Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

@g3rv4, I understand it really sucks and feels terrible. But I also understand their reaction.

Don't be surprised about legal writing. He/She as a legal person is responsible for writing in a very clear and explicit way since any misunderstanding might cost the reader or themselves in the future. It just shows their accountability. You don't want a misunderstanding cost you trouble.

I have colleagues working in the legal department. They understand you, but they still have to make sure there is no misunderstanding there.

They are serving enterprise companies, Anything goes wrong can destroy their business. It makes sense for them not to risk anything.

Companies are paying them for the security. Otherwise, there are cheaper alternatives to Slack with somewhat similar features.

Slack could allow custom clients. But I'm pretty sure all major customers will require their employees not to use un-official clients for security reasons.



> Don't be surprised about legal writing. He/She as a legal person is responsible for writing in a very clear and explicit way since any misunderstanding might cost the reader or themselves in the future.

Ok, then he/she can be called out since we are on the front page of HN and there is a lot of noise and harm done. I honestly can’t see a single reason why slack legal department, probably worth millions per year, in a company worth several billions, can write such things just to kill a free chrome extension built by a single person for non profit reasons. I never used slack but from now on I will actively advice against using it. When you arrive at the point that you can’t even modify your browser to see whatever you like I think that we are almost at the brink of total destruction/anarchy/“choose your not so preferred destination”. Disclosure for slack layers: I never used your product, so I never agreed to your TOS and I would never use it hopefully. I am not associated in any way with any of your competitors. I sadly have to admit that sometimes I play with JSFiddle in my browser just for fun. If you want to sue me please go on, there is not much difference compared to what you are suing g3rv4 for.


> But I also understand their reaction.

And I don't. I mean, charitably this could be attributed to some non-tech person noticing the extension and sending/asking legal to send a C&D because they didn't like it. That's the only thing I can think of, because the alternative is plain malice. This is a client-side modification, the main part of their letter is just absurd, and the justification is nonsense.


But they are risking something. As a Slack user, I find the temerity of this extremely annoying. I imagine that I'm not the only one.

If those enterprise customers are worried, they're free to lock down browser extensions on their employees' systems if they want. If they're worried about this, they should be just as worried about extensions acting on webmail, internal sites, etc.


I get it... but literally, there are THOUSAND extensions already injecting javascript on their site.

are they going after all of them? if that's the case, I'd understand.


> Companies are paying them for the security. Otherwise, there are cheaper alternatives to Slack with somewhat similar features.

> Slack could allow custom clients. But I'm pretty sure all major customers will require their employees not to use un-official clients for security reasons.

Is security really a client side thing? Obviously I understand stuff like key logging and such in a malicious client, but how would somebody using a custom client affect another user's security with an official client? I mean if it would, wouldn't that be a horrible situation anyway from security point of view?


And by writing that way they likely underweight the PR risk to their business. It's their choice, but it sure as hell just turned me off.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: