12 ms·
WhatsApp banned on House staffers' devices
- sandworm101 1y agoGood. Another point to be made when my friends push me to install bloated spyware just to plan a pizza party. Use Signal.
- SketchySeaBeast 1y ago[flagged]
- deleted 1y ago[deleted]
- sandworm101 1y agoWell, if you just cannot be botherer to drive to the scif, and if you are best buds with the man in charge, do whatever least impacts your workout schedule.
- FuriouslyAdrift 1y agoWhat, you don't bring your SCIF wherever you go? https://www.theemcshop.com/benchtop-faraday-tents/select-fabricators-series-500-484878-mobile-tent/ https://www.theemcshop.com/benchtop-faraday-tents/select-fab...
- game_the0ry 1y agoThat wasn't signal's fault. They accidentally invited a journalist to the chat.
- iAMkenough 1y agoThe federal government uses a third-party Signal client that saves their conversations in clear text to a database, which has been breached before. Clearly user error, not Signal's fault.
- ben_w 1y agoWhile it is correct that this was a PEBKAC error rather than Signal's error, I would like to suggest that, in general, all mobile phone apps are poor choices for anything as sensitive as planning a missile strike.
- Zak 1y agoI think one could design a procedure involving a mobile phone and Signal that would be reasonably secure for that kind of use case. The number one point on that procedure would be that the phone in question isn't used for anything other than secure communication. Of course, the US government already has approved procedures and devices for secure communication, so senior official making up their own is reckless and unprofessional.
- game_the0ry 1y agoI wouldn't disagree with you, here.
- snickerbockers 1y agoI agree in principle but this was (probably) a result of somebody fat-fingering the wrong contact and I do think there's some culpability on either the app or the phone for making that possible to do by mistake. Touch screens are an inherently clumsy interface, and Android in general has a lot of problems with UI elements suddenly moving around without warning as you're clicking on things. And then there's auto correct, UI hanging for several seconds at a time only to suddenly wake up and replay everything that you tried to do while it was non responsive, phantom button presses caused by the device getting too warm, etc. None of this is meant to excuse these officials for not authenticating everybody in that group or for using highly informal text messages to plan an airstrike of all things. Ultimately there's no excuse for leaking information when you're at that level of government; I just feel like the app industry needs to take responsibility and fix several obvious, well-known and common UI issues.
- mapmeld 1y agoI thought the latest on this was that the journalist's number was in an internal email from spokesman Brian Hughes, and software or human error led to his phone number being associated with Hughes in Waltz's phone contact
- upofadown 1y ago>but this was (probably) a result of somebody fat-fingering the wrong contact... Supposedly, it was the result of a helpful Apple feature getting the wrong phone number for one of the intended group participants. Then Signal cheerfully used that wrong phone number to add the reporter to the group. * https://www.theguardian.com/us-news/2025/apr/06/signal-group-chat-leak-how-it-happened https://www.theguardian.com/us-news/2025/apr/06/signal-group...
- bee_rider 1y agoI don’t think there’s any culpability or responsibility for the app, it doesn’t really bill itself as a good platform to do the high-level planning of military strikes. If there are UI issues, they should be fixed because they are also annoying when planning somebody a surprise birthday party. (Or all the other stuff an encrypted chat app might be good for). On the other hand, PGP just calling itself “pretty good” was pretty funny. Maybe that’s the level of active humbleness that everybody should aim for.
- upofadown 1y agoYeah, but Signal really didn't help them at all with that. As with most of these phone oriented encrypted messengers, Signal is pretty sloppy with identity management. It would be hard to find a better example of this than SignalGate 1.0. * https://articles.59.ca/doku.php?id=em:sg https://articles.59.ca/doku.php?id=em:sg End to End Encrypted Messaging in the News: An Editorial Usability Case Study (my article)
- jeroenhd 1y agoIt wasn't Signal's identity management that proved to be a problem: https://www.theguardian.com/us-news/2025/apr/06/signal-group-chat-leak-how-it-happened https://www.theguardian.com/us-news/2025/apr/06/signal-group... When it comes to practical cryptography, nobody is doing signing parties anyway. It's all TOFU unless someone forces people's hands, and when you force people to do security you can assume they won't bother checking if the QR code they're scanning is coming from a real app or a livestream of someone else's app, they just want to get the scanning done. The whole key scan thing is probably only of any use to people keeping contact after meeting with journalists.
