each other here because "Sunni vs. Shia" is a distinction that has great meaning to those on the inside of that religious or regional context, but means absolutely nothing to most on the outside - especially but not only those in the US.
Imagine that there was a wave of Buddhist terrorism. Would people in mostly-Christian or mostly-Muslim countries notice or care about mahayana vs. hinayana (vs. other)? Big nope. If they made any distinctions at all, those would be on the basis of country/region or skin color or just about anything besides doctrinal differences. More likely they'd just tar all Buddhists with the same brush. Do people in Iran pay attention to factional differences in the US, or are we all "Americans"?
So it is with US vs. Iran. Sunni vs. Shia might well be important, might be highly visible to you, but to at least one half of the people making geopolitical decisions it's just not part of the equation. Maybe that's a good reason not to have the ecclesiastical and secular authorities so intertwined, as it makes such confusion almost inevitable (cf. Israel vs. Judaism).
It isn't a "oh you're a Muslim/Iranian/Cuban/resident of Kiev, banned!" thing it's a "Oh, you could cost us millions and millions of dollars in legal trouble, exposure of our other customer's data, etc, sorry but we have to sever ties with you immediately to reduce our risk to very serious government investigation and litigation".
Given Slack also uses encryption at rest and in transit, there may be a LEGAL REQUIREMENT not to allow users with ties to Iran to use the product under CFR title 15 chapter VII, subchapter C.
> Shi'ite Iran certainly has human rights issues, but as far as terrorism is concerned the majority of them are orchestrated by Sunni groups
It doesn't matter what religious sect has perpetrated acts, the current government is reliably documented to a laundry list of terrorist attacks, cyber attacks, imprisoning/lashing/executing members of the gay community, at least 15 assassinations on foreign soil (US, FR, DE, CH, SE etc), a recent president was a staunch holocaust denier and the government even sponsored an anti-holocaust conference.
We impose sanctions, embargoes etc on COUNTRIES not religious sects. We hold COUNTRIES responsible for war crimes and genocides, not specific religious sects. The current government of Iran in this instance has a history of doing bad things for its entire existence, as such the U.S. government has decided they are both a threat to nation and worthy of sanctions for various reasons. I suspect the powers that be at Slack simply are trying to minimize risk to the company and other customers by eliminating users that have shown a connection to IPs geographically connected to the nation of Iran.
See:
- 15 CFR chapter VII, subchapter C.
- 31 CFR Part 560 and Appendix A to Chapter V
- Public Law 115–44 (the CAATSA)
Speaking of which, are there any open source alternatives to Slack which anyone could recommend?
There is also matrix (riot.im) which is fully decentralized though the UX still needs a lot of work last time I checked.
His Slack account was blocked today, with that same message.
The crazy thing is that he's Irish and living in the EU, with no actual ties with the countries being mentioned.
He does travel for business purposes outside of Europe, but again, not in the listed countries.
if account.countries.include(/ir.*an/)
account.delete()Is that when the account was first used? Majority of use related to IP? Something to do with the email address?
But this makes me think. Many of the services I use are from US companies. Most notable are: Gmail (Google Drive, Google Calendar, etc.), Github, Dropbox, Trello and Toggl. Should I be worried? Should I actually start switching away from these services before they close my accounts and remove all my data without notice?
Not a conspiracy, IMO, just taking shortcuts to be "better safe than sorry." So what a few thousand users are incorrectly banned? We'll restore many of them one by one but at least we'll be fine with the US Gov. Plus, depends on what the government says "users" mean. If you used Slack in Iran...what's Slack to do?
Unaffected orgs will just keep on using slack, as will many affected orgs, and Free alternatives and irc will be mocked and laughed at by next week for being inconvenient and old in comparison to yet another proprietary solution, or even slack itself.
If you rely on communication, and you don't control your communication, you can't rely on that communication.
There'll be a reminder in 2025.
1. https://xkcd.com/743/ (and it really should be a Free Software violin now. If you ever wondered about the difference outside of licenses: this is it.)
We are based in the EU and can offer an embargo-free and on-prem capable environment.
You can disagree with the idea of sanctions based upon this, but this is how sanctions work. Companies need to comply with sanctions and the repercussions of not complying can be severe.
I'm not sure WHY Slack chose this method to respond to the sanctions, nor why they've chosen to do this at time. Slack may have received a shoulder tap from a US agency that forced their hand or their legal department got cold feet. Until we know for sure, this seems like a overly cautious approach but not some kind of nefarious scheme.
That was funny.
