Back to browse
Exploiting Slack's video embeds to achieve E2EE communication

Exploiting Slack's video embeds to achieve E2EE communication

by victorio·Jun 15, 2026·29 points·3 comments

AI Analysis

●●●BangerWizardryBig Brain

Slack video blocks as encrypted iframe carriers is genuinely clever security research.

Strengths
  • Exploits undocumented Slack behavior (video blocks accept any URL) for real utility.
  • Uses browser SubtleCrypto + OpenPGP.js for proper client-side encryption.
  • Stores encrypted data in Slack metadata fields for stateless operation.
Weaknesses
  • Video blocks can't appear in ephemeral messages, limiting some workflows.
  • Depends on Slack not closing this embed loophole in future updates.
Category
Target Audience

Security-conscious teams using Slack for communication

Similar To

Signal · Keybase · Wire

Similar Projects

SaaSMid

Embed Notion Pages into Your Website

Notion-to-site wrapper competing with Super.so and Potion.

Solve My ProblemCozy
qwikhost
2021d ago