Live data from Hacker News

WhatsApp banned on House staffers' devices

axios.com

141–150 of 161 posts

Re: WhatsApp banned on House staffers' devices

#141

When I was at unnamed major financial institution, we were ordered to stop using WhatsApp, but it had nothing to do with security and everything to do with avoiding even the possibility of the appearance of backroom dealing or production avoidance in the event of subpoena. Maybe the truth has more to do with that, or maybe not, what do I know, who are all you people anyway, and why am I posting here?

WhatsApp also feels... tonally weird to use at a serious company, like in the same way it would feel weird to be using snapchat for team meetings.

Right? If you use snap chat for meetings emojis, "dude", "bro", "like then he said, and i was like..." etc would be the communication denominator. It'd be fun, silly, and stupid

Re: WhatsApp banned on House staffers' devices

#142
This makes sense from a security perspective, but I’m curious how much it will affect the workflow and communication efficiency for House staff. WhatsApp is convenient and widely used, so switching to more controlled tools like Microsoft Teams might slow things down and make communication less smooth.

Re: WhatsApp banned on House staffers' devices

#144
post #123

Earlier quoted context omitted.

Their statement doesn't sound like what you said at all: > The Office of Cybersecurity has deemed WhatsApp a high-risk to users due to the lack of transparency in how it protects user data, absence of stored data encryption, and potential security risks involved with its use (Of course that statement seems to be highly confused overall. What "stored data encryption"?)

Does WhatsApp encrypt the data on the device after it’s received and decrypted at your phone’s end (then stored indefinitely)? I thought the term of art was “encrypted at rest,” but “stored data encryption” makes sense to me too. I was of the impression that Whatsapp’s messages (and its backups, photos, etc) kind of just hung around in plaintext once they reached the device. Which would seem to be a problem should th…

> Does WhatsApp encrypt the data on the device after it’s received and decrypted at your phone’s end (then stored indefinitely)?

The operating system (Android/iOS) encrypts everything anyway. Why would you double that? More to the point, do any of the other "safe" apps, like iMessage, do that?

Re: WhatsApp banned on House staffers' devices

#145

When I was at unnamed major financial institution, we were ordered to stop using WhatsApp, but it had nothing to do with security and everything to do with avoiding even the possibility of the appearance of backroom dealing or production avoidance in the event of subpoena. Maybe the truth has more to do with that, or maybe not, what do I know, who are all you people anyway, and why am I posting here?

i heard (anecdotally) that wall street used to run on Yahoo IM - fascinating. do you know if that extended into your previous employer?

Not while I was there, anyway. The corporate image was so locked down that only named binaries would run, and Internet access was heavily filtered and MITM'd for inspection/retention. We didn't even have a shitposting channel. All the juicy stuff happened over the phone, because most people weren't recorded apart from traders and those adjacent to them (and you'd know if they were recorded because of the IVR announcement preceding their join).

Re: WhatsApp banned on House staffers' devices

#146

When I was at unnamed major financial institution, we were ordered to stop using WhatsApp, but it had nothing to do with security and everything to do with avoiding even the possibility of the appearance of backroom dealing or production avoidance in the event of subpoena. Maybe the truth has more to do with that, or maybe not, what do I know, who are all you people anyway, and why am I posting here?

WhatsApp also feels... tonally weird to use at a serious company, like in the same way it would feel weird to be using snapchat for team meetings.

The UK conservative government ran a lot of meetings on whatsapp because they believed it was secure and unarchived, i.e. could escape the normal retention requirements. Of course what happened is that once the chat got large enough and the government fractious enough, people started leaking messages by screenshot.

When trying to avoid subpoenas of data on the device itself, it's important to frequently "lose" the phone with the messages on.

Re: WhatsApp banned on House staffers' devices

#147
post #92

I can't imagine any justification for any government device that should be secure to have anything on it but the bare minimum software and the device in whatever hardened mode it has. If they visit the White House, government facility ... should go in a locker. I worked for a company that sent people onsite to government contractors. One contractor we rarely visited was at a facility where you arrived at the front ga…

The 24/7 usage of Twitter, Truth Social, and random Signal group chats by the White House should give you some idea how seriously security is taken there.

Re: WhatsApp banned on House staffers' devices

#148
post #66
post #63

Earlier quoted context omitted.

What implementation of end to end encryption doesn't involve this?

OTR, for IRC/XMPP, PGP for Email and Olm/Megolm provided by Element for Matrix operators. Essentially the software creating the keys is not controlled by the same entity controlling the transmission method. In email/matrix you have an additional protection in that you can host your own server; the best protection is the one you never have the possibility of traffic being diverted, and even if it was it would be encry…

Irony over irony I think you can include Telegram here:

- yes not end-to-end encrypted by default

- but I haven't seen any complaints about their end-to-end encryption, except that it isn't enabled by default

- and unlike WhatsApp they publish reproducible builds so we can know the endpoints do what the source code says

Re: WhatsApp banned on House staffers' devices

#149

Earlier quoted context omitted.

Signal lacks other compliance features. e.g. message archiving It might be good if you're a journalist, but it's not as good if you have compliance requirements beyond confidentiality.

Wouldn't this be pretty easy to roll your own? You could set up different servers like Molly does. Or you could just recompile the app. Or you could force link it to a desktop session? Just spitballing here

There are already forks that add some of those features.

Re: WhatsApp banned on House staffers' devices

#150
I don't understand why the government can't just fork signal and build up what they need to keep all these government people off "regular" messengers. They are going to do it as long as it's BYOD in the government or they allow individuals to install whatever they like on their phones.
Post reply on HN