Disclaimer: I work on Matrix (should have made that clear in the parent comment too)
^1: Well, hmm, I wonder what % of active instances are on a free tier, but that's a separate unrelated question
https://docs.google.com/spreadsheets/d/1-UlA4-tslROBDS9IqHal...
(I didn't make that spreadsheet, but found it quite interesting when it was posted on HN a few weeks ago)
I’m getting fed up with paying for a bloated Electron app with nice colors and now improved with tracking of it’s users.
Next on HN: Falsehoods Programmers Believe About Race
One of the personal projects of mine was to put on a map the nationalized buildings that used to be owned by Jewish owners (I live in a former Easter-European communist country, we did nationalize a lot of stuff immediately after WW2 ended). That was pretty simple: I just got the nationalization order/law from back in the day (it included the names of the building owners and the addresses), I inputed it in a database and then I matched those owners' names against a public database containing only jewish names, meaning this one [1]. It was a lot more difficult to exactly geo-locate those buildings on a map (a lot of street names had changed in the last 70 years) than it was to guess the ethnicity of a lot of people on that list.
Again, this was part of a personal project that I had built in order to better know the history of the local Jewish community, but I could see the same "technique" (meaning just plain name matching against a known database with positive ethnic identification) being used for nefarious reasons in other circumstances and places.
Well, guess what kind of treasure trove that census data was for the Nazis later.
My point is - it's not just "this modern age". In every age sharing too much information about yourself is potentially dangerous, even if you can't see the danger yet.
2) The US has a reputation for being quite aggressive with certain things. Can't be surprised if some firms take steps that seem overkill. Not that it makes it better, but rocks and hard places.
Use IRC. Its not nearly as walled off.
2. Discrimination based on ethnicity, religion or political views is forbidden by law.
In the absence of proof that this user had business with Iran (or any of the other sanctioned countries) through Slack's platform, the export control regulations do not apply.
If the user has business with Iran outside of Slack's platform, Slack can not invoke the export control regulations to justify their action.
Ergo, the only thing left here is that Slack broke the law that forbids discrimination based on ethnicity.
If the USA fails to punish Slack for it's illegal behavior, and Slack successfully avoids prosecution elsewhere, other country have the right to block access to Slack completely, from within their own borders.
Personally, I think US citizens should be more concerned with what their government does, especially to and with other parts of the world. For eventually, the will feel the consequences of those actions on their own skin.
That's not how it works. Even if Slack is mistaken in their belief that export regulations apply, their action is still taken in that belief, which is not legally-discriminatory.
Would you say that robbing a bank is okay, if the robber believes that it's okay?
>Ergo, the only thing left here is that Slack broke the law that forbids discrimination based on ethnicity.
There's no evidence that's the case. Most likely it's done based on IP geolocation. A white (for lack of a better term) Canadian who was using slack in Iran would probably be banned as well.
>In the absence of proof that this user had business with Iran (or any of the other sanctioned countries) through Slack's platform, the export control regulations do not apply.
Banning based on IP geolocation is not perfect by any means, but what's the alternative here? That you ask suspected Iranian users to check a box saying "I'm not an Iranian, pinky swear!"?
The export regulations apply to business. In order for it to apply, there needs to be proof of a business relationship. Simply being Iranian or having non-business related communication with Iran, which is the only thing IP geolocation on its own indicates, does not warrant invoking this law.
However, I am sympathetic when you're talking about software that needs to be run server side. Because in that case, you almost always have to deploy and manage the infrastructure yourself (or know somebody to do it that you trust), which is just too much for most people.
With chat specifically, you might be able to avoid self-hosting by using something that supports federation. Personally I'm rooting for Matrix to establish itself here.
We had an alumni from my university who opened a company and sold some stuff to a client in a middle east country. Hardware parts, not software. One shipment got stopped at the border for a random control, before the police showed up at the office and arrested everyone. Turns out there are sanctions. Couldn't sell there.
If former nationals are more likely to have visited an embargoed country, it could conceivably fall under discrimination laws.
But it is probably even more problematic if using a service from an country specific IP actually should triggers the embargo from a legal point of view?
Then we have a problem, because suddenly you won't be able to use your phone, even turn it on at all while traveling an embargoed country if this starts to be applied broadly.
Furthermore, it would imply that things like a single BGP route hijack could kill all of a company's accounts on any US service, without recourse.
If this would be the case, using any service from a country interpreting embargoes this way becomes an impossibly risky proposition. Which was probably not the intent of the embargo.
There is no conflict with discrimination though. Sanctions takes precedence over pretty much everything else.
