Banks hit with millions in fines for using Signal and WhatsApp
cnbc.com
cnbc.com
https://www.bloomberg.com/opinion/articles/2023-08-08/don-t-...
His is a pretty balanced take and raises some interesting points:
> I have argued that the SEC has aggressively expanded the recordkeeping requirements. In the olden days, almost all communication was informal and not recorded, and only formal decisions were memorialized in typed and carbon-papered memos, so the SEC had access only to a pretty limited slice of communications. Now, vastly more informal communication is text-based, and texting is a substitute for conversation, not for formal memos.
The rest of the piece and some of his related commentary in the area is worth a read.
The point is that from a bank employee perspective, a hallway conversation, a text message, and a WhatsApp chat might seem pretty similar, and no one expected face to face chats to be memorialized in preserved records, so why the other two?
So in a meaningful sense, the requirements around preservation have expanded significantly, and it shouldn't be a surprise that a lot of banks ended up breaking the rules.
As he writes in another piece (https://news.bloomberglaw.com/mergers-and-acquisitions/matt-...):
> My point here is that when these rules were written, it would have been absurd to say that brokers had to “appropriately conduct their communications about business matters within only official channels.” Everyone understood, in 1948, that only a small sliver of business was conducted in formal letters and memoranda, and that mostly you’d talk about business face-to-face. “As technology changes,” lots of forms of written electronic communication become substitutes not for memoranda, but for face-to-face conversation. So the SEC’s requirements constantly become broader. If you just talk to your colleagues in person, the SEC does not expect you to preserve that. Once you move that chat to WhatsApp, it does.
Now the SEC has run around fining a bunch of institutions and sent a message, and so you can expect compliance will improve.
As an aside, you'll notice that piece was written nearly a year ago, so this isn't exactly a new story.
To quote Stringer Bell from The Wire: “Is you taking notes on a criminal fucking conspiracy?”
When it comes to avoiding the record, it doesn't have to be lofty corrupt/ish deals or schemes, but also cases like certain anti-union threats, or even plain personal power-tripping.
e.g. the C-level one-liner email that consists of "lets have a chat about this"
doesn't even have to be anything malicious, such as not wanting to socialize an idea until it's fully-baked or hiring for a new VP role
"Banks fined millions evading regulation with Signal & WhatsApp"
News headlines have rules they use to make for shorter sentences.
They'd probably write
"Banks fined millions, delete records, use E2E apps"
It makes no mention of evading regulation. This fine is for a failure to retain written communications. Which is impossible to do for some of these communications channels.
Nobody working in banking is unaware of the written comms rules. Nobody using Signal or WhatsApp in that context is unaware they can't retain written comms. Can you prove intent? Probably not. Is it clear as daylight why this happened? Uh, yes.
And so the SEC hits them where it hurts at least a little bit, in the wallet.
Also, if you pay attention to the banking space... this is pretty much the usual cast of characters. There's absolutely no surprise.
People use iMessage/Signal/WhatsApp for myriad reasons: some good, some bad. There's no evidence in this case that any of what was said was in furtherance of a crime. The crime they've been fined for is that people--just people--were talking in totally normal communications channels, and their employer has failed to scrape one end of their E2E communications and save it to show to the SEC whenever it asks.
That's a much stronger issue than "if you've got nothing to hide, you don't need secrecy" nonsense that I suppose your NSA comment is supposed to refer to. Nobody is making that argument here.
As for "it's just people talking" - what else do you suppose a "archive all communications" regulation refers to?
And sure there's no evidence. Hence my "can you prove intent" statement. But if it's a regulatory violation that other banks have already been fined for, years ago, and you still sidestep the regulation, there's a strong question why you keep sidestepping it.
If you don't like that, you might not want to work in a space with regulatory oversight.
I am talking about business communications in a regulated sector.
It is absolutely incompatible with E2E encryption to mandate a third party access to one of the Es for surveillance purposes.
can't push jail on customers...
What forum is this?
Any idea on the % adoption rate? Couldn't easily find it.
Deposits at credit unions are also a liability to the credit union. The nonprofit and local angles, however, are germane.
For businesses, they might have the most attractive product and so you go with them. For example, they have an entire practice finance department that lends on favorable terms without SBA fees. However, they require using their checking account as a term of the loan. You could just fund the account and leave it, or use it.
The worst thing that has happened to me with them was they once allowed someone to cash a fake check using my account number. They put the money back but closed the account and I had to change over all my stuff to a new account number. I was a little disturbed that they didn't check the name on the account to the account number before approving the check.
But all of the other horror stories seem to happen on the consumer side.
I suspect for most consumers they don't know or notice the difference, but I wish they did.
Credit Unions FTW!
it's completely, undeniably worth it. unless you're a real big shot (worth millions in assets to the bank) who doesn't