top | item 45249595

(no title)

dabeeeenster | 5 months ago

Several years ago the UK government started being defacto run via Whatsapp. I was absolutely furious about this, but seemed to be in a tiny minority of people who cared about it!

Our PM at the time of covid "lost" his Whatsapp backups, and his replacement also had problems getting access to Whatsapp messages. How convenient.

If you worked in a regulated industry this would be instant dismissal. For the UK govt its business as usual.

discuss

order

pasc1878|5 months ago

In practice this is not that much different to what went before except that things happen more quickly.

Before people would go down the pub and have a discussion or in the corridor.

Things were never all discussed through official channels.

Now actually is probably more transparent as some of the WhatsApp messages are leaked and people can't deny them.

dijit|5 months ago

I'm certain that people will take an emotional reaction to what you've written, but I just want to be the first to say that I think you're right.

"Whatsapp" is the new "talking to the person in the corridor" or "having a quick chat down the pub", it's not the new email, and having them leak is ironically the most accountability we've seen.

I'll use an example of someone I support generally now: Tony Blair was accused of having backroom discussions regarding the invasion of Iraq and secret meetings away from even his cabinet[0]. Since we only have hearsay of what went on, it's very difficult to hold him accountable for this.

[0]: https://www.bbc.com/news/uk-politics-12306377

dathinab|5 months ago

Technically speaking WhatsApp is roughly second place on secure messaging behind Signal.

So while there are massive issues wrt. compliance and giving a US company control over all of this from a purely security choice they could have done way worse and still f*up compliance.

amiga386|5 months ago

In the US, it's Signal. In the UK, it was WhatsApp.

When researchers dumped 100% of Signal's users in the USA, because its contact discovery API has no rate limiting, they found a huge portion of Signal's US userbase has Washington D.C. area codes.

"Signal; Washington D.C. numbers are more than twice as likely to be registered with Signal than for any other area in the US" https://encrypto.de/papers/HWSDS21.pdf

Meanwhile, in Scotland since the pandemic, Nicola Sturgeon ran her government with an entirely parallel communication network on WhatsApp, explicitly to prevent her government's discussions and decisions from being discoverable by FoI requests.

There was daily deletion of messages. It was drummed into people by Sturgeon's head civil servant, Ken "Plausible Deniability" Thompson: https://archive.is/jK6Bd

> Thomson was head of the Covid co-ordination directorate of the Scottish government and wrote: “Just to remind you (seriously), this is discoverable under FOI [freedom of information]. Know where the “clear chat” button is…”. He later added: “Plausible deniability are my middle names. Now clear it again!”

Sturgeon, just like Boris Johnson, retained zero WhatsApp messages: https://www.bbc.co.uk/news/live/uk-scotland-67949454

Scotland only banned use of WhatsApp in government 4 months ago: https://www.bbc.co.uk/news/articles/c4g8pe585z1o

dabeeeenster|5 months ago

I don't really mind someone foreign having access to what is being said, as much as I mind public servants not being able to be held accountable because all of the discussions are encrypted.

alistairSH|5 months ago

The compliance (audibility, recovery, etc) is the big problem, IMO, not the security.

pxoe|5 months ago

It may seem like it's "convenient", but whatsapp is truly a nightmare when you try to move it literally anywhere in any way. Huge backups, needing to transfer phone numbers, having to restore from backups, having and moving those backups in the first place, the way it's designed in that regard is the most inconvenient for a platform that doesn't even necessarily provide more security or anything for that to be worth it at all, particularly for people who don't even seek that kind of security or even know about it and just use it for "texting and stuff". Not to defend that or say that it isn't just a convenient excuse (it can be for sure), but just to say that whatsapp is possibly the most annoying app in that regard. It's such a pain in the ass I'd rather store all of that in the cloud. (Which ironically whatsapp pretty much just does anyway if it backs up to google drive, it just makes it the most inconvenient it could be)

jaapz|5 months ago

Is it that hard? Every time I moved to a new phone, whatsapp's backups are in my google drive and restored without any problem whatsoever

clort|5 months ago

The short term problem is, that the government are responsible for sacking themselves in the short term - and those clowns just refused to, which is not the case for the current government who are replacements for the clowns who the electorate firmly sacked at their first opportunity.

So re your comment: 'For the UK govt its business as usual', not really.

You do not have to like the government of the day, but don't fall into the trap of believing that they are all the same.

JTbane|5 months ago

Trump admin did the same thing with Signal. I'm pretty sure they did it because US gov't emails and IMs are for sure archived.

ncruces|5 months ago

Politicians around the world do it on purpose because they know they can more easily get away with leaving no trace.

It's not an accident they don't use government email/IM and use WhatsApp/Signal instead.

But then they turn around and want to convince us it's bad when we use it. Because they're the ones handling “acceptable” secrets, somehow.

dmix|5 months ago

The US gov started using Signal before Trump and they were backing up Signal chat logs (which it seems the UK wasn't doing with WhatsApp?). It was just controversial which vendor the prior US gov had chosen to handle the backups (an Israeli tech firm) and how it was used by the executive branch. But they were ultimately following transparency/archiving rules.

_heimdall|5 months ago

I never saw any reporting after those Signal chat stories came out. At the time it was reported that they had a period of time to make sure conversation were archived properly. It would be interesting to know if that actually happened.