What If All Your Slack Chats Were Leaked?
nytimes.com
nytimes.com
- Anything written down and transmitted digitally will be available to anyone who wants it eventually. Besides my copy, the recipient has a copy, as do any number of intermediaries. Encrypted or not, that encryption will almost certainly be broken in my lifetime.
- Anything written down on physical medium or stored digitally (but not transmitted) will be freely available to anyone that wants it eventually. It's slightly more secure than a digital copy, because I have physical control over the only copy and would most likely know if that physical control was compromised (so my NAS is considered transmitted since it is possibly accessible).
- Anything I say to someone in person is pretty safe, depending on how much I trust them not to record what is said (otherwise it becomes classified as digitally transmitted). Of course now a copy remains in their mind's eye, which is in some cases worse since it can be modified and they don't even know it.
- Any thought I have that I have never expressed outside my body is almost completely safe, baring successful administration of truth serum (or until someone invents adversarial brain scans).
How does this affect me in real life? I don't write down things I wouldn't want other people to know, and I am pretty careful about saying things I don't want other people to know. I use encryption whenever I can because it will at least slow down the attackers, but I never assume something that is encrypted is safe.
> - Anything I say to someone [..]
In my hierarchy these two points are swapped. At least I think there is a real chance to keep written material secret as long as you are not a target of a state level adversary. I can write in a room where I am sure there are no cameras watching and I can put my copy in a safe where I would know if it was compromised. On the other hand I can almost never be sure not be audio recorded - be it deliberately or accidentally by any of the microphones that are almost everywhere nowadays.
We're increasingly surrounded by microphones/cameras, some of which are embedded in IOT or other appliances.
Given the NSA's track record, the risk of devices getting hacked, etc. I've become rather conscious of potential implications they could have.
> - Anything written down and transmitted digitally will be available to anyone who wants it eventually. Besides my copy, the recipient has a copy, as do any number of intermediaries. Encrypted or not, that encryption will almost certainly be broken in my lifetime.
I completely agree. So we're now assuming that the information will exist indefinitely for adversaries (NSA warehouse), however if I don't have a copy then it's effectively gone (for me only).
> - Anything I say to someone in person is pretty safe, depending on how much I trust them not to record what is said.
I'm not quite there yet, but I've become leary of all the phones, laptops, cameras, personal assistants, etc. While I'm from the US (so mass spying is supposed to be illegal), and most companies like Amazon/Apple have been shown to be "mostly telling the truth" in terms of how they only transmit data after a trigger phrase, it's a lot of microphones.
Let's assume the person I'm talking to is 100% trusted, all it takes is a hacked Alexa to leak the conversation.
Likely or practical? Not really. Do I do anything specific such that I'd consider myself a potential NSA target? Not really.
But I consider privacy a human right so it's always something I'm thinking about.
These are coming sooner than many people will be comfortable with: https://www.npr.org/templates/story/story.php?storyId=157448...
You need to start from the assumption that it can happen here and take steps to ensure that damage is minimal /recoverable. Part of that is policy, part culture, another part is technical but none are sufficient by themselves. On the tech side, look at systems designed to comply with data protection laws.
To me, the article's focus on permanently deleting old messages specifically avoids that error - it's not about avoiding disclosure but as defense-in-depth since disclosure is always a possibility. Beyond that, avoiding Slack (even with data deletion) is unlikely to increase security, but it does decrease priority for smaller users who might be swept up in an attack on Slack in general.
One day, I walked into a meeting to learn that I was being fired without warning, and would have absolutely no opportunity from that moment forward to log in to any of my business-related accounts.
That sudden unexpected contextual change really puts the lack of privacy control into perspective.
Suddenly, all the conversations that I had had with other coworkers were taken away from me, and made available to whoever was in charge of handling my old logins. Is that really acceptable?
I always make a point to remember the communication medium that I am using, and to filter myself respectively, but how many events like this exist that I have no control of? How can I predict the events that will put my privacy in jeopardy? What text exists that I would have liked to be more private?
