Previously, you could only see employee DMs if you turned on Compliance Exports, at which point you could download all of them going forward. Now it sounds like everything you've ever written could be downloaded at any time without notice.
So, all of those communications you had with co-workers based on the promise they would be private until you were notified future ones wouldn't be anymore? Now it's ALL available to your employer.
Meh. Nobody should be surprised by any of this in the slightest. If your employer provides / pays for any kind of communications tool, the only sane position is to assume that they can - and probably do - monitor every single byte you send.
Honestly I didn't realize my Slack DMs on my work account weren't private until I saw this. I assumed that since my employer pays for the account, any message I sent was being monitored.
That's what I'm thinking. I mean... of course employers expect to be able to have access to communication done by employees in the course of doing their jobs. They've been able to do this with every (archivable) communication medium since the invention of writing. Where is the news here?
If you want privacy use a private channel. Your employer's work tools don't qualify.
By private channel, I assume you mean a completely separate system that is not slack, and not a private slack channel (which, prior to this, was private from slack workspace admins, with hilarious results).
I think there's some middle ground, some grey area where whether it's alright is murky. It's kind of pulling the rug out from under people when the policy of a 3rd party provider abruptly changes and suddenly tons of messages become available to the company.
There are a number of things I might mention to a coworker over a private IM which wouldn't necessarily put my employment at risk, but would be awkward for management to suddenly have access to.
A couple made up examples:
"I'm super sick, but $boss is really pushing me to get the report out. I just want to go home and be sick all alone."
"I hate management's decision to reduce vacation days. No wonder we can't keep people around here."
"Did you see Tom's email? It's kinda awkward that he thinks he's a strong contributor to the group..."
No they don't, but I work at a large megacorp. At a small 10-20 person non-technology company startup, the admin on Slack is likely to be the owner or general manager. It could be another 5-10 people before a person is hired on as full-time IT.
These are all the sorts of things that you would ideally want management to know about so they can make better informed decisions. Assuming of course that you have competent and trustworthy managers.
>Assuming of course that you have competent and trustworthy managers.
You're begging the question.
"Competent and trustworthy" people won't abuse their power by definition. Anyone who abuses their power intentionally is untrustworthy, and anyone who abuses their power unintentionally is incompetent.
In the real world there are many incompetent and untrustworthy leaders. Slack has no choice but to operate in the real world.
Additionally, unless your work environment is sophisticated enough to fiddle with the certificates on your machine, and run a MITM proxy, you should be safe using something like GMail over https. Now I'm sure some companies do manage to intercept outgoing https traffic, but I doubt that most companies do.
OTOH, I still think being paranoid is the safest policy, so if you're plotting to overthrow your boss, or sell secrets to your biggest competitor, I still wouldn't do it on the company networking, and/or using a company computer.
Agreed. I was referring to the parent post's comment about using personal accounts at work. That might be safe, to some extent. But again, I would lean on the side of paranoia if you're talking about anything that could get you (fired|put in jail).
In any case, if you would plan any of that, I would guess that it would most probably leak out through entirely nontechnological channel - e.g. by somebody overhearing in person, or even by a co-conspirator defecting for their own gain.
Cloak-and-dagger games are very similar to building your own crypto: likely to be broken at a fundamental level, never mind the amount of magic security glitter that you pile on top.
Yeah, they said it here[1], and basically, given cause and given notice, they can still access private communications on work property. So not exactly what you are implying.
Thanks for the document. I think it still says that the employer should notify the employee beforehand of any potential monitoring of communications, which is different from assuming that every byte is being monitored.
You should not assume your communications are private if there is no end-to-end encryption. Also, the employers are often required to do this because of regulations. (I think those are silly regulations given that end-to-end encryption is so easily available nowadays, but the companies don't really have a choice here.)
You shouldn't assume they're private just because they're encrypted. Employers can and will install SSL certs on your desktop machine so that they can decrypt and scan/archive everything at the gateway. This is standard practice in financial companies, and is easily done anywhere.
