An Apology and an Update
slackhq.com
slackhq.com
They admit the mistake was theirs and they take responsibility for it. They say sorry. They explain what they're going to do to fix the situation. They say they're going to learn from this and not have similar mistakes in the future. Pretty solid.
The only thing that is missing, in my view, is personalization. Tell me who you are, speaking for the organization. This humanizes the apology, and also gives a face to who it is saying they're going to improve. Ideally the CEO.
Still, I give it 8/10.
It's Slack, so actually 2/10.
They should have communicated with their users to begin with before taking such harsh actions.
I'd say no.
Your thesis needs work IMO.
Make sure you don't fail morally by ever presenting an incomplete/unsound thesis again!
(Serious question)
By that argument regret seems impossible. Some nuance is probably lost here, to be fair.
What about responding to that honest emotional expression directly? "Ouch. I hadn't realize how much I'd hurt you. Truly, I'm sorry."
In each case though you did it to begin with because
1) while you knew you would be sorry, you surmised you would be more sorry not doing it, or
2) did not believe anyone would mind your actions, or
3) did not realize you would so much regret it when others took offense to your actions.
#3 absolves you of nothing. #2 absolves you unless you thought they wouldn't mind simply because they wouldn't know. #1 could absolves you in theory, but might just reflect priorities that the recipient of your apology doesn't share.
All this is likely of little use to anyone, but I couldn't resist writing it down anyway.
We (humans) are not always good at predicting the future or other people’s reactions. We do stupid things and make stupid mistakes all the time and when these things affect others we often feel sorry that we did those things.
If you are really sincere with your apology, and you are doing the best you can to fix what you did, so just ignore this kind of statement. You are doing your part.
Okay, so how did you block them?
>As is standard in the enterprise software industry, Slack uses location information principally derived from IP addresses to implement these required blocks.
So, you blocked users based on their nationality.
>We do not collect, use, or possess any information about the nationality or ethnicity of our users.
you clearly possess enough information about the nationality of your users to block them based on it, which was your intent. You backpedaled when people who were not the target nationality began to complain.
Where you are currently located or resident is effectively unrelated to your nationality (unless you were born a citizen of your country and have never left it, not even for a vacation).
This comment by Slack was in response to several (fairly overblown) comments that they were racially targeting users ("Slack bans Iranian in Canada"), when in fact they were disabling accounts of people who have used Slack from an embargoed country at some point. To be clear, this is still bad, just not "blocking users based on their nationality". All of the outrage was over expats (or travellers) being blocked.
It's okay to mess up if you quickly correct the issue or at least quickly recognize it and try to correct it. The problems arise when incidents are buried or ignored. Late apologies are not apologies at all.
Slack is only apologizing due to the public uproar, as apparently many people were affected.
Our cofounder was also locked of his account. He's Irish and living in Romania, with nothing to do with the embargoed countries.
To make matters worse, he tried contacting support to prove his nationality and country of residence and 2 days later he's still locked out of Slack.
In absolute terms yes. Compared to how for example google handles this it’s outstanding.
Regarding user support, Google ranks on par with an anvil.
Anvils do break, sometimes, and the failure mode is catastrophic: https://duckduckgo.com/?q=broken+anvil&t=h_&iax=images&ia=im...
We had someone locked out of their email while using Google's paid company mail service (App engine, I think it was called). Several days with no mail and no useful support taught me that relying on Google can leave you with no recourse.
I also had Google accuse me of "click fraud" on a website I ran in college- they stole about $300 from me, with no ability to appeal.
Google's support- even for paying customers- is abysmal.
I've spent the day messaging and talking with friends who work within Slack in an engineering capacity who feel, frankly, betrayed by the organization. Slack advertises itself internally as an engineering-driven company and on the security side, has an incredibly elaborate system of internal controls that I have espoused emulations of during my consulting that, and I am being very specific without being too specific here, were bypassed to perform these account bans. Slack's security team was bypassed. Slack's internal controls were contravened. Slack has demonstrated that they can access every location you've ever logged in from and will cheerfully give that information up for the pleasure of the US Government without it even being required of them.
Some of us use Slack because we have work to do.