1. My access to that record. I can no longer audit or edit that information. Even though I made a constant effort to preserve my privacy, I am left with a worrying lack of certainty. After all, I can't be expected to remember many months worth of communication, or what out of that I may find concerning in this new context.
2. My relationship with my (ex) employer. Sure I could have assumed an eventual change in that relationship from the beginning, but it's still drastic to have that change come suddenly and without warning.
I realize those are subtle, and that - hopefully - they do not become an issue. I only want to highlight my experience, because I found it eye opening.
The real issue is that there is an informal expectation of privacy without the user having permanent control over his/her information.
Except the desire for privacy isn't limited to the rude things you say.
None of us truly wants to live in a world where a third party can secretly review a permanent record of our communications.
After getting this Zulip migration approved the CEO pulled the plug in the last minute because he realized during a discussion about how to handle the import of the original messages - that all the old (toxic) discussions would now be in the hands of his internal employees and they couldn't be trusted not reading all the shit him and everyone else said behind each others back.
This made me aware that Slack has some interesting reasons for why teams are locked into their SaaS platform which may have nothing to do with scalability or uptime. In our case it was fear of libel lawsuits and further turnover. While you might be able to live with the insider-threat at SlackHQ with them being able to read your messages, sometimes the idea that anyone in your IT can read everything management has said shared or discussed in the past may be too risky for most.
* You can set a message retention policy that will delete each message after N days. (We're building the UI for it, but currently you can email support@zulipchat.com for help on turning it on.)
* On Zulip Cloud, you can set a message visibility limit that will save all your messages (e.g. for legal/compliance reasons), but only the last N messages will be visible to the team.
http://nymag.com/intelligencer/2016/03/what-hulk-hogan-taugh...
https://splinternews.com/the-gawker-hulk-hogan-trial-and-the...
Just because you don't think you have anything interesting doesn't mean a competitor isn't going to subpoena it years later.
Edit: That was before I read the article. He rants, with apparent sincerity, about the politically correct losers who thought that having an official, internal anything-goes-flamefest vent forum was a bad idea; describes how he went to great lengths to preserve it; finds out exactly why it really was a bad idea (it got subpoenaed so Microsoft could rake it for dirt); and then rants about that. At no point does he show any awareness of the irony.
What a guy.
If you think "I have nothing to hide" you're lacking in imagination.
Yes, 99.9% of what you do or say in your daily life is likely of no consequence. But every now and then you may do or say something that could be used against you, and someone who has many years worth of data collected on you can probably find quite a few such bits of info.
Among all of your internet "transactions" probably less than 0.1% are with your bank, for instance (sending your credentials, etc). You want end-to-end encryption and good security to protect that 0.1% of your data, not for the other crap.
People rant about coworkers and managers, complain about their spouses, joke about doing something illegal/stupid, compare themselves (favorably or not!) against a competitor, and share the occasional off color story/picture with a friend.
Should those things happen on corp systems/network? Most of them, no. Do they? Absolutely.
When we do those things, we don't think about it because we all have the immediate context, feelings, and stress of the situation in addition to knowing the other person involved.
If an opposing attorney or law enforcement reads it years later without the context and knowing the people, they can't interpret it the same way.
No. Privacy is not about your right to hide. It is about another's access to info about you, i.e. consent.
"If you've got nothing to hide" is pure misdirection. It doesn't matter one bit why I won't allow you access to personal info.
I do not owe you an explanation - if you want my data, you owe me one.
grep -i "new iphone" apple_dump.txtThe sexualized commentary about employee V's nice boobs.
The CEO arguing that employee M be kept because he's got leverage and we should let employee Z go instead.
That discussion we had about the time a hacker got ahold of 4000 customer records but we paid them off to delete the records.
I dunno, pretty much the stuff that can break a company into nothingness.
(FYI those are not scenarios where I work)
Lots of people believed what you did, but you only need to have said one thing.
For a long time I have noticed what I would call 'ankle biting journalism'. Basically take whatever is trendy, make only the most obvious observations about it (things that someone who only rudimentary knowledge would come up with in a few minutes), then act like these obvious things are serious and there is a problem here.