They can also install screen capture and key logging software if they want, but that's less common and without disclosure is a lot shadier (although certainly legal in the US). I wouldn't expect it most places; it's a more extreme step.
But never trust encryption at work unless you know your company's policies.
If the employer had physical access, what would prevent them installing a rootkit? Then you couldn't detect a fake certificate no matter what you tried. Or deeper, if you distrust the provided software, what makes you trust the hardware? It's turtles all the way down ;)
I'm not talking about anything shady here. We're told that they're going to update our desktop SSL certificates for this reason. Partially CYA, partially compliance/legal. I'd probably quit if someone were keylogging or screengrabbing my work machine without my knowledge, but I'm not talking about employers being sneaky.
And this is exactly end-to-end encryption that the original thread responder mentioned; I know it's in place so I won't connect to my personal accounts from the work machine. That's what my phone is for (and I won't use their wifi for my phone, either).
The OS should have a trusted CA list somewhere (not sure where OSX does); checking that it matches a fresh install should be the first step. Note that there might be multiple lists - Firefox, for one, tends to keep their CA list separate.
I doubt this has anything to do with GDPR which is about personal information of customers and users. In this case the customer is the company and I don't think GDPR applies.
The announcement email says "As part of our growth and in support of upcoming changes to EU data protection law, we’re launching new tools and features and updating our Privacy Policy and User Terms."
"As part of our growth and in support of upcoming changes to EU data protection law, we’re launching new tools and features and updating our Privacy Policy and User Terms."
That sounds like a convenient marketing bullshit bogey man to me.
Actually GDPR also applies to your personal information that a company holds about you as an employee. However GDPR doesn’t apply if there are other laws that also apply to the data, which will be the case in a lot of circumstances for employees.
Why would you have such conversations or expectations when using company chat? That's unprofessional and, frankly, stupid because it puts one's job in danger (as could an in person conversion heard by the wrong people at work). If you want to talk in private, there's dozens of other chat programs out there you can run on your own devices.
You really thought Slack somehow didn't have access to those messages or deleted them? That this feature wouldn't be inevitable? Their whole sales spiel is that they can keep all your messages forever. This shouldn't be surprising. I'm not missing the point at all. I always assumed they had an entire history and could reveal it at any time. It's not end to end encrypted. Assuming otherwise is dangerous and frankly, idiotic in today's world.
why presumably due to GDPR? I would think it was a possible GDPR problem for them in the future. Specifically, you wrote it based on expectation it was private and now it is not, when did you give permission for sharing that data?
An employee's use of a company-provided communication channel like Slack isn't covered by GDPR, but the company is liable for the content that's stored in their Slack account. Under GDPR, I, as a customer of Company X, have a right to know about and request a copy of any data stored about me by that company, which includes Slack conversations, in both open and "private" channels. GDPR also applies retroactively, so the old compliance export process wouldn't cover it.
If it's your company's asset, you gave permission for sharing that data when you signed the e-handbook at orientation, the same document that gives them the right to monitor your work emails, put MDM on your work-issued phone, and log your work machine's network traffic into their SIEM.
You have no right to privacy when you're inside your company's office using your company's computers to access your company's network. They own it all, you just have permission to use it within the guidelines they set and you signed off on when you were hired.
Then your mistake was having conversations you wouldn't like your boss to read using your company's internal messaging system. How is this any different than e.g. emails?
This is to be expected from Big Brother. These days one should assume the telescreen is always watching and so should be very cautious as to not commit a thoughtcrime.
---- Edit ----
To clarify; my comment is referring to the novel 1984. While a bit tongue in cheek, it was not meant entirely as a joke.
This is a forum visited mostly by IT workers. I would assume most of us here know enough (or should know enough) to realize that any of our communications at work can be read by someone else and so you may want to treat it a bit as such.
In my personal programming working experience I have seen data captured in all of the following forms, reviewed, and then used to fire or prevent firing individuals.
So, all of those communications you had with co-workers based on the promise they would be private until you were notified future ones wouldn't be anymore? Now it's ALL available to your employer.
Surprise!
(This is presumably due to GDPR)