{"id":41944,"date":"2021-03-25T15:54:59","date_gmt":"2021-03-25T15:54:59","guid":{"rendered":"http:\/\/icloud.pe\/blog\/?guid=8777c0d40c76ab42a917737de8741be6"},"modified":"2021-03-25T15:54:59","modified_gmt":"2021-03-25T15:54:59","slug":"slack-abandons-external-message-invites-over-harassment-concerns","status":"publish","type":"post","link":"https:\/\/icloud.pe\/blog\/slack-abandons-external-message-invites-over-harassment-concerns\/","title":{"rendered":"Slack abandons external message invites over harassment concerns"},"content":{"rendered":"<p><span class=\"field field-name-field-author field-type-node-reference field-label-hidden\"><br \/>\n      <span class=\"field-item even\"><a href=\"https:\/\/www.cloudpro.co.uk\/authors\/bobby-hellard\">Bobby Hellard<\/a><\/span><br \/>\n  <\/span><\/p>\n<div class=\"field field-name-field-published-date field-type-datetime field-label-hidden\">\n<div class=\"field-items\">\n<div class=\"field-item even\"><span class=\"date-display-single\">25 Mar, 2021<\/span><\/div>\n<\/p><\/div>\n<\/div>\n<p class=\"short-teaser\">\n<a href=\"https:\/\/www.cloudpro.co.uk\/\" title=\"\" class=\"combined-link\"><\/a><\/p>\n<div class=\"field field-name-body\">\n<p><a href=\"https:\/\/www.itpro.co.uk\/search\/slack\" data-cke-saved-href=\"https:\/\/www.itpro.co.uk\/search\/slack\">Slack<\/a> has removed a capability that allowed users to customise external invites with a message after users expressed concerns that the function could subject users to harassment and unwanted messages.<\/p>\n<p>The communications platform has said it &#8220;immediately&#8221; removed the function on\u00a0Slack DMs, a new cross-organisational messaging service that only launched yesterday.<\/p>\n<p>Slack DMs was designed as a new feature for\u00a0<a href=\"https:\/\/www.itpro.co.uk\/marketing-comms\/business-communications\/356217\/slack-expands-business-communications-with-slack\"  data-cke-saved-href=\"https:\/\/www.itpro.co.uk\/marketing-comms\/business-communications\/356217\/slack-expands-business-communications-with-slack\">Slack Connect<\/a>, the platform&#8217;s external channel sharing feature that provides a secure way of collaborating with teams outside of an organisation, that first launched in June 2020. The DMs feature allowed users to connect with an external user\u00a0by sending an\u00a0invite with a bespoke message.<\/p>\n<p>Shortly after its launch,\u00a0Twitter product developer Menotti Minutillo revealed that the function could be used to send a seemingly unlimited number of\u00a0malicious messages to external users. The feature would also email a copy of the invite to the target containing the message in full, which appeared to be impossible to block as they originated from a generic Slack address.<\/p>\n<div class=\"wysiwyg-widget-wrapper\">\n<blockquote class=\"twitter-tweet\">\n<p lang=\"en\" dir=\"ltr\">well that was easy as shit to abuse<\/p>\n<p>&#8211; send invite with nasty language<br \/>&#8211; slack emails you w\/ the full content of the invite<br \/>&#8211; can&#39;t block the emails because they come from a generic slack address that informs you of invites<br \/>&#8211; abuser can keep inviting w\/ abusive language <a href=\"https:\/\/t.co\/Mw9W5L251a\">https:\/\/t.co\/Mw9W5L251a<\/a> <a href=\"https:\/\/t.co\/dWEAD7ccRO\">pic.twitter.com\/dWEAD7ccRO<\/a><\/p>\n<p>&mdash; Menotti Minutillo (@44) <a href=\"https:\/\/twitter.com\/44\/status\/1374737695444901891?ref_src=twsrc%5Etfw\">March 24, 2021<\/a><\/p>\n<\/blockquote>\n<p><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/div>\n<p>\nFollowing the initial backlash, Slack has now said that users will be unable to customise messages as part of the invite function.<\/p>\n<p>&#8220;After rolling out Slack Connect DMs this morning, we received valuable feedback from our users about how email invitations to use the feature could potentially be used to send abusive or harassing messages,&#8221; said Jonathan Prince, Slack&#8217;s vice president of communications and policy. &#8220;We are taking immediate steps to prevent this kind of abuse, beginning today with the removal of the ability to customise a message when a user invites someone to Slack Connect DMs.<\/p>\n<p>&#8220;We made a mistake in this initial roll-out that is inconsistent with our goals for the product and the typical experience of Slack Connect usage. As always, we are grateful to everyone who spoke up, and we are committed to fixing this issue.