- upofadown 1y agoIf you blame the incorrect phone number in the Apple address book then sure, but that implies that you think that a smart phone address book should be responsible for identity management in an end to end encrypted messenger. Oh, and the telephone number to identity mapping is the responsibility of: * Signal * Twillo * The phone company That's all OK as far as it goes, but the root problem here is that a typical Signal user is made aware of none of this. Sure it's legit to take convenience over security, but it is not OK to leave this tradeoff completely unknown to the people affected.
- snickerbockers 1y agoHe did say last year he was going to make this the most open and transparent administration in US history. What other administration would grant a hostile journalist an inside look at the planning and execution of an airstrike? Promises made, promises kept.
- femiagbabiaka 1y ago"hostile"
- snickerbockers 1y agoThe article itself commented on how ironic it is that of all the journalists they could have invited to the chat, it was one who has been highly critical of the president and not some sycophant who might have kept it a secret or turned it into a puff piece like what I just did except without the sarcasm.
- deleted 1y ago[deleted]
- janice1999 1y ago[flagged]
- mikehotel 1y agoSee https://archive.ph/oXYXe https://archive.ph/oXYXe for more info about TeleMessage version of Signal approved for use by government offices.
- unethical_ban 1y agoAre "paid for" and "properly approved for classified information" being conflated here? I may have missed something.
- duxup 1y agoAlso don't willfully send that info to your wife, lawyer ... friends ... for fun.
- seethishat 1y agoOr just call, email or txt. Signal is only as secure as the device it runs on. Cell Phones are not secure. They are blackboxes and probably track you and may have built-in backdoors (only to be used to catch 'real' criminals), etc. The idea that you can turn a device like that into some form of secure communication platform by installing an app is not realistic.
- Tijdreiziger 1y agoYeah, but the location of your next pizza party probably isn’t a state secret either.
- ceejayoz 1y agoIt is if the party's in the Situation Room at 3am. https://www.fastcompany.com/91352935/pentagon-pizza-index-the-theory-that-surging-pizza-orders-signal-global-crises https://www.fastcompany.com/91352935/pentagon-pizza-index-th...
- deleted 1y ago[deleted]
- mailund 1y agoUnless you are the secretary of defence, in which case you probably shouldn't use signal
- alephnerd 1y agoThis is due to the addition of Meta AI in WhatsApp [0]. Unsurprisingly, data egress to third parties is a major security vector - especially for mission critical jobs like working in the House. MS apps incorporating Copilot have faced similar blocks as well. This requirement for data stewardship is called out in HITPOL8 as well [1][2] (the AI tool standards set by the House CAO). [0] - https://faq.whatsapp.com/203220822537614/?cms_platform=iphone https://faq.whatsapp.com/203220822537614/?cms_platform=iphon... [1] - https://cha.house.gov/_cache/files/4/2/42dca19e-194b-481e-b11b-67153a8ab821/A0DC312390F4983FB50A73CB71E3E346.cha-modernization-ai-flash-report-12-20-24-v3.0.pdf https://cha.house.gov/_cache/files/4/2/42dca19e-194b-481e-b1... [2] - https://cha.house.gov/_cache/files/0/8/08476380-95c3-4989-ad4c-1e2a454b0007/9668ADB6A0D503B944E26EDB81EDC585.cha-modernization-ai-flash-report-10-25-24.pdf https://cha.house.gov/_cache/files/0/8/08476380-95c3-4989-ad...
- esafak 1y agoSource for reason?
- alephnerd 1y agoThe article as well as HITPOL8 [0][1]. WhatsApp has been blocked for the same reason Deepseek AI (the Deepseek app) is blocked - "Stewardship of Legislative Branch Data". [0] - https://cha.house.gov/_cache/files/4/2/42dca19e-194b-481e-b11b-67153a8ab821/A0DC312390F4983FB50A73CB71E3E346.cha-modernization-ai-flash-report-12-20-24-v3.0.pdf https://cha.house.gov/_cache/files/4/2/42dca19e-194b-481e-b1... [1] - https://cha.house.gov/_cache/files/0/8/08476380-95c3-4989-ad4c-1e2a454b0007/9668ADB6A0D503B944E26EDB81EDC585.cha-modernization-ai-flash-report-10-25-24.pdf https://cha.house.gov/_cache/files/0/8/08476380-95c3-4989-ad...
