Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I don't think that applies to Slack admin access.
 help



In absence of a good enforcement mechanism, it absolutely does apply. Is Slack going to strip Mullenweg of admin control in absence of court order, as long as the Slack bills are paid? It would set a terrible precedent for them to do so unilaterally. Whatever the legal process this battle follows, it will be a year or two before it's even possible for a final ruling + court order for the handover of Slack admin control to happen. That's de facto Slack control for at least a year or two.

If employees can be persuaded to move themselves + systems to a board controlled chat instance, that's an angle, but Mullenweg has stronger cards if he's liked by employees.


If the board can show they fired him and he's now accessing their systems without authorization, I don't think it's a civil matter, and criminal courts might move faster.

> It would set a terrible precedent for them to do so unilaterally.

Speaking generally (not about Automattic), big SaaS have law enforcement desks that work on exactly this type of thing, and the "terrible precedent" is already widely set. Plenty of law enforcement outreach (which includes lawyers, courts, and actual law enforcement officials) results in pre-emptive compliance by SaaS companies. I would be massively surprised if Slack has not already done this in many cases, because most huge companies routinely do.

That's neither generally good nor generally bad; whether it's the right move depends on the charge, requested actions by law enforcement, status of legal proceedings, and the values/diligence by which the SaaS business assesses the legitimacy and likely cost/benefit of a law enforcement request. Note that "pre-emptive compliance" doesn't always mean an email saying "hey, the FBI said you suck so we terminated your account". There's a broad spectrum of tools available to a SaaS ranging from sending that email, to holding bespoke contract re-negotiations (which are functionally always in process between a SaaS and a huge customer) hostage to endless redlining rounds, to enforcing ToS violations that the SaaS previously turned a blind eye towards due to customer size.

> Whatever the legal process this battle follows, it will be a year or two before it's even possible for a final ruling + court order

Preliminary injunctions can be issued in days to weeks, not months to years, in all sorts of civil and criminal cases in all sorts of jurisdictions. Those can take the form of "don't change stuff with your admin access" or "grant admin control to someone else"-type orders. In cases where a service administrator is materially involved, injunctions are also easy to get on the basis of evidence preservation.

That's a pretty sharp tool. Failure to comply with those opens individuals and businesses up to way more legal penalties and tighter timeframes. Even if an injunction is later vacated/dismissed/modified, the legal argument that you violated it because you knew that would happen is an extremely tough sell.


It absolutely does.

OAUTH is 9/10ths of system access, it doesn't have the same ring to it...

And yet



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: