Slack now lets you DM anyone, and you can use it to send unblockable abuse
People can utilize Slack's new feature to send unblockable abuse within invitations.
Updated March 24, 2021 at 2:35 pm ET: In response to concerns raised over potential for abuse, Slack has disabled the ability to customize the message inviting people to try the cross-org DM feature. In a statement to The Verge, Slack's vice president of communications and policy, Jonathan Prince, said the following:
What you need to know
- Slack now lets you send direct messages to anyone on the platform.
- The feature is intended to help people work across organizations.
- People seem to have already found flaws with the system.
Slack, the popular communication platform, recently gained the option to send direct messages (DMs) to anyone using the service. The feature is called Slack Connect DMs, and it is meant to help people work with partners or clients that are part of another company. The feature is available now, though options vary for for paid and free Slack customers. Paid users can initiate direct messages, but free users can only participate after someone else initiates. Both paid and free users will soon be able to initiate direct messages.
While the feature lets you message anyone across Slack, there are some limitations. First, IT departments have to allow the feature. Second, people have to accept an invite to start messaging through Slack.
These protections are in place to make sure that only those that want to chat with someone have to see messages. You, theoretically, shouldn't be able to be spammed with messages. You can, however, get harassed by message requests, at least according to Twitter user Menotti Minutillo.
well that was easy as shit to abuse
- send invite with nasty language
- slack emails you w/ the full content of the invite
- can't block the emails because they come from a generic slack address that informs you of invites
- abuser can keep inviting w/ abusive language https://t.co/Mw9W5L251a pic.twitter.com/dWEAD7ccROwell that was easy as shit to abuse
- send invite with nasty language
- slack emails you w/ the full content of the invite
- can't block the emails because they come from a generic slack address that informs you of invites
- abuser can keep inviting w/ abusive language https://t.co/Mw9W5L251a pic.twitter.com/dWEAD7ccRO— Menotti Minutillo (@44) March 24, 2021March 24, 2021
According to Minutillo, if you send someone an invite to the message, the other person will see the contents of your invitation. That message can contain anything you'd like, including abusive language. As far as we can tell, you can't block these types of emails because they come from a generic Slack email address.
Hopefully, Slack plugs this hole in the system soon. The ability to connect with anyone across Slack could be extremely useful, but it's important that it works well.
Get the Windows Central Newsletter
All the latest news, reviews, and guides for Windows and Xbox diehards.
Sean Endicott is a tech journalist at Windows Central, specializing in Windows, Microsoft software, AI, and PCs. He's covered major launches, from Windows 10 and 11 to the rise of AI tools like ChatGPT. Sean's journey began with the Lumia 740, leading to strong ties with app developers. Outside writing, he coaches American football, utilizing Microsoft services to manage his team. He studied broadcast journalism at Nottingham Trent University and is active on X @SeanEndicott_ and Threads @sean_endicott_.