- ethan_smith 1y agoSignal would be the obvious choice here - open source, no AI integration, minimal metadata collection, and recommended by security professionals for sensitive communications.
- 1y ago
- v5v3 1y agoGovernment: Zuck put a backdoor in WhatsApp or we will put you in a blacksite UFC ring and beat you up. Also Government: WhatsApp has a backdoor. Don't use it.
- kotaKat 1y agoWhatsApp on TV: “Trust us! It’s encrypted :) :) :)”
- scoot 1y agoAnd on social media. Maybe I'm being too literal and pedantic, but it bugs me that they say "nobody" can read your messages. What's the point of using it if even the recipient can't read them (or the sender for that matter!).
- gruez 1y ago>Government: Zuck put a backdoor in WhatsApp or we will put you in a blacksite UFC ring and beat you up. Source? >Also Government: WhatsApp has a backdoor. Don't use it. If "zuck" is really in the pocket of the US government, why should they worry about their own backdoors?
- kurthr 1y agoOnce it's backdoored you don't know who's watching it. It's the most hilarious thing about backdoors or collecting extensive covert intel on your own population, that any failure of opsec makes it much easier for all your adversaries to also spy on them in ways they would never otherwise be able to, then compromise them, and flip them.
- baxtr 1y ago>Andy Stone, a spokesperson for WhatsApp parent company Meta, said in a statement to Axios, "We disagree with the House Chief Administrative Officer's characterization in the strongest possible terms." (..) "Messages on WhatsApp are end-to-end encrypted by default, meaning only the recipients and not even WhatsApp can see them. This is a higher level of security than most of the apps on the CAO's approved list that do not offer that protection."
- theodric 1y agoWhen I was at unnamed major financial institution, we were ordered to stop using WhatsApp, but it had nothing to do with security and everything to do with avoiding even the possibility of the appearance of backroom dealing or production avoidance in the event of subpoena. Maybe the truth has more to do with that, or maybe not, what do I know, who are all you people anyway, and why am I posting here?
- Marsymars 1y agoWhatsApp also feels... tonally weird to use at a serious company, like in the same way it would feel weird to be using snapchat for team meetings.
- LgLasagnaModel 1y agoTotally agree. Now let me go play with this model I got off of Hugging Face
- oceansky 1y agoWhatsApp is already the de facto communication channel in a lot of countries. In Brazil even subpoenas can be sent via WhatsApp.
- BeetleB 1y agoHeh. I have a friend here in the US. His father passed away in his home country. No will. The whole family needed to show up in court for probate, but he could not travel at that time. The court: "No problem, just join the session on video using WhatsApp"
- oceansky 1y agoReally? Remote court sessions are usually on Google Meet or Zoom
- lcnPylGDnU4H9OF 1y ago
- axus 1y ago> "We know members and their staffs regularly use WhatsApp and we look forward to ensuring members of the House can join their Senate counterparts in doing so officially," Stone said. Go on...
- jandrewrogers 1y ago> "Messages on WhatsApp are end-to-end encrypted by default, meaning only the recipients and not even WhatsApp can see them." The handling and metadata around encrypted messages is nearly as exploitable as the actual message contents. End-to-end encryption is necessary but not sufficient. The infrastructure has to be designed to minimize risk of other forms of exploitive analysis as well but in the case of WhatsApp that is essentially their business model.
- dijit 1y agoIf the network controls the endpoints; then E2EE is meaningless.
- benced 1y agoWhat implementation of end to end encryption doesn't involve this?
- dijit 1y agoOTR, for IRC/XMPP, PGP for Email and Olm/Megolm provided by Element for Matrix operators. Essentially the software creating the keys is not controlled by the same entity controlling the transmission method. In email/matrix you have an additional protection in that you can host your own server; the best protection is the one you never have the possibility of traffic being diverted, and even if it was it would be encrypted so that the server doesn’t leak anyway, security is like an onion after all.
