Hacker News new | ask | show | jobs
by _yy 3807 days ago
Is Slack really the right place for security-critical notifications?
3 comments

yes?

I mean the next step is to have an automated phone call go out to people (which is what we do for critical alerts).

Short of that, slack is on my desktop, laptop, and phone. If i don't have one of those around me at the time, you aren't getting ahold of me for any reason.

So yeah i think it's perfectly valid for security-critical notifications. Plus this isn't as security critical as you'd think. I don't want klaxons going off every time someone sshs into a server... This can just be an additional layer of security.

Slack is terrible for auditing, though. What's wrong with email?
people are more likely to be looking at chat windows as opposed to emails
Not in my book. Slack seems to be really cool but since it's not self-hosted and owned by a US entity, I'll stay clear.
It's an ssh login notification with a user and IP address. It's not notifying everyone what the new launch codes are. Let's not overstate it.
I'm not referring to the SSH logging, I mean slack in general.
We just discovered that some developers at my workplace use their domain user account credentials for Slack as well. My manager was not happy.
What would you use instead?
IRC on a server I control, or some slack clone with on-premise hosting. Call me paranoid, but I'm paranoid.
I still don't understand why everyone is so excited about slack, it really doesn't offer that much more than IRC.
I use IRC, but come on. It offers a lot more than IRC right out of the box.

* File uploads

* Embedding portions of links (tweets, images)

* A very good search

* Multi-line posts

* Code-formatting, including multi-line posts, and also snippets.

* A mobile client that alerts you when someone mentions you.

* Scroll-back history when you sign on at any time.

* Syncing between multiple clients.

Yes, you could create a bot or modify an irc server to do this, and then find or write a client that will do all that stuff, and an irc bouncer can fill in for a lot of this.

But Slack does it out of the box. Zero extra work needed.

I like IRC, but if you claim that Slack doesn't offer anything more than IRC, you're either delusional or using an incredibly broad definition of IRC.

It offers marketing and support, that's about it.

Nobody is selling IRC.

cough www.grove.io would like a word with you ;-)
Mattermost
or Actor.im
Are you asking if a communication platform is a good place for communications?

Yes.