How noble in reason! Some of us were banned without justification from our jobs today via the unjustified unilateral action of a private company. In fact, my job is to help companies secure their internal communications. So, talking with people about this was my job. What was yours?
They're required by law not to do business in certain countries. They were over-broad and over-aggressive in how they tried to follow that law, unnecessarily shutting down accounts, which was certainly a fuckup. But I don't see any indication that they gave information to the US government.
This doesn’t really mean much by itself. These are elements of the BP apology for the gulf spill as well. The only thing that matters is actions taken. Anything else is fluff part of standard PR.
That specifically doesn't admit the mistake or take responsibility.
You can find further discussion of their apologies here, and they get a 3/10 rating for apologizing well: https://www.perfectapology.com/BP-oil-spill-apology.html
> We do not collect, use, or possess any information about the nationality or ethnicity of our users.
No nationality? Don't they kind of have to collect nationality in order to comply with the law on implementing sanctions?
You can use the default (free) Matrix homeserver with Riot and you'll basically have a free chat system without any setup (besides installing the client).
I've been using Riot for a while now, and while Slack does seem a bit more polished, having client-side encryption for all my messages gives Riot the upper hand: I don't worry about sending passwords or sensitive info as much as I do with Slack.
you can participate in the discussion at https://riot.im/experimental/#/room/#modular:matrix.org to understand more if you want.
Perhaps I am overreacting, but that sort of attitude on matters core to basic privacy in the post-Snowden era seems both problematic and incurable.
I care about encryption, you care about encryption, and they care about encryption. "Giving up on them" and saying their attitude is "problematic and incurable" is hurting, not helping.
I still fell victim to apparently being reported as non-human (after 9 years of using FB with over a hundred RL friends and former class mates, many photos of me, real name from day one, and so on), and while I could send a photocopy of my ID to Facebook, as a matter of principle I didn't and won't, not without even having the right to confront my accusers. For all I know, they're bots, at best some people who didn't like a comment I made on some article -- and from the accounts of others, even showing your ID doesn't mean you won't get fucked over in a similar way again. There is just no real recourse, so why even start jumping through hoops, I'm not going to be party to normalizing that nonsense.
I also don't believe in technical solutions to social problems. Encryption gains me nothing in a world where my neighbours just shrug when I get carted off for having using encrypted communication -- or get booted off Facebook -- so that needs to be "fixed" anyway, and should it ever be, encryption would be something that protects you against criminals and assholes, not something that protects you against big brother. IMO it's lethal to assume it ever could or should. It's something we can and should use on our way to social solutions to social problems, but not something to rely on. I know that many people in other countries or very different circumstances NEED encryption, so they should have it, and I might use it out of solidarity and to give them cover even -- but that won't fix the problem anymore than Napster fixed the music industry.
But in theory all of those can be replaced, a site that was recently in the news for being kicked off Godaddy, Google, tucows, Cloudflare, the Russian media watchdog, namecheap, DreamHost and a ton of others. Today its online using a Chinese based provider.
But yeah, if SV takes a disliking to you, it can be a right PITA to find some where to get back online.
But you are right, Someone somewhere has to host you and/or provide you with services (even if you self host) you are still dependant on to be able to stay online.
I'm hoping to spend some of my christmas break contributing some work to the project. I agree, bridging SMS into a chat service that you can use from anywhere is a killer feature.
Is Slack legally required to do this? As long as they aren't knowingly accepting payment from these countries, shouldn't they be in the clear?
How are other tech companies dealing with this? Does Google block access from embargoed countries? Does Windows refuse to work?
Yes, absolutely. Breaking sanctions is not just illegal, it's a criminal offense. There have been sanctions against Iran since roughly when Trump withdrew the US from the Joint Comprehensive Plan of Action [1] in May of this year.
The CFO of Huawei was arrested in Canada per a request by the US because of their dealings with Iran [2].
[1]: https://en.wikipedia.org/wiki/Joint_Comprehensive_Plan_of_Ac...
[2]: https://www.bloomberg.com/news/articles/2018-12-05/huawei-cf...
Slack is actually not required to do this as IM applications are exempt from sanctions.
Still, even though the sanctions rules may apply, I'm glad Slack is reversing their overbroad application of these rules.