As usual, it's not that serious, and there isn't a problem here. I have no idea how Slack stores user chat history, but lets say they store them in plain text in the cloud. Then Slack is about as secure as IRC, which is exactly what it is trying to be, IRC 'but better'.
Besides, if you are using Slack for work, whoever is the 'Owner' of the enterprise account can export and view every conversation whenever they want, because 'compliance'.
Does it have to be " a shocking expose"?
All the things you mentioned about communication seem to apply to this article.
But I think what makes for interesting news are things that are new and non-obvious. The point of the thread starter (which resonated with me) is that this is neither. What rubs me wrong about the article is that it lacks context. From just this article, this sounds like a novel threat. But it's ludicrously far from that. You could write the same article about every communication system used by every business ever. For instance, tons of important stuff is still required to be done by fax, which is far less privacy-preserving than Slack. Email remains pretty much universally unencrypted.
The article doesn't try to grapple with this context at all, which makes it read oddly to me.
Any form of communication (or really any form of information storage) could be sensitive, that's my point exactly. There's literally no reason to mention Slack other than it's hot and the author could glom onto a trendy brand name to get people to read an article that is basically devoid of any novel content.
If a new sport which merges football, basketball, and chess become popular, we would see a bunch of articles 'People Who Play Chessketball are Getting Injured'. 'Chessketball has an Injury Problem'. 'Things you Need to Know before you Let Your Children Play Chessketball' Yes, people are more likely to be injured whenever they participate in any physical activity. Also when they ride a bike or go for a jog. Also, it turns out, if they don't do any physical activity at all they will suffer from heart disease.
I don't think that because the topic is "hot" that makes talking about it "no reason other than".
I feel like there is a surprising volume of "oh man why did the author bring this up" type posts on HN, I don't get it. The topic seems valid.
I hope that stories like this continue so that e2e encryption is supported by any messaging platform that wants to be taken seriously.
Do companies no longer have Document Retention Policies? That seems like the bigger piece of the story here.
Anything I write on IRC I assume is public. Not so with Slack, where much is written in DMs.
The email comparison is more apt.
As is the case with most chat platforms, the technical safeties put in place only serve to protect _legitimate_ users. The problem you're referring to is a matter of _illegitimate_ users or _insider-threats_.
* What if I copy-paste a sensitive conversation to a third-party?
* What if I export conversations or user accounts to a third-party?
* What if I grant an unauthorized party access to a conversation that they wouldn't otherwise be able to see?
In-transit encryption and encrypted storage do not solve these issues, because an insider threat inititated the action.
But I can directly go into all those things and delete at least my copies of them. Even with as many problems as Google and Facebook have, it's relatively straightforward to see the entire history of what I have on their sites and delete it.
> As usual, it's not that serious, and there isn't a problem here.
Quoth the article,
> Everything beyond that 10,000-message limit remains on Slack’s servers. So while those messages might seem out of sight and out of mind, they are all still indefinitely available to Slack, law enforcement and third-party hackers.
So I can't go back and check those on any free Slack server I post on.
And if someone decides to pay Slack for one of those servers, blam, any convo that got heated but that I forgot about is now visible to anyone with an axe to grind.
We've seen 10 year old tweets dredged up to go after people of all stripes, so this is certainly a thing that happens.
1. the mostly anonymized logs that require a technically difficult crack and would impact many thousands (millions?) of people simultaneously.
2. activity that can be tied directly back to individuals by anyone with time on their hands.
You're absolutely right that there are servers maintaining logs and such, that aren't accessible, but they fall into #1. And category #1 can happen, the famous cheating website being cracked as a great example. But that was itself relatively exceptional since simply being a user was enough to end in divorce.
The Slack message history distinctly falls into #2. It's a far more immediate problem.
I reported it to security. Next day I'm suspended. Turns out security did it because they wanted to search through 'just in case' but didn't want to go through the process properly.
Either it was my fault or they were incompetent, guess which one they chose. I was forced to quit eventually.
In the end I lost all my equity.
That’s just user hostile. If I don’t pay, I shouldn’t have all that message history stored forever. Either let me set retention on my messages or delete anything over 10k automatically. Don’t hold my content hostage and make it completely inaccessible and un-deletable unless I pay.
