Live data from Hacker News

WhatsApp banned on House staffers' devices

axios.com

111–120 of 161 posts

Re: WhatsApp banned on House staffers' devices

#111
post #66
post #63

Earlier quoted context omitted.

What implementation of end to end encryption doesn't involve this?

OTR, for IRC/XMPP, PGP for Email and Olm/Megolm provided by Element for Matrix operators. Essentially the software creating the keys is not controlled by the same entity controlling the transmission method. In email/matrix you have an additional protection in that you can host your own server; the best protection is the one you never have the possibility of traffic being diverted, and even if it was it would be encry…

If you think WhatsApp leaves a lot of metadata on the table for analysis, try doing a Matrix chat. You get a plaintext view of which device used which key to send which message ID to which room/person. If the message is a reply, you get the message ID your new message is a reply to in plaintext as well.

Without even looking at things like HTTP headers, this is what the metadata an E2EE-encrypted message (with verified+cross-signed keys) looks like, with specific identifiers censored just in case:

    {
      "type": "m.room.encrypted",
      "sender": "@.......:jeroenhd.nl",
      "content": {
        "algorithm": "m.megolm.v1.aes-sha2",
        "ciphertext": "AwgAEqAC/..........",
        "device_id": "EDNM......",
        "sender_key": "+rKR.......",
        "session_id": "H3Oyob........",
        "m.relates_to": {
          "m.in_reply_to": {
            "event_id": "$5qFg........"
          }
        }
      },
      "origin_server_ts": 17507.......,
      "unsigned": {
        "membership": "join",
        "age": 127,
        "transaction_id": "m17507........."
      },
      "event_id": "$_KBk.......",
      "room_id": "!.........:jeroenhd.nl"
    }
Unlike on platforms like Whatsapp, these message envelopes are available to anyone with access to either a session token or the user's password. The E2EE keys require a bit of extra verification, but you don't need those to build a pretty solid who-talks-to-who-when network even in encrypted chatrooms.

I understand why they implemented some of the metadata this way, but the encryption-stapled-to-unencrypted-messaging approach just leaves a lot to be desired. Signal, on the other hand, leaks pretty much nothing.

Re: WhatsApp banned on House staffers' devices

#112

Earlier quoted context omitted.

If you think end-to-end encryption is the only thing that matters in security, then yeah sure, WhatsApp is more secure. Personally, I'd be embarrassed to let people know I thought that way, but to each their own.

So you would potentially prefer an app without end-to-end encryption to WhatsApp? What are these important security features?

Message retention, audit logging, SSO to name a few off the top of my head.

Re: WhatsApp banned on House staffers' devices

#113
People seem to be missing the point here.

I think it is fair to assume that the US intelligence apparatus has inside knowledge on how comprised or otherwise different platforms are. They are the experts in compromising apps so I'm going to take their word for it.

We learned from Snowden how this is achieved, have people forgotten all of that already?

So to recap, how I assume this is done. A combination of "legal" American routes to gain access to data and embedding agents in the actual organizations to do your technical bidding.

This is speculation but if I were compromising whatsapp I'd leave a bug in there that allowed me to compromise accounts on demand. Something like being able to reduce the randomness of the RNG for a particular account. Then I could just decrypt the messages super easy (cause I already know a range of RNG seeds that work) and it would look to everyone like it was encrypted.

So, who is the chief culprit for doing this, if I was a guessing man (and I am) I would probably say Israel has compromised WhatsApp and the US gov knows it and would like Israel not to know everything that Whitehouse staffers are saying.

Re: WhatsApp banned on House staffers' devices

#114

Serious question: who else takes for granted that Zuck gets a daily summary of all high-level federal governmental communications, as harvested via backdoors or simply from non-end-to-end encrypted traffic on any Meta property? I assume he does. I assume moreover that most people aware of this at Meta consider this due diligence in defending shareholder value. What's that line from Dune 2, a wise hunter climbs the ta…

What would Meta get out of spying on their own government? That's a "life in secret jail" kind of risk for a sickeningly rich CEO with a private island. We haven't even found any evidence of backdoors used against foreign governments, they'd be pretty stupid to attack the American government.

Plus, when it comes to important communications, the weird, hacked, Israeli Signal fork already has access to these documents anyway, even when they don't accidentally add a journalist to the group chat.

If we're talking summaries of government communications, that's more Microsoft territory, who don't even bother adding proprietary E2EE implementations to their chat software.

