People can utilize Slack's new feature to send unblockable abuse within invitations.
What you need to know
- Slack now lets you send direct messages to anyone on the platform.
- The feature is intended to help people work across organizations.
- People seem to have already found flaws with the system.
Slack, the popular communication platform, recently gained the option to send direct messages (DMs) to anyone using the service. The feature is called Slack Connect DMs, and it is meant to help people work with partners or clients that are part of another company. The feature is available now for paid Slack customers and will roll out to free users in the future.
While the feature lets you message anyone across Slack, there are some limitations. First, IT departments have to allow the feature. Second, people have to accept an invite to start messaging through Slack.
These protections are in place to make sure that only those that want to chat with someone have to see messages. You, theoretically, shouldn't be able to be spammed with messages. You can, however, get harassed by message requests, at least according to Twitter user Menotti Minutillo.
well that was easy as shit to abuse
— Menotti Minutillo (@44) March 24, 2021
- send invite with nasty language
- slack emails you w/ the full content of the invite
- can't block the emails because they come from a generic slack address that informs you of invites
- abuser can keep inviting w/ abusive language https://t.co/Mw9W5L251a pic.twitter.com/dWEAD7ccRO
According to Minutillo, if you send someone an invite to the message, the other person will see the contents of your invitation. That message can contain anything you'd like, including abusive language. As far as we can tell, you can't block these types of emails because they come from a generic Slack email address.
Hopefully, Slack plugs this hole in the system soon. The ability to connect with anyone across Slack could be extremely useful, but it's important that it works well.
0 comments:
Post a Comment