- jeroenhd 1y agoIf you think WhatsApp leaves a lot of metadata on the table for analysis, try doing a Matrix chat. You get a plaintext view of which device used which key to send which message ID to which room/person. If the message is a reply, you get the message ID your new message is a reply to in plaintext as well. Without even looking at things like HTTP headers, this is what the metadata an E2EE-encrypted message (with verified+cross-signed keys) looks like, with specific identifiers censored just in case: { "type": "m.room.encrypted", "sender": "@.......:jeroenhd.nl", "content": { "algorithm": "m.megolm.v1.aes-sha2", "ciphertext": "AwgAEqAC/..........", "device_id": "EDNM......", "sender_key": "+rKR.......", "session_id": "H3Oyob........", "m.relates_to": { "m.in_reply_to": { "event_id": "$5qFg........" } } }, "origin_server_ts": 17507......., "unsigned": { "membership": "join", "age": 127, "transaction_id": "m17507........." }, "event_id": "$_KBk.......", "room_id": "!.........:jeroenhd.nl" } Unlike on platforms like Whatsapp, these message envelopes are available to anyone with access to either a session token or the user's password. The E2EE keys require a bit of extra verification, but you don't need those to build a pretty solid who-talks-to-who-when network even in encrypted chatrooms. I understand why they implemented some of the metadata this way, but the encryption-stapled-to-unencrypted-messaging approach just leaves a lot to be desired. Signal, on the other hand, leaks pretty much nothing.
- aaroninsf 1y agoSerious question: who else takes for granted that Zuck gets a daily summary of all high-level federal governmental communications, as harvested via backdoors or simply from non-end-to-end encrypted traffic on any Meta property? I assume he does. I assume moreover that most people aware of this at Meta consider this due diligence in defending shareholder value. What's that line from Dune 2, a wise hunter climbs the tallest hill? _You need to see._
- preachermon 1y agoOfficial press release, https://www.army.mil/article/286317/army_launches_detachment_201_executive_innovation_corps_to_drive_tech_transformation https://www.army.mil/article/286317/army_launches_detachment... he U.S. Army is establishing Detachment 201: The Army’s Executive Innovation Corps, a new initiative designed to fuse cutting-edge tech expertise with military innovation. On June 13, 2025, the Army will officially swear in four tech leaders. Det. 201 is an effort to recruit senior tech executives to serve part-time in the Army Reserve as senior advisors. In this role they will work on targeted projects to help guide rapid and scalable tech solutions to complex problems. By bringing private-sector know-how into uniform, Det. 201 is supercharging efforts like the Army Transformation Initiative, which aims to make the force leaner, smarter, and more lethal. The four new Army Reserve Lt. Cols. are Shyam Sankar, Chief Technology Officer for Palantir; Andrew Bosworth, Chief Technology Officer of Meta; Kevin Weil, Chief Product Officer of OpenAI; and Bob McGrew, advisor at Thinking Machines Lab and former Chief Research Officer for OpenAI. So yes, Meta's CTO is now a high ranking army officer
- jeroenhd 1y agoWhat would Meta get out of spying on their own government? That's a "life in secret jail" kind of risk for a sickeningly rich CEO with a private island. We haven't even found any evidence of backdoors used against foreign governments, they'd be pretty stupid to attack the American government. Plus, when it comes to important communications, the weird, hacked, Israeli Signal fork already has access to these documents anyway, even when they don't accidentally add a journalist to the group chat. If we're talking summaries of government communications, that's more Microsoft territory, who don't even bother adding proprietary E2EE implementations to their chat software.
- deadbabe 1y agoMaybe they should use Meshtastic
- benced 1y ago[flagged]
- GuB-42 1y agoIt doesn't mean that MS Teams is safer, it means that the government has tighter control on MS Teams. Or maybe that Microsoft pays more than Meta.