See specific of the current application of the rules here: https://www.treasury.gov/resource-center/faqs/Sanctions/Page...
"Specifically, section 560.540 of the ITR authorizes the exportation from the United States or by U.S. persons, wherever located, to persons in Iran of services incident to the exchange of personal communications over the Internet, such as instant messaging, chat and email, social networking, sharing of photos and movies, web browsing, and blogging, provided that such services are publicly available at no cost to the user."Of course, any sanctions regime that does still apply wouldn't require the collateral damage of Slack's excessive initial ban.
Also, the license applies to services for a fee.
Also, exchanging information isn't embargoed.
But Slack does support a lot more than just people chatting with people, like bot and app/SaaS integrations. Those clearly aren't personal communications and frequently accomplish more than just exchanging information.
Good catch that the license does have provisions for fee-based services as well. However, the person I was replying to quoted the one for no-cost services, so that's what I focused on in my reply.
EDIT: I know that Google AppEngine and probably Cloud are blocked, because they provide foreign nation with "computing resources", but that's also its own different bucket.
Regardless, there remain restrictions on certain countries.
Phone calls, SMS, and the like work fine enough to embargoed countries (although North Korea doesn't allow that, except to a very limited set of phone numbers, mostly consolates), and that likely involves payments between phone companies in the embargoed countries and in the US.
I'm aware that Softlayer (IBM) blocks traffic to embargoed countries by default, but has a process to allow traffic, given documentation of exemption.
No, the reason is Saudi Arabia told them to.
> The Crown Prince also invested $45 billion into a SoftBank subsidiary, the Vision Fund, which made subsequent investments in a number of US tech companies. The Vision Fund made significant investments into Slack, DoorDash, and Nvidia. Slack declined to comment and DoorDash did respond to a request for comment as of publication.
Technically their underlying problem is relying on IP ranges, wich is flawed and raises false positives all the time.
They seem to recognize they shouldn’t be doing irreversible and critical action with only that info, yet will still use it to drop traffic.
To me their message is “sorry we screwed with your accounts, going forward we’ll only screw with your messages”. Am I supposed to be that reassured ?
Probably they asked some junior engineer to write a database query looking for a list of accounts with IP logs that matched a range of IPs coming from the banned countries, and then they passed that list to another junior employee who deactivated the accounts.
Of course, there are many reasons for those IPs that are not your default/work/home, to be logged against your Slack account. They probably didn't think this throughly.
But the problem then is what they ought to rely on. If in fact they are legally required to deny service to those in sanctioned countries.
The whole thing is silly. I mean, anyone in a sanctioned country who was truly up to no good would be spoofing their IP address in some way. So most of the users that they ban or block will be innocent.
I don't get how IP-based geolocation could satisfy either standard.
One country decides "fuck that other country in particular", either alone by their power of sovereignty or together with some international body. The sanctioning country (say, the US) now declares economic sanctions against another country (say, Iran). Since the US can only directly make rules for citizens/entities within the US, they say "it is illegal for anyone to export goods or services to anyone in Iran - if your company does it, the company gets fined and the CEO goes to prison". They might also say "and if anyone else that I can't punish directly sells to Iran, I will prohibit my people from selling things to you!" to force others to also participate in their sanctions.
Now, the US gets a suspicion that Slack provided services to Iran. They arrange for the FBI (or whoever is responsible) to raid their offices, build a case beyond reasonable doubt that shows Slack provided services to a company in Iran, e.g. because said companies egress NAT IP was connecting and the user names match people working for that company in Iran. On top of that, they also show that Slack didn't do enough to prevent that from happening. Now, Slack gets fined and their CEO goes to jail (not sure if that's the penalty for sanction violations but I'd assume so).
Since the CEO doesn't want to go to jail, and the company doesn't want to be fined, they'll do whatever they can to avoid selling services to Iran. They can generally choose who they do business with, and its in their best interest to err on the side of caution. You have little recourse if Slack doesn't do business with you because they don't like your IP, and they're almost certainly well covered by their ToS.
Posting this I'm sure someone will take the challenge and can find an example where it wasn't assigned to the right country, but is it more than one in a billion IP addresses?
GeoIP databases on the other hand, the city and often even the province/department/state are very unreliable.
