惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

T
Tenable Blog
K
KPMG report finds enterprise disconnect between AI and its ROI | CIO
V
Vulnerabilities – Threatpost
G
GRAHAM CLULEY
Simon Willison's Weblog
Simon Willison's Weblog
C
CXSECURITY Database RSS Feed - CXSecurity.com
P
Privacy International News Feed
H
Heimdal Security Blog
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
S
Secure Thoughts
MyScale Blog
MyScale Blog
C
Cyber Attacks, Cyber Crime and Cyber Security
V
Visual Studio Blog
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
L
LINUX DO - 最新话题
D
Darknet – Hacking Tools, Hacker News & Cyber Security
The Cloudflare Blog
美团技术团队
Recorded Future
Recorded Future
T
Tailwind CSS Blog
Latest news
Latest news
Security Archives - TechRepublic
Security Archives - TechRepublic
Security Latest
Security Latest
Know Your Adversary
Know Your Adversary
Cloudbric
Cloudbric
Schneier on Security
Schneier on Security
I
Intezer
L
LINUX DO - 热门话题
P
Palo Alto Networks Blog
云风的 BLOG
云风的 BLOG
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
Vercel News
Vercel News
Attack and Defense Labs
Attack and Defense Labs
人人都是产品经理
人人都是产品经理
L
LangChain Blog
爱范儿
爱范儿
博客园 - 三生石上(FineUI控件)
博客园 - 叶小钗
L
Lohrmann on Cybersecurity
S
SegmentFault 最新的问题
W
WeLiveSecurity
C
Cybersecurity and Infrastructure Security Agency CISA
S
Securelist
SecWiki News
SecWiki News
V2EX - 技术
V2EX - 技术
IT之家
IT之家
Cyberwarzone
Cyberwarzone
F
Full Disclosure
Spread Privacy
Spread Privacy
阮一峰的网络日志
阮一峰的网络日志

Element Blog

Organise your chats your way with Sections We’re interoperable, so you can be sovereign Matrix-based ZaPuK confirmed as a core component within Germany’s Deutschland-Stack Element recognised as a Digital Public Good CompuGroup Medical (CGM) and Element partner to transform healthcare communications Sweden goes live with Matrix-based federation! Air-gapped communications for national security Seamless encrypted history sharing arrives in Element Digital sovereignty is built on an open standard that enables federation Introducing the ESS Community migration tool Spaces has landed on Element X! Meedio partners with Element to deliver sovereign communications across Europe Governments need to adopt Matrix responsibly The Cyber Resilience Act: Implications for open source and digital products Sustainable decentralised comms at Element Exploring MatrixRTC: Real time communication in rooms The Digital Omnibus: opportunities and risks for open source Element’s multi-tenancy TI-Messenger solution secures ‘Good’ rating in gematik commissioned pentest Open source is key to Europe’s digital sovereignty
Latest Signal and WhatsApp breaches show that consumer apps have no place in government
Steve Loynes · 2026-03-11 · via Element Blog

On Monday the General Dutch ⁠Intelligence Agency (AIVD) and Dutch Military Intelligence and Security Service (MIVD) announced a sustained Russian-backed campaign targeting Signal and WhatsApp users. 

It follows a similar warning in February, from Germany’s Domestic Intelligence Agency (BfV) and Federal Cybersecurity Office (BSI).

The attacks are based on relatively straightforward social engineering. Signal or WhatsApp users are targeted by fake Support Chatbots and then duped into divulging PIN codes or adding the attacker to conversations through ‘link device’ functions. Much like email phishing, it’s straightforward but effective; the Dutch agencies have acknowledged that the attackers are likely to have gained access to sensitive information.

The attacks are yet another example of why consumer messaging apps are not appropriate for use within governments. Intelligence agencies and other cyber experts have continuously warned that the likes of Signal and WhatsApp are frequently targeted because their end-to-end encryption gives government users a false sense of security. Yet end-to-end encryption is pointless when you can’t trust who is in the conversation.

Signal and WhatsApp are designed for consumer use only. They do not offer organisation-level administration or management, leaving government officials vulnerable to anyone who is able to contact them. Consumer messaging apps are - from an IT department point of view - “insecure by design” and therefore the very opposite of what governments should be using. 

Secure by design

Element Server Suite Pro protects against the type of social engineering attacks targeted at Signal and WhatsApp because it provides an enterprise-grade messenger. 

Most government deployments of Element are either ‘internal-only’ or for use within a ‘closed federation’ of trusted partners. As a result, it’s extremely difficult for an external attacker to even target government employees. 

End-users are managed through an organisation’s existing directory service - the systems that are trusted to identify and control access to all the organisation’s applications, as well as supporting single sign-on. In addition to protecting against external threats, end-user management also guards against accidental invites, such as the Signalgate incident.

Element's identity and access management stops Signalgate incidents

As a further line of defence, within Element Server Suite Pro, room administrators are able to insist that end-users verify their devices to ensure that devices are trusted. 

Adopting the correct security posture

Governments and other organisations that have to prioritise security are generally good at assessing risk, and adjusting their security posture accordingly. Many of our customers, for example, use Element for communications within their air-gapped environments. Some are even introducing cross domain gateways to connect high and low side communications.

Yet other parts of those same organisations can still have a blind spot when it comes to messaging apps. While budgets exist for air-gapped networks, or to replace a collaboration suite, many find it difficult to win a new budget to provide a sovereign messenger as an alternative to the unsanctioned use of (free of charge) consumer messaging apps.

Yet governments typically require dedicated, hardened communication systems that incorporate strict access controls, monitoring, and security policies rather than relying on consumer messaging services. 

Sovereign and secure

Talking of the latest attacks, Vice-Admiral Peter Reesink, director, Dutch Military Intelligence and Security Service, says: "Despite their end-to-end encryption option, messaging apps ​such as Signal and WhatsApp should not be used as channels for classified, confidential or sensitive information." 

Signal is a centralised vendor-controlled service, from a US headquartered organisation and runs its entire service on AWS. WhatsApp is owned by US headquartered Meta, one of the world’s largest data mining companies. Neither Signal or WhatsApp offer any level of sovereignty, and both are designed purely for consumer use - creating a raft of vulnerabilities for workplace use. And as Australia’s government concluded in March 2025, they also erode the democratic process through a lack of record keeping.

As European governments embrace digitally sovereign IT strategies to improve national security, they should also move decisively to ban government officials from using Signal and WhatsApp for government-related conversations. 

Simultaneously, they need to give officials a sovereign and secure alternative.