- alephnerd 1y agoMS products allow you to store data locally without any egress, so an IT team has access to it. This is the sticking point, because WhatsApp has now integrated Meta AI into the app, but (obviously) do not provide an on-prem data store. This is why Deepseek AI (the Deepseek app) and ChatGPT (the OpenAI app) are barred as well. Data Stewardship and Zero Trust has been an internal initiative in the House for a couple years now. The fact that almost no one on this thead knows these (imo overused) terms and design patterns highlights one of the various major gaps in Software Dev I've been observing for several years now - especially the North American market (given the hours that this was posted). The inability to incorporate or understand some basic security architectures is a major gap. Edit: Keep pushing the downvotes. The truth hurts, and plays a role in jobs leaving, and funds like my employer funding cybersecurity startups in Israel, India, and Eastern Europe because the ecosystem doesn't exist in the US anymore. A similar trend happened in data layer related work. We don't need more SKLearn plumbers calling themselves "ML Engineers" or Angular monkeys calling themselves "Fullstack Engineers" - we need people who truly understand fundamentals (or - shudders - first principles), be they mathematical (optimization), systems (virtualization), or algorithms (efficient data structures)
- josefritzishere 1y agoThis seems sensible.
- williamscales 1y agoI mean, regardless of any argument about Whatsapp, shouldn't installing any app on a government phone that's not allowed be impossible? Sheesh. This shouldn't even be a discussion in the first place.
- duxup 1y agoI can't imagine any justification for any government device that should be secure to have anything on it but the bare minimum software and the device in whatever hardened mode it has. If they visit the White House, government facility ... should go in a locker. I worked for a company that sent people onsite to government contractors. One contractor we rarely visited was at a facility where you arrived at the front gate in your rental car with your ID, keys, and equipment you needed. You were told if you brought anything else expect to lose it. They took your ID and keys at the gate, searched the car, you were blindfoled and they escorted you to the location of the equipment. If you had to go to the bathroom your were escorted (all the way...). You left with the clothes on your back. We went through a lot of laptops, but ... that place was secure.
- deleted 1y ago[deleted]
- scrubs 1y agoThank goodness somebody takes security seriously. The cynic in me (opposed in strongest terms by the realist and give-a-damn in me) says: Whitehouse? Go for it. You'll probably leave more stupid (confused) than you went in.
- duxup 1y agoIn this case it was a military facility and contractor so security is kinda built in to the system to some extent. Security involving politicians / civilian workers ... much harder I imagine.
- pjc50 1y agoThe 24/7 usage of Twitter, Truth Social, and random Signal group chats by the White House should give you some idea how seriously security is taken there.
- fennecbutt 1y agoAre they allowed to have X installed on them though? ;) Man, politics and finance are a trainwreck enabled by apathetic voters who think democracy is about picking a sports team.
- reillyse 1y agoPeople seem to be missing the point here. I think it is fair to assume that the US intelligence apparatus has inside knowledge on how comprised or otherwise different platforms are. They are the experts in compromising apps so I'm going to take their word for it. We learned from Snowden how this is achieved, have people forgotten all of that already? So to recap, how I assume this is done. A combination of "legal" American routes to gain access to data and embedding agents in the actual organizations to do your technical bidding. This is speculation but if I were compromising whatsapp I'd leave a bug in there that allowed me to compromise accounts on demand. Something like being able to reduce the randomness of the RNG for a particular account. Then I could just decrypt the messages super easy (cause I already know a range of RNG seeds that work) and it would look to everyone like it was encrypted. So, who is the chief culprit for doing this, if I was a guessing man (and I am) I would probably say Israel has compromised WhatsApp and the US gov knows it and would like Israel not to know everything that Whitehouse staffers are saying.
- rendall 1y agoThis is illuminating: > "high-risk to users due to the lack of transparency in how it protects user data..." > "We disagree with the House Chief Administrative Officer's characterization in the strongest possible terms." It seems like this is non-responsive to the first claim. Meta goes on to say that WhatsApp is end-to-end encrypted, but the quotes never really do address the transparency issue.
- Huxley1 1y agoThis makes sense from a security perspective, but I’m curious how much it will affect the workflow and communication efficiency for House staff. WhatsApp is convenient and widely used, so switching to more controlled tools like Microsoft Teams might slow things down and make communication less smooth.
- EasyMark 1y agoI don't understand why the government can't just fork signal and build up what they need to keep all these government people off "regular" messengers. They are going to do it as long as it's BYOD in the government or they allow individuals to install whatever they like on their phones.
- feoren 1y agoThe government is not allowed to build anything, because that would interfere with the rent-seeking of private entities. This is why Digital Services was destroyed by Musk.