Live data from Hacker News

WhatsApp banned on House staffers' devices

axios.com

151–160 of 161 posts

Re: WhatsApp banned on House staffers' devices

#151
post #139
post #92

I can't imagine any justification for any government device that should be secure to have anything on it but the bare minimum software and the device in whatever hardened mode it has. If they visit the White House, government facility ... should go in a locker. I worked for a company that sent people onsite to government contractors. One contractor we rarely visited was at a facility where you arrived at the front ga…

Thank goodness somebody takes security seriously. The cynic in me (opposed in strongest terms by the realist and give-a-damn in me) says: Whitehouse? Go for it. You'll probably leave more stupid (confused) than you went in.

In this case it was a military facility and contractor so security is kinda built in to the system to some extent.

Security involving politicians / civilian workers ... much harder I imagine.

Re: WhatsApp banned on House staffers' devices

#152
post #128
post #28

Earlier quoted context omitted.

And on social media. Maybe I'm being too literal and pedantic, but it bugs me that they say "nobody" can read your messages. What's the point of using it if even the recipient can't read them (or the sender for that matter!).

I often remember something I posted and wish nobody had ever seen it.

Ouch, ok, yes, point taken...

Re: WhatsApp banned on House staffers' devices

#153
post #85

Earlier quoted context omitted.

Perhaps you're unaware that there is a special, DoD-certified version of Teams called "Gov Teams", which can be used to share data at multiple impact levels securely. This version of Teams, and the entire Office365 suite, has undergone extensive security certification for use with high IL data.

Having seen other certification programs before I’m hesitant to think that it’s not theatre

In this case the certification program is extremely onerous, having experienced it myself. A government testing agency will not give you an authorization to operate on a given network or given data impact level until they can independently verify you meet very specific standards, including keeping data at different impact levels physically separate and encrypted at rest at specific encryption standards, keeping processes that access such data on different machines, allowing only one way data transfer across specialized hardware, having a physically separate network from the internet, etc.

Just getting a well-known Python package authorized for install on a single machine can take multiple years. People are used to corporations engaging in security theater, but in the DoD world it's much the opposite: the security apparatus is so paranoid and strict that nobody can get anything done.

Re: WhatsApp banned on House staffers' devices

#154
post #82

Earlier quoted context omitted.

> The fact that almost no one on this [thread] knows these Its not that they aren't known, but rather we just came off a long trend of thin-clients and cloud storage. Some companies merely stay in that ethereal space, while others had concerns about their data. Criticizing people for doing what experts were pushing for the past 20 years doesn't need to devolve into calling their expertise into question. The downvotes…

I don't think I understand what you're saying here.

Around 15ish years ago, there was a heavy push for things like parallel computing, hosting things on 'the cloud', and managing "big data". So the overarching recommendation was for devices and data to be accessible through a server. It was cheaper to use a third-party for high end compute and large storage rather than storing locally. Remember this was a time when Dropbox was still quite popular.

My original comment is mostly saying that it is too critical of staff saying "how did they not know" when we're now starting to return to in-house solutions. The prior solution was "Go Cloud", now its "Stay Home". In a decade, once enough people learn the struggles of having everything in-house, the next solution will be "Go Cloud" again, or whatever the future equivalent is.

The overall purpose of my comment was more akin to "calm down, we're just in a new tech cycle, no one's an idiot for following the last cycle's solution".

Re: WhatsApp banned on House staffers' devices

#155

Earlier quoted context omitted.

I don't think I understand what you're saying here.

Around 15ish years ago, there was a heavy push for things like parallel computing, hosting things on 'the cloud', and managing "big data". So the overarching recommendation was for devices and data to be accessible through a server. It was cheaper to use a third-party for high end compute and large storage rather than storing locally. Remember this was a time when Dropbox was still quite popular. My original comment…

I disagree with your statement simply because I myself started my tech career in the midst of the Cloud First hype cycle, and even then principles around data management and limiting access (eg. via RBAC) was already well understood.

Maybe a significant portion of the HN base simply never worked with companies that either sold to or were a part of regulated industries, but I do not buy that.

Furthermore, all of the design patterns I am describing can and have be implemented within cloud environments as well.

Re: WhatsApp banned on House staffers' devices

#156
post #29

Earlier quoted context omitted.

Why would there be a source for a backdoor of a closed source application?

Usually when you make important claims it's expected you back them up with some sort of evidence.

There was a joke in there which might have gone unnoticed.

Re: WhatsApp banned on House staffers' devices

#157

I don't understand why the government can't just fork signal and build up what they need to keep all these government people off "regular" messengers. They are going to do it as long as it's BYOD in the government or they allow individuals to install whatever they like on their phones.

The government is not allowed to build anything, because that would interfere with the rent-seeking of private entities. This is why Digital Services was destroyed by Musk.

Re: WhatsApp banned on House staffers' devices

#159
post #48

Earlier quoted context omitted.

> If "zuck" is really in the pocket of the US government, why should they worry about their own backdoors? Have you ever watched a Saturday morning cartoon? Minions betray their masters all the time. An effective evil overlord doesn’t underestimate their lackey’s capacity for duplicity and betrayal at a pivotal moment. The most fun may even appreciate the gall: https://memory-alpha.fandom.com/wiki/The_Nagus_(episode)…

I have a movie for you: "Broken City" (2013) great cast and constantly unexpected turns of events

Thank you for the recommendation, but definitely not for me. Couldn’t get past the half-way mark.

Re: WhatsApp banned on House staffers' devices

#160

When I was at unnamed major financial institution, we were ordered to stop using WhatsApp, but it had nothing to do with security and everything to do with avoiding even the possibility of the appearance of backroom dealing or production avoidance in the event of subpoena. Maybe the truth has more to do with that, or maybe not, what do I know, who are all you people anyway, and why am I posting here?

That's why they used TeleMessage's modified version, which saves all logs to fulfill transparency requirements. They were also hacked and leaked hundreds of GBs of messages.
Post reply on HN