I'm pretty sure that won't work. They keep the logs regardless of whether you pay. It's not like if you don't pay for it, they erase your messages starting at 10k. You can't see it, but upon paying for slack premium, you'll immediately get access to them.
We might not have bothered if the history was simply deleted. I was grateful they didn't as there are some great moments in there, i.e. our first invoice, announcement of our first member of staff, prototype renders, etc.
2) There's no way to know now what you'd want to be private in the future.
For example, let's say you're gay and mention your boyfriend casually in a Slack chat. Then your country outlaws homosexuality. Suddenly, a casual detail becomes a secret you're terrified of getting out.
You can apply this analogy to your religious beliefs, traveling to certain countries, or even reading certain websites. You just don't know what the public or your govt will find unacceptable in the future.
Keybase is open source and uses pgp. Easy for the the average user. Can be used in command line.
Been using keybase for a while now, haven't tried the tool.
I guess there's also the problem of how to let a new joiner view previous messages. Can that be done with e2e encryption?
512 GB
> How about on your phone?
256 GB
> I guess there's also the problem of how to let a new joiner view previous messages. Can that be done with e2e encryption?
Of course. Share the key with a new joiner. Probably should be an option for admin, whether he wants to share (share the key) or does not want to share (generate new key and use it since that moment, old clients still remember old keys and can decrypt things).
Granted, I don't know much about encryption, end-to-end messaging, or otherwise, but it seems like a Very Hard Problem to solve for something like Slack.
Yes, shared among participants.
> it seems like a Very Hard Problem to solve for something like Slack.
There are plenty of messengers with E2E encryption and group chats with working search. Sure, it's not a straightforward task and server-side handling of search and other functions makes everything much easier, but I don't think that it's impossible task.
Though I'm not sure if demand is big enough. I would think that just self-hosting slack would be preferable for many organizations.
Honest question - how does this work across thousands of employees, some of which are almost guaranteed to be bad-actors at one point? Or is that just not a problem that's trying to be solved? What are the impacts if someone leaks that?
> There are plenty of messengers with E2E encryption and group chats with working search.
I don't know - are they on the (user) scale of Slack? How many people can you add to a group in WhatsApp or iMessage? (I honestly don't know, but I would suspect Slack lets you have more people in a 'group' than them).
Again, I have only a very cursory knowledge of how iMessage does E2E encryption. Obviously Slack would need to choose a different approach, but I wouldn't look at other messaging apps for examples.
- https://github.com/matrix-org/matrix-search
- https://github.com/vector-im/riot-web/issues/2548Now I guess you could set up some kind of broker system and have like a different encryption key per channel or per conversation or something, which would at least mean some hacker has to get both the archived chats as well as the keys. This would make stealing chat histories more complicated, but not less possible.
Now with iMessage in iCloud, I do not know how the E2E encryption is done.
It isn't done. Apple holds the master keys. The trust is that the iCloud server is not compromised.
> Messages in iCloud also uses end-to-end encryption. If you have iCloud Backup turned on, your backup includes a copy of the key protecting your Messages. This ensures you can recover your Messages if you lose access to iCloud Keychain and your trusted devices. When you turn off iCloud Backup, a new key is generated on your device to protect future messages and isn't stored by Apple.
https://pxlnv.com/linklog/improving-imessage-encryption/
> During an interview with Apple blogger and Daring Fireball’s owner John Gruber, Federighi said that the company has figured out a way to do syncing while still remaining unable to read your iMessages.
We're still at a point in time where 99% of communities are ready to make exactly 0 compromise for privacy over usability. Slack is catering to the 99%.
If one definition includes "the server(s)" then I'm positive it does at least on their Enterprise product, which notably last time I looked was the only one that could be considered HIPAA-compliant, aka "no your two - site medical practice can't use Slack to chat between the sites and coordinate anything involving patients."
Gosh, everyone who runs a computer is at risk for nation-state attacks.
The real question is: how high is the risk?