Don't expect your phone and applications to be usable when you travel to Iran/Syria, many services won't work. There was a news not long ago about Google Cloud blocking network access from Iran.
Edit: one thought, hopefully they can open a new Slack account with IPs originating in Canada and Slack can copy/move/reinstate the account.
It seems from reading other comments that this Slack team was created when he was in Iran from an Iranian IP. And they used originating IP when the team was created and not access to determine. We can debate the proper technical solution to base the rule when you apply it across your SaaS-based application at world-scale, but implying that Slack did this on race is pretty absurd at this point.
Is Twitter, Google, Microsoft behaving the same here?
P.S. On a side note, if these sanctions are really about 'punishing the regime', blocking mediums for Iranians to speak on isn't a way to do it, but what do I know.
Obviously, looking from outside you can't tell that this rotten boat is carrying expensive gadgets. I saw this because my friend owns a wharehouse and he had to put some of his stuff into same boat.
Funny thing is Tinder is available in Iran and i used it there when i was at home for vacation.
I don't think they do anything completely cleanly, so I question the thinking for Silicon Valley Unicorns using them to head their IPOs
Greece the 2008 crisis buyouts 1MDB
Look at the 1MDB scandal, where we are only now seeing charges coming against GS - The 1MDB and Greece scandals are very similar in the sense that GS had information regarding both situations which they knew was criminal, but chose to profit from it as opposed to prevent it. Knowing that their profiting would outweigh the consequences.
They are the antithesis of "in good faith" actors - and as such, I personally question the integrity of the companies and company founders who put their IPOs in GS' hands.
Look at FB... we know where their integrity lies.
I am reminded of the "How I built This" episode on Slack, and how it grew and the values of its founder -- which I now take with a grain of salt given that they are going with GS.
(Note: we haven't actually stopped yet.)
Can someone explain an interpretation of US sanctions that causes situations like this?
This could be US sanctions or it could be a companies poor reading of them.
https://twitter.com/a_h_a/status/1059225338650144774?s=12
The notion that the US conducts military operations “only” to exploit oil is a popular one but it’s not very nuanced thinking, and dances close to extremism. I haven’t spent the time to read what else this guy espouses but I suspect the ethnicity card is being played to hype up some drama when there are other issues at play.
Even after confirming with a white person banned for using slack while visiting Iran, he continued to claim in the thread it is racial.
Reality: he was banned for using slack with an Iranian IP.
Whether or not that’s export control overreach / unethical / bad business not my point, it’s clearly very different to ethnic targeting.
Yes this is annoying but probably not slacks fault.
It's unethical to enforce unethical rules, even if the government tells you to.
Their non-compliance is fact.
Whether or not you consider that law to be ethical is opinion.
I was not stating an opinion, merely stating fact. I was not trying to start a discussion of politics. I appologize if I was misunderstood.
This is almost certainly related to the user's travel to Iran, and not any form of racial profiling. Everybody please remain calm.
It's emblematic of today's society that at the first mention of ethnicity, everybody grabs their anti-racism pitchforks. I agree racism is a problem, but let's treat it appropriately. We need to look at it more like drug addiction today (an invisible psychological problem that can be healed), and less like drug addiction 30 years ago (a moral failing that must be punished).
Well, that is called breaking the law and I fully understand why slack terminated his account when he broke the law and violated their terms of service.
For example, other services or tools (like cisco anyconnect) clearly state, that you are not allowed to use them when in embargoed contries.
If Slack allows connections from embargoed nations, that’s on them, not the individuals who might happen to connect from an embargoed nation. Slack is responsible for their own export, and if a user accesses Slack from an embargoed nation, it indicates that Slack is enforcing the embargo improperly. More importantly, blocking that user doesn’t fix their export issue.
https://techcrunch.com/2018/12/07/huawei-cfo-accused-of-frau...
https://www.bassberrygovcontrade.com/iran-sanction-violation...
That the US, supposedly the leader of the free world, is threatening prosecution and jail to those who want to treat everyone in the world equally, is a ludicrous state of affairs.
If a country does smth, citizens are punished.
This has been case throughout the history.
Alexander took the losing kingdom's citizen as slaves and American bombed Hiroshima and Nagasaki, again the citizens of Japan who were living there.
EDIT: Also, in a different comment in this thread, you claim to be Iranian. Why are you defending sanctions against the country that you are from?
About the same time as Japanese citizens were punished for the Bataan Death March, the Rape of Nanking, and the Korean Comfort Women.
Besides, since when is it appropriate to "punish" a country for winning a war in which it was aggressed against?
https://www.bloomberg.com/news/articles/2018-12-12/trump-say...