Slack now lets you DM anyone — and that's a problem

Slack connect dms
(Image credit: Shutterstock)

Slack is going to start letting its users direct-message people outside of their company with the new Slack Connect DMs feature.

The service was originally announced back in October, but it’s only just started rolling out. The goal is to ensure companies working with partners or clients can communicate, though there are so many more possibilities than that.

However, it could also be regarded as a bad move, much like how publishing your personal email address on 4chan could be considered a very bad idea.

Connect DMs functions through Slack’s Connect feature, which launched last year and was built to help businesses collaborate through shared channels. Adding DMs into the mix is the latest part of that. 

The good news is that it’s not like email or text messaging, where anyone can send you a message provided they have the right address. 

Connect DMs work by sending a special link and force both sides to start the shared conversation. Depending on how a business has set up their Slack channel, it may require admin approval as well.

Connect DMs could have security and privacy issues

A lot of the outrage against this feature on Twitter has focussed on the risk of abuse and spam that stems from letting outsiders send messages to private Slack channels. Those concerns are because Slack has no options to block or report other users.

But there are, rightfully, concerns about security and privacy, such as the fact that Slack doesn’t encrypt your messages, and stores them indefinitely. That includes direct messages, which can be accessed archived and exported if your employer has a Slack Plus plan

That will likely include direct messages sent between companies, and presumably those conversations would be available to admins on both sides.

But personal privacy isn’t the only issue, because it could expose company’s sensitive information.

Remember the big Twitter hack from last year? The one that had celebrities tweeting out an almost-identical Bitcoin scam? 

According to a New York Times investigation, it all happened because a hacker managed to get into Twitter’s private Slack channel. Once there “Kirk”, as he was known, was able to access a service that gave him access to Twitter servers. Access that was then reportedly used to launch the crypto scam.

The story hasn’t been confirmed by Twitter, which declined to comment at the time. But it does go to show how something could go wrong if you give private Slack access to someone with nefarious intentions. 

Last week, an 18-year-old Florida man was sentenced to three years in prison for the hack, which took place while he was a juvenile. Florida authorities said he convinced a Twitter employee that he also was a Twitter employee and deserved access to Twitter's internal systems.

Connect DMs won’t give outsiders unfettered access to a private Slack channel, but it does mean there's another potential hole in security. Slack may not be the most obvious target for hackers, but we’ve already seen what can happen if they manage to access the wrong conversations. So Slack admins take note.

Slack Connect DMs is rolling out to paid users today, and will eventually come to free users “soon”.

Tom's Guide needs you!

We're looking at how our readers use VPN for a forthcoming in-depth report. We'd love to hear your thoughts in the survey below. It won't take more than 60 seconds of your time.

>> Click here to start the survey in a new window <<

TOPICS
Tom Pritchard
UK Phones Editor

Tom is the Tom's Guide's UK Phones Editor, tackling the latest smartphone news and vocally expressing his opinions about upcoming features or changes. It's long way from his days as editor of Gizmodo UK, when pretty much everything was on the table. He’s usually found trying to squeeze another giant Lego set onto the shelf, draining very large cups of coffee, or complaining about how terrible his Smart TV is.

Read more
Instagram app on iPhone
Instagram DMs just got better — 5 features worth trying
Slack
Slack was down — latest updates on massive outage
Instagram logo on iPhone with Instagram website in background.
Instagram now lets you schedule DMs — here's how to do it
How to tell if you&#039;ve been blocked on WhatsApp
The best WhatsApp alternatives in 2025
Discord on a phone and a laptop
Almost 1 million Discord users just had their account details exposed in new RestoreCord data breach — what to do now
An illustration of a person holding a smartphone with a padlock in front of speech bubbles on the screen
The best encrypted messaging apps in 2025
Latest in Instant Messengers
How to delete TikTok
8 TikTok alternatives — where to go if the app gets banned
How to tell if you&#039;ve been blocked on WhatsApp
New WhatsApp green screen bug is making the app unusable
The WhatsApp logo on a screen in front of a laptop
WhatsApp starts rolling out Events planning feature for group chants — here’s how it works
The WhatsApp logo on a screen in front of a laptop
WhatsApp looking to add AirDrop-esque feature to iPhones — what we know
The WhatsApp logo on a screen in front of a laptop
WhatsApp drops surprise design update — it's rounder and darker now
WhatsApp logo on iPhone
How to rejoin a group chat on WhatsApp
Latest in News
iPhone 16
Hoping for a new iPhone 16 color? You’re probably out of luck
iOS Photos app
iOS 18.4 Photos update makes it easier to sort, hide and delete your photos on iPhone — here’s what you can do
Dyson Purifier Cool (TP11) in office
Dyson just launched its new high-tech air purifier — right in time for allergy season
Nvidia RTX 5090
RTX 5060 breaks cover in Acer gaming PC — is Nvidia’s next GPU launch imminent?
Samsung Galaxy Tab S10 FE renders
Samsung's Galaxy Tab S10 FE crushes its predecessor with 40% speed boost in leaked benchmark
The camera assembly on the Google Pixel 9
The latest Google Pixel update is breaking fingerprint scanners — but there may be a fix