Charges Against Treasury Employee Show Weakness of Encrypted Apps

Charges Against Treasury Employee Show Weakness of Encrypted Apps

Encryption apps are only as secure as you make them.

Last week, the government unveils criminal charges against a Treasury Department employee accused of leaking confidential banking reports involving key figures in the special counsel's prove of Russian electron interference. The findings are a reminder that encrypted apps used by millions around the world may provide a false sense of security for people who do not use them correctly or take other security precautions.

Prosecutors say Natalie Mayflower Sours Edwards, a senior official at the department's financial crimes unit, sent photos of the documents through an encrypted app to a reporter, who used them as the basis for a dozen stories related to the probe, according to the Washington Post. 

Normally, it would have been extremely difficult for investigators to have intercepted the messages because of the high level of security encrypted messaging apps provide, but prosecutors say they found hundreds of the messages Edwards stored on her cellphone when they searched the device last week.

The messages are said to have included communications in which Edwards "transmitted or described" the banking documents to the reporter.

The case is a high-profile reminder that users need to take extra steps — beyond just downloading an app — to receive the full benefits of an encrypted service. In other words, if you are backing up your decrypted messages onto your device, you are no longer protected by the app.

The potential false sense of security is an especially important warning sign for reporters and their sources, who have turned increasingly to encrypted apps for confidential communication. 

Cybersecurity reported Kim Zetter tweeted, "This should be an instruction for both reporters and their sources — encrypted messages are UNENCRYPTED on receiving/sending devices. If authorities obtain the device, the encryption is no good."

About the Author

Sydny Shepard is the Executive Editor of Campus Security & Life Safety.

Featured

New Products

  • Compact IP Video Intercom

    Viking’s X-205 Series of intercoms provide HD IP video and two-way voice communication - all wrapped up in an attractive compact chassis.

  • Camden CM-221 Series Switches

    Camden CM-221 Series Switches

    Camden Door Controls is pleased to announce that, in response to soaring customer demand, it has expanded its range of ValueWave™ no-touch switches to include a narrow (slimline) version with manual override. This override button is designed to provide additional assurance that the request to exit switch will open a door, even if the no-touch sensor fails to operate. This new slimline switch also features a heavy gauge stainless steel faceplate, a red/green illuminated light ring, and is IP65 rated, making it ideal for indoor or outdoor use as part of an automatic door or access control system. ValueWave™ no-touch switches are designed for easy installation and trouble-free service in high traffic applications. In addition to this narrow version, the CM-221 & CM-222 Series switches are available in a range of other models with single and double gang heavy-gauge stainless steel faceplates and include illuminated light rings.

  • Luma x20

    Luma x20

    Snap One has announced its popular Luma x20 family of surveillance products now offers even greater security and privacy for home and business owners across the globe by giving them full control over integrators’ system access to view live and recorded video. According to Snap One Product Manager Derek Webb, the new “customer handoff” feature provides enhanced user control after initial installation, allowing the owners to have total privacy while also making it easy to reinstate integrator access when maintenance or assistance is required. This new feature is now available to all Luma x20 users globally. “The Luma x20 family of surveillance solutions provides excellent image and audio capture, and with the new customer handoff feature, it now offers absolute privacy for camera feeds and recordings,” Webb said. “With notifications and integrator access controlled through the powerful OvrC remote system management platform, it’s easy for integrators to give their clients full control of their footage and then to get temporary access from the client for any troubleshooting needs.”