Hacker News new | ask | show | jobs
by btown 383 days ago
If you need your partners/bankers/salespeople/cabinet-level officials etc. to be able to converse with their clients on the E2E encrypted systems those clients already use, like WhatsApp and Signal, but maintain retention for legal or internal data-mining reasons, the only way to do that is to have a modified client, perhaps cracked or forked from an official client, that speaks the same wire protocol, but copies messages to separate storage.

Now, such a system could be set up to route those copied messages in a separately E2E-encrypted way to the client's in-house/on-prem archival systems, and have the client be responsible for implementing decryption and secure storage at rest. But it's far easier to just sell a centralized cloud-based archival/retrieval system - which must necessarily be able to decrypt messages, and thus makes for an incredibly juicy target.

Given the supply-chain risks of the provider offering the customized clients anyways, one would expect them to have a strong security focus... but it certainly seems this was not the case.

1 comments

> the only way to do that is to have a modified client

My firm requires screenshots. If the concern is that someone would bypass that, well, someone could bypass TeleMessage, too.

One has to wonder what type of legal requirement this satisfies.

It certainly wouldn’t hold up to the “beyond a reasonable doubt” standard for US criminal prosecution.

I’ve been exposed to “lit holds” for various document management system before and usually a third party such as Box or Microsoft can attest to the immutability of files placed under lit hold, and/or there is an audit trail to make sure the chain of custody is intact.

> what type of legal requirement this satisfies

Typically between commercially reasonable and best efforts.

> been exposed to “lit holds” for various document management system before

I think these are held to a higher standard than run-of-the-mill securities compliance.

Why not try a new Document Management system - comes witH AI oCr and Extraction module. Name - DocuSensa AI