Live data from Hacker News

WhatsApp banned on House staffers' devices

axios.com

121–130 of 161 posts

Re: WhatsApp banned on House staffers' devices

#121

Earlier quoted context omitted.

Yeah, but Signal really didn't help them at all with that. As with most of these phone oriented encrypted messengers, Signal is pretty sloppy with identity management. It would be hard to find a better example of this than SignalGate 1.0. * https://articles.59.ca/doku.php?id=em:sg End to End Encrypted Messaging in the News: An Editorial Usability Case Study (my article)

It wasn't Signal's identity management that proved to be a problem: https://www.theguardian.com/us-news/2025/apr/06/signal-group... When it comes to practical cryptography, nobody is doing signing parties anyway. It's all TOFU unless someone forces people's hands, and when you force people to do security you can assume they won't bother checking if the QR code they're scanning is coming from a real app or a livestrea…

If you blame the incorrect phone number in the Apple address book then sure, but that implies that you think that a smart phone address book should be responsible for identity management in an end to end encrypted messenger. Oh, and the telephone number to identity mapping is the responsibility of:

* Signal

* Twillo

* The phone company

That's all OK as far as it goes, but the root problem here is that a typical Signal user is made aware of none of this. Sure it's legit to take convenience over security, but it is not OK to leave this tradeoff completely unknown to the people affected.

Re: WhatsApp banned on House staffers' devices

#122

Earlier quoted context omitted.

If you think end-to-end encryption is the only thing that matters in security, then yeah sure, WhatsApp is more secure. Personally, I'd be embarrassed to let people know I thought that way, but to each their own.

So you would potentially prefer an app without end-to-end encryption to WhatsApp? What are these important security features?

The threat model of an organisation is almost the opposite of you as an individual.

For you, you trust yourself the most, followed by your device, and the intermediate servers are a threat. For an organisation, the servers are the most trusted entity, followed by the org-provided device, and a certain percentage of users are an active threat.

Re: WhatsApp banned on House staffers' devices

#123

Earlier quoted context omitted.

> WhatsApp is always end-to-end encrypted, Teams only in certain cases Which is an anti-feature given this application: you want a certain level of oversight and control over what staffers communicate.

Their statement doesn't sound like what you said at all: > The Office of Cybersecurity has deemed WhatsApp a high-risk to users due to the lack of transparency in how it protects user data, absence of stored data encryption, and potential security risks involved with its use (Of course that statement seems to be highly confused overall. What "stored data encryption"?)

Does WhatsApp encrypt the data on the device after it’s received and decrypted at your phone’s end (then stored indefinitely)? I thought the term of art was “encrypted at rest,” but “stored data encryption” makes sense to me too.

I was of the impression that Whatsapp’s messages (and its backups, photos, etc) kind of just hung around in plaintext once they reached the device.

Which would seem to be a problem should the device be stolen, or observed by other applications on the phone or a tethered device, or twiddled with sneaky hardware (e.g. [0]) that might use physical means to access the device’s file system.

Although as I understand it, the privacy claims are kind of window dressing anyway, and Meta has been more than willing to share plenty of WhatsApp’s data with all and sundry… even before AI-in-the-same-search-bar came along [1]

[0] https://shop.hak5.org/products/omg-cable

[1] https://www.propublica.org/article/how-facebook-undermines-p...

Re: WhatsApp banned on House staffers' devices

#124
post #79
post #72

Earlier quoted context omitted.

I ban Whatsapp but require Teams on company devices. Can you explain why the thinking is wrong?

This is very reasonable if you have compliance needs or similar. That’s not what this office is saying - it’s saying teams is more secure. This is wrong. The nature of banning private messaging apps is trading security for legibility. If this office is interested in that (which it’s not - it allows Signal), they should say so.

Your Teams is not the government's Teams.

Microsoft maintains specific secure government versions of Teams that use their own special secure data centers. It's a full parallel extra secure set of infrastructure.

Re: WhatsApp banned on House staffers' devices

#125
post #48
post #16

Earlier quoted context omitted.

>Government: Zuck put a backdoor in WhatsApp or we will put you in a blacksite UFC ring and beat you up. Source? >Also Government: WhatsApp has a backdoor. Don't use it. If "zuck" is really in the pocket of the US government, why should they worry about their own backdoors?

> If "zuck" is really in the pocket of the US government, why should they worry about their own backdoors? Have you ever watched a Saturday morning cartoon? Minions betray their masters all the time. An effective evil overlord doesn’t underestimate their lackey’s capacity for duplicity and betrayal at a pivotal moment. The most fun may even appreciate the gall: https://memory-alpha.fandom.com/wiki/The_Nagus_(episode)…

I have a movie for you: "Broken City" (2013) great cast and constantly unexpected turns of events

Re: WhatsApp banned on House staffers' devices

#127
post #62

[flagged]

Given the events of the last few days, it's possible the United States Government - who just dropped massive weaponry onto a target the size of a dishwasher from halfway across the world without anyone knowing - aren't the incompetent boobs your purport they are, despite their rejection of venture-backed smartphone apps.

Re: WhatsApp banned on House staffers' devices

#128
post #28
post #15

Earlier quoted context omitted.

WhatsApp on TV: “Trust us! It’s encrypted :) :) :)”

And on social media. Maybe I'm being too literal and pedantic, but it bugs me that they say "nobody" can read your messages. What's the point of using it if even the recipient can't read them (or the sender for that matter!).

I often remember something I posted and wish nobody had ever seen it.

Re: WhatsApp banned on House staffers' devices

#129
post #85
post #62

[flagged]

Perhaps you're unaware that there is a special, DoD-certified version of Teams called "Gov Teams", which can be used to share data at multiple impact levels securely. This version of Teams, and the entire Office365 suite, has undergone extensive security certification for use with high IL data.

Having seen other certification programs before I’m hesitant to think that it’s not theatre

Re: WhatsApp banned on House staffers' devices

#130
post #76
post #74

Earlier quoted context omitted.

Isn't deepseek 100% open source?

The model weights themselves are, but there's also the hosted SaaS.

I remember something about llama only being open-weight, not open-source. Does that mean deepseek is under a similar license and not completely open? I seem to recall some concern about llama's license.
Post reply on HN