When I was at unnamed major financial institution, we were ordered to stop using WhatsApp, but it had nothing to do with security and everything to do with avoiding even the possibility of the appearance of backroom dealing or production avoidance in the event of subpoena. Maybe the truth has more to do with that, or maybe not, what do I know, who are all you people anyway, and why am I posting here?
WhatsApp also feels... tonally weird to use at a serious company, like in the same way it would feel weird to be using snapchat for team meetings.
WhatsApp banned on House staffers' devices
141–150 of 161 posts
Re: WhatsApp banned on House staffers' devices
#142Re: WhatsApp banned on House staffers' devices
#143Good. Another point to be made when my friends push me to install bloated spyware just to plan a pizza party. Use Signal.
Re: WhatsApp banned on House staffers' devices
#144Earlier quoted context omitted.
Their statement doesn't sound like what you said at all: > The Office of Cybersecurity has deemed WhatsApp a high-risk to users due to the lack of transparency in how it protects user data, absence of stored data encryption, and potential security risks involved with its use (Of course that statement seems to be highly confused overall. What "stored data encryption"?)
Does WhatsApp encrypt the data on the device after it’s received and decrypted at your phone’s end (then stored indefinitely)? I thought the term of art was “encrypted at rest,” but “stored data encryption” makes sense to me too. I was of the impression that Whatsapp’s messages (and its backups, photos, etc) kind of just hung around in plaintext once they reached the device. Which would seem to be a problem should th…
The operating system (Android/iOS) encrypts everything anyway. Why would you double that? More to the point, do any of the other "safe" apps, like iMessage, do that?
Re: WhatsApp banned on House staffers' devices
#145When I was at unnamed major financial institution, we were ordered to stop using WhatsApp, but it had nothing to do with security and everything to do with avoiding even the possibility of the appearance of backroom dealing or production avoidance in the event of subpoena. Maybe the truth has more to do with that, or maybe not, what do I know, who are all you people anyway, and why am I posting here?
i heard (anecdotally) that wall street used to run on Yahoo IM - fascinating. do you know if that extended into your previous employer?
Re: WhatsApp banned on House staffers' devices
#146When I was at unnamed major financial institution, we were ordered to stop using WhatsApp, but it had nothing to do with security and everything to do with avoiding even the possibility of the appearance of backroom dealing or production avoidance in the event of subpoena. Maybe the truth has more to do with that, or maybe not, what do I know, who are all you people anyway, and why am I posting here?
WhatsApp also feels... tonally weird to use at a serious company, like in the same way it would feel weird to be using snapchat for team meetings.
When trying to avoid subpoenas of data on the device itself, it's important to frequently "lose" the phone with the messages on.
Re: WhatsApp banned on House staffers' devices
#147I can't imagine any justification for any government device that should be secure to have anything on it but the bare minimum software and the device in whatever hardened mode it has. If they visit the White House, government facility ... should go in a locker. I worked for a company that sent people onsite to government contractors. One contractor we rarely visited was at a facility where you arrived at the front ga…
Re: WhatsApp banned on House staffers' devices
#148Earlier quoted context omitted.
What implementation of end to end encryption doesn't involve this?
OTR, for IRC/XMPP, PGP for Email and Olm/Megolm provided by Element for Matrix operators. Essentially the software creating the keys is not controlled by the same entity controlling the transmission method. In email/matrix you have an additional protection in that you can host your own server; the best protection is the one you never have the possibility of traffic being diverted, and even if it was it would be encry…
- yes not end-to-end encrypted by default
- but I haven't seen any complaints about their end-to-end encryption, except that it isn't enabled by default
- and unlike WhatsApp they publish reproducible builds so we can know the endpoints do what the source code says
Re: WhatsApp banned on House staffers' devices
#149Earlier quoted context omitted.
Signal lacks other compliance features. e.g. message archiving It might be good if you're a journalist, but it's not as good if you have compliance requirements beyond confidentiality.
Wouldn't this be pretty easy to roll your own? You could set up different servers like Molly does. Or you could just recompile the app. Or you could force link it to a desktop session? Just spitballing here