The risk section of an S1 tries to list every imaginable threat as a risk, without any assessment of the probability or impact (the two components of risk). Using this is a source for such an article is simply wrong.
> Right now, Slack stores everything you do on its platform by default — your username and password ...
I would be extremely surprised if they store plaintext or even encrypted passwords. Maybe the author means usernames/passwords sent in messages, but that's not unique to slack.
Does anyone 'behind-the-curtain' know anything that would contradict my assumptions?
This should be considered harmful, due to exactly the scenario described by the GP! Perhaps it's true that tokens and such should not be shared on a channel like Slack to begin with, but it's also very reasonable to assume that deleted messages actually get deleted, at least absent a data forensics expert or similar.
The logic goes: 1) something happened. 2) we regret it - please hide it from (most) quesry responses.
I know if I was dealing with an RDBMS, it's probably easy enough to delete it, but in an eventually consistent, heterogenous, append-only world, an actual delete-delete is kind of a hassle to even contemplate.
Our production emergency debuggers, there aren't many, get a bit more leeway than they probably should because they are trying to help us respond to failures under heavy SLA penalties. The 'these-people-ran-this-query' logs are immutable, and (hopefully) keep them in check from random lookups on their ex's during some dumpster fire exercise or another.
An encrypted password can be reversed, a hashed password cannot, it can only be verified. An encrypted password is only slightly preferable to a plaintext one because you still need to store the password somewhere, which am attacker would theoretically have access to, so it mostly serves as obfuscation.
In general, I shouldn't be able to tell you your password, I should just be able to tell you if the password you just gave me is the one you gave me before.
> Password verification commonly relies on cryptographic hashes. Storing all user passwords as cleartext can result in a massive security breach if the password file is compromised. One way to reduce this danger is to only store the hash digest of each password. To authenticate a user, the password presented by the user is hashed and compared with the stored hash. A password reset method is required when password hashing is performed; original passwords cannot be recalculated from the stored hash value.
https://en.wikipedia.org/wiki/Cryptographic_hash_function#Pa...
Slack itself is just a chat system. Ok, what's the risk? By design, people (the user base, or admins, up to each company) can integrate third party applications. The permissions system allows chat data to flow to these third parties without any logging or visibility by the Slack business customer. So in effect, each employee (depending on perms) may on behalf of their company, relay all chat messages to third parties that their company does not have a legally binding agreement and NDA with. This is the actual risk with Slack (the product, not the company).
So by design, employees can leak all the chats for all of the #public channels they are a member of and they won't even see it happening. Some companies choose to have admins review the third party applications and integration. "But they are #public, right?". People in a company don't assume that the public channels are really public in the sense that third parties outside of their company can see these messages. Employees may discuss very sensitive topics about their own customers that may not be appropriate to relay to extended parties that their company does not have mutually binding agreements and NDA's with.
When you run your own servers such as IRC, Mattermost, etc.., the chat admins know what third party servers (if any) they are linking to. This does not preclude an employee from relaying their own data through their workstation, but that can be addressed by edge DLP devices for monitoring or mitigation. Even then, the employee knows exactly what they are relaying.
When the chat system itself is a third party, and that third party allows relaying of user data, chat data to fourth parties, then by design, the system will always leak data. Slack does not alert members in a channel which bots are reading their messages real time and where that data is being stored and who is reading it and for what purpose. This also becomes a problem for data retention policies. The parties external to Slack may retain and use the data for as long as they wish, even if Slack purge data from a channel after a period of time. I see this as a legal quagmire.
In terms of leaking private messages, those are also stored so that an admin in a company may review them by request. This is only an issue if Slack's servers were compromised. That risk applies to both self hosted and third party chat servers, though Slack becomes a much more juicy target by having the private chats of many companies. This is similar to the risk of routing non-static content through Akamai. Akamai had employees caught selling sensitive data to other nations which highlights the risk of aggregating private data through one transit provider that can decrypt your data or see your data in plain text. This risk could be mitigated by having short data retention policies, however that is the opposite of what users expect. They expect their messages to be around forever.
http://media4.giphy.com/gifsu/2w5ffEOlO1ni8ArLnq/giphy-overl...