Re: WhatsApp banned on House staffers' devices

#115

Earlier quoted context omitted.

If you think end-to-end encryption is the only thing that matters in security, then yeah sure, WhatsApp is more secure. Personally, I'd be embarrassed to let people know I thought that way, but to each their own.

So you would potentially prefer an app without end-to-end encryption to WhatsApp? What are these important security features?

Lack of complete e2ee is a feature for many large organizations—they still want everything encrypted, they just want a master key to be able to audit communications for compliance/investigations/insider threat identification. They also want strict control over who does what with the app, and where all of the associated data lives. Teams is just a totally different product from WhatsApp in that regard, with all sorts of functionality that will never exist in WhatsApp—tons of control over user identity and access management, integration with all sorts of other security tooling, etc.

Re: WhatsApp banned on House staffers' devices

#116

Earlier quoted context omitted.

That wasn't signal's fault. They accidentally invited a journalist to the chat.

Yeah, but Signal really didn't help them at all with that. As with most of these phone oriented encrypted messengers, Signal is pretty sloppy with identity management. It would be hard to find a better example of this than SignalGate 1.0. * https://articles.59.ca/doku.php?id=em:sg End to End Encrypted Messaging in the News: An Editorial Usability Case Study (my article)

It wasn't Signal's identity management that proved to be a problem: https://www.theguardian.com/us-news/2025/apr/06/signal-group...

When it comes to practical cryptography, nobody is doing signing parties anyway. It's all TOFU unless someone forces people's hands, and when you force people to do security you can assume they won't bother checking if the QR code they're scanning is coming from a real app or a livestream of someone else's app, they just want to get the scanning done. The whole key scan thing is probably only of any use to people keeping contact after meeting with journalists.

Re: WhatsApp banned on House staffers' devices

#117

When I was at unnamed major financial institution, we were ordered to stop using WhatsApp, but it had nothing to do with security and everything to do with avoiding even the possibility of the appearance of backroom dealing or production avoidance in the event of subpoena. Maybe the truth has more to do with that, or maybe not, what do I know, who are all you people anyway, and why am I posting here?

Makes sense, there are lots of requirements for communication retention in financial institutions. If I recall the phone lines are permanently recorded on trading desks by regulators so if anything does happen they have all the info... it's why socializing in person is such a big part of being a trader.

Re: WhatsApp banned on House staffers' devices

#118
post #12

Government: Zuck put a backdoor in WhatsApp or we will put you in a blacksite UFC ring and beat you up. Also Government: WhatsApp has a backdoor. Don't use it.

Grammar is really needed here cos:

Zuck put a backdoor

And

Zuck, put a backdoor

…are about as different as they could be

Re: WhatsApp banned on House staffers' devices

#119

Earlier quoted context omitted.

If you think end-to-end encryption is the only thing that matters in security, then yeah sure, WhatsApp is more secure. Personally, I'd be embarrassed to let people know I thought that way, but to each their own.

So you would potentially prefer an app without end-to-end encryption to WhatsApp? What are these important security features?

E2EE is mostly useful for consumer applications, where you trust the endpoint (yourself), but not the intermediary servers (some megacorp that doesn't care about you).

The situation is entirely different when you are managing very large organizations.

In those situation, you don't necessarily need the need the data to be invisible to the intermediary servers, because you might either just be able to control them yourself, secure them with NDAs, etc. And if the server is controlled by you, then you might not even want the data to be invisible to yourself. But, your primary risks may be the compromise of endpoint devices, mistakes or leaks by your users, or a lack of controls over data exchange. Also, many organizations may need to provide records of their internal communications in order to comply with legal requirements.

You might be surprised to know that enterprise offerings of many apps that otherwise support E2EE, often have a way for administrators to intentionally turn those features off.

Re: WhatsApp banned on House staffers' devices

#120

This is due to the addition of Meta AI in WhatsApp [0]. Unsurprisingly, data egress to third parties is a major security vector - especially for mission critical jobs like working in the House. MS apps incorporating Copilot have faced similar blocks as well. This requirement for data stewardship is called out in HITPOL8 as well [1][2] (the AI tool standards set by the House CAO). [0] - https://faq.whatsapp.com/203220…

Signal would be the obvious choice here - open source, no AI integration, minimal metadata collection, and recommended by security professionals for sensitive communications.

Signal lacks other compliance features. e.g. message archiving

It might be good if you're a journalist, but it's not as good if you have compliance requirements beyond confidentiality.

Post reply on HN