&#8221;<\/p>\n<p>Slack DMs &#8211; and Slack Connect &#8211; is only available on\u00a0paid businesses accounts. <\/p>\n<\/p><\/div>\n","protected":false},"excerpt":{"rendered":"<p><span class=\"field field-name-field-author field-type-node-reference field-label-hidden\"><br \/>\n      <span class=\"field-item even\"><a href=\"https:\/\/www.cloudpro.co.uk\/authors\/bobby-hellard\">Bobby Hellard<\/a><\/span><br \/>\n  <\/span><\/p>\n<div class=\"field field-name-field-published-date field-type-datetime field-label-hidden\">\n<div class=\"field-items\">\n<div class=\"field-item even\"><span class=\"date-display-single\">25 Mar, 2021<\/span><\/div>\n<\/p><\/div>\n<\/div>\n<p class=\"short-teaser\">\n<a href=\"https:\/\/www.cloudpro.co.uk\/\" title=\"\" class=\"combined-link\"><\/a><\/p>\n<div class=\"field field-name-body\">\n<p><a href=\"https:\/\/www.itpro.co.uk\/search\/slack\" data-cke-saved-href=\"https:\/\/www.itpro.co.uk\/search\/slack\">Slack<\/a> has removed a capability that allowed users to customise external invites with a message after users expressed concerns that the function could subject users to harassment and unwanted messages.<\/p>\n<p>The communications platform has said it &#8220;immediately&#8221; removed the function on\u00a0Slack DMs, a new cross-organisational messaging service that only launched yesterday.<\/p>\n<p>Slack DMs was designed as a new feature for\u00a0<a href=\"https:\/\/www.itpro.co.uk\/marketing-comms\/business-communications\/356217\/slack-expands-business-communications-with-slack\" target=\"_blank\" data-cke-saved-href=\"https:\/\/www.itpro.co.uk\/marketing-comms\/business-communications\/356217\/slack-expands-business-communications-with-slack\" rel=\"noopener\">Slack Connect<\/a>, the platform&#8217;s external channel sharing feature that provides a secure way of collaborating with teams outside of an organisation, that first launched in June 2020. The DMs feature allowed users to connect with an external user\u00a0by sending an\u00a0invite with a bespoke message.<\/p>\n<p>Shortly after its launch,\u00a0Twitter product developer Menotti Minutillo revealed that the function could be used to send a seemingly unlimited number of\u00a0malicious messages to external users. The feature would also email a copy of the invite to the target containing the message in full, which appeared to be impossible to block as they originated from a generic Slack address.<\/p>\n<div class=\"wysiwyg-widget-wrapper\">\n<blockquote class=\"twitter-tweet\">\n<p lang=\"en\" dir=\"ltr\">well that was easy as shit to abuse<\/p>\n<p>&#8211; send invite with nasty language<br \/>&#8211; slack emails you w\/ the full content of the invite<br \/>&#8211; can&#8217;t block the emails because they come from a generic slack address that informs you of invites<br \/>&#8211; abuser can keep inviting w\/ abusive language <a href=\"https:\/\/t.co\/Mw9W5L251a\">https:\/\/t.co\/Mw9W5L251a<\/a> <a href=\"https:\/\/t.co\/dWEAD7ccRO\">pic.twitter.com\/dWEAD7ccRO<\/a><\/p>\n<p>\u2014 Menotti Minutillo (@44) <a href=\"https:\/\/twitter.com\/44\/status\/1374737695444901891?ref_src=twsrc%5Etfw\">March 24, 2021<\/a><\/p>\n<\/blockquote>\n<\/div>\n<p>\nFollowing the initial backlash, Slack has now said that users will be unable to customise messages as part of the invite function.<\/p>\n<p>&#8220;After rolling out Slack Connect DMs this morning, we received valuable feedback from our users about how email invitations to use the feature could potentially be used to send abusive or harassing messages,&#8221; said Jonathan Prince, Slack&#8217;s vice president of communications and policy. &#8220;We are taking immediate steps to prevent this kind of abuse, beginning today with the removal of the ability to customise a message when a user invites someone to Slack Connect DMs.<\/p>\n<p>&#8220;We made a mistake in this initial roll-out that is inconsistent with our goals for the product and the typical experience of Slack Connect usage. As always, we are grateful to everyone who spoke up, and we are committed to fixing this issue.&#8221;<\/p>\n<p>Slack DMs &#8211; and Slack Connect &#8211; is only available on\u00a0paid businesses accounts. <\/p>\n<\/p><\/div>\n","protected":false},"author":403,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[],"tags":[],"class_list":["post-41944","post","type-post","status-publish","format-standard","hentry"],"_links":{"self":[{"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/posts\/41944","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/users\/403"}],"replies":[{"embeddable":true,"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/comments?post=41944"}],"version-history":[{"count":1,"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/posts\/41944\/revisions"}],"predecessor-version":[{"id":41945,"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/posts\/41944\/revisions\/41945"}],"wp:attachment":[{"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/media?parent=41944"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/categories?post=41944"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/tags?post=41944"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}