Try anything in 17.x
However, https://www.iplocation.net/ reports some results indicating that it's in the UK, and some indicating that it's in Tuvalu.
According to Hurricane Electric's BGP Toolkit, the origin AS for 5.62.58.0/23 is AS198605, with "Country of Origin: Czech Republic".[0]
But results from many ping probes (ping.pe, asm.ca.com and maplatency.com) indicate that the server is in Miami, FL, US.[1]
That's a lot different from Tuvalu, the UK or the Czech Republic.
0) https://bgp.he.net/AS198605
1) https://www.ivpn.net/blog/wp-content/img/HMA-fun-tv.prcdn_.n...
So, to answer your question, I doubt anything serious changed outside of Slack. Inside, however, maybe they got a new legal team that flagged this as a liability, or they're getting serious about compliance, or they're preparing for an IPO[1], or whatever...
[1] https://www.cnbc.com/2018/12/07/slack-has-hired-goldman-sach...
It's very clear to me that this is some housekeeping attached to their IPO.
With respect to Slack, if they intend to IPO in 2019 they may be going through a due diligence checklist as others have suggested.
Also note that all the major cloud providers in the US do not do business with embargoed countries. They all block IP from Iran, et al. to compute within the US, but allow it to compute within other geos, this extends to tech support, sales, etc.
I'm honestly surprised that Slack users within Iran could access the service running in US to begin with. In all likelihood they could only access edge servers located in other geos in APAC or the EU.
Look closely at everything Slack says in this message and others. "Enterprise Software" is tossed around a lot. They want to be the communications platform for the enterprise and have to meet these standards to compete with other offerings that exist today.
So why ban any account? Why not just drop connections from IP addresses in embargoed countries?
(Put another way, it seems like they’re saying some accounts remain de-activated. So which is it? Accounts are de-activated or IP addresses are blocked?)
This wasn't a bug, but a management level decision.
What made matters much worse for them was that their algorithm failed, also blocking unaffiliated with any of the embargoed countries. But the design itself is the bigger problem.
"It happens" is a poor excuse.
What if people with blocked accounts lost revenue due to Slack's decision? Will Slack pay for the damages?
Which is usually taken as, "enough to inconvenience unintended targets, even if intended targets can easily avoid the punishment."
So Slack is a communications platform.
If we have an embargo against a country, we have to shut off any services we offer to that country? Including communications platforms.
Doesn't seem like that will help improve things in that country, or help the people in that country communicate.
I'm all for not sending a dictatorship steel or guns, but why would we cut off communications platforms? That seems batshit.
I'm betting that Slack only had to do this to comply with some dumb laws regarding sanctions because I am unable to see why anyone from these countries using civilian, commercial, non-sensitive services such as Slack would have any impact on sanction enforcement.
As seen here, sanctions turn companies that provide services into poor customer service scenarios through forced compliance for what reason ultimately? All that does is make it harder to track since we now live in a surveillance society. What a waste of time and energy. We are living in an age of the abuse of economic sanctions, that ultimately harm the wrong people and make companies/products look bad.
That’s the whole point. It’s not an unintended side effect. You’re targeting an entire country’s economy to pressure the government regardless of whether or not it’s elected.
Disclaimer: This is not an endorsement of embargoes.
It is a bit medieval and tribal if you ask me and doesn't work today.
Targeting individuals that actually cause the problems is a better strategy.
Ultimately, we live in a surveillance society now, blocking people with reckless abandon only limits access to individuals causing issues for all. Technology is being used by authoritarians in frightening ways, somehow this has to get fixed, companies/people need to stop falling in line.
That or a special kind of callousness, because most often the only way the citizenry can effect change is through violent revolt after reaching the boiling point of poverty and/or oppression.
It takes a special kind of naïveté to think governments run in a vacuum independent of the economy.
Sincerely, a citizen of a country whose government literally actively bankrupts it.
Of course in the long term this is just incentive for countries to support balkanisation of the Internet.
Hypothetical: If you build a product meant for use in other countries than (also as well as) the one it’s been built in, should you be allowed embargo its use based on the (possibly arbitrary) politics of a single one of those countries?
I suppose the makers can do as they please/are required to in their home country.
However, it opens another costly-to-startups hypothetical: If the politics of our home country swing to the (insert x-axis direction) and we decide (insert country Y) are baddies, do we have the resources to comply with an enforced embargo?
Surely, the point of "not trading with Iran" is to avoid, through one's economic activity, enriching the citizens or corporations of Iran; and has nothing to do with preventing access to people who just happen to currently be within the geographic boundaries of Iran. (So: email blocking by detection of Iranian-ISP mail host = sensible; Iranian IP blocking = not-so-much.)
Unless, I suppose, you expect that a tourist accessing your service through an Iranian ISP, will be enriching the Iranian ISP to exactly the degree that you are serving them, and therefore, you are legally required to not serve the tourist, lest they enrich the ISP thereby. (That would be a hard point to prove.)
But actually, even if it was just the letter of the sanctions that you had to obey, I would expect that "not trading with Iran" would be a lot harder than it sounds—it would require, for example, that you do not trade with an Iranian citizen who is currently geographically located in, say, Mexico. How would you know? Your random IM webapp would need a KYC process (submission of ID documents, etc.) to be "sanction-compliant", wouldn't it?
It may sound like there's no way to win for them, but well, mistakes have consequences. Time will heal the wounds.
It seems odd to me that IPs can still be used to (semi-)reliably determine a client's geographical location.
With the immensely larger address space that comes with IPv6, does that give the Internet a chance to completely sever the link between geography and IP address? Or do we still have issues with aggregating routes in a space-efficient way?
I don't think limited addresses was ever the reason for assigning in blocks but the real reason is it makes routing easier. Instead of having every router know the path to 128² addresses it only needs to know that everything starting with these few bytes goes to this port which saves memory on routers.
Addresses should correspond to network topology in order to be useful for, you know, routing. And network topology tends to correspond to physical location for practical engineering reasons. Of course there's no reason someone couldn't run a cable halfway around the world to use IP space in one country from a different one (or use a VPN, is what people do in practice), but realistically what would they gain from that?
But that’s wrong. Having a massive address space makes it trivial to keep routable blocks contiguous no matter how many IPs they contain.
But they still say:
> We would also like to notify our users that as we continue to update our systems over the next several weeks, we will soon begin blocking access to our service from IP addresses associated with an embargoed country.
I'm no expert, but I did spend a couple months checking alleged locations of VPN servers. I compared: 1) location alleged by the VPN provider; 2) location from various geolocation databases; and 3) ping results from several hundred servers (from various providers).
Bottom line, locations alleged by VPN providers and locations from geolocation databases were generally in agreement. But for some VPN providers, such as HideMyAss, ping results demonstrated that those locations were very often implausible. Because they implied signal transmission faster than the speed of light.
So anyway, basing life-altering decisions on IP-based geolocation is an extremely stupid (or at least, unjust) thing to do.
Eg; you're not allowed to sell stuff to Iran, or certain individuals.
Actions speak louder than words. Blocking people accounts was a management level decision that they are only regretting due to this coming to the public’s attention.
I work in banking, and when we discuss certain kinds of remote access, it's notable that there is no "OFAC" list. There are shit tons of lists for different things. I wonder which list Slack uses.
There's also the negative PR that comes with being labeled as "aiding and abetting the enemy".
* Broken in that they are levied against random individual citizens of sanctioned countries instead of groups trading with or state entities otherwise interacting with the US.
As another HN commenter @SamWhited put it, "Using a proprietary protocol that doesn't allow any form of federation is an unacceptable way to build a global community". We need to develop and use FLOSS protocols/tools as much as possible.
Is there a service you recommend?
https://twitter.com/aaomidi/status/1075621119028314112
You might read that and infer that Slack is somehow tracking the national origin, ethnicity, or race of all of its users, which would be much fishier behavior than IP-based blocking. They're explicitly saying that they don't do that and that they don't have that information.
But they did do it, so what does that mean...
Misguided politics of the Trump 'administration'. This stuff is highly unpopular outside the US.
For me a reason to avoid US services which actually enforce these politics. Slack can do whatever they want, but these actions make sure that I never want to be a customer of theirs and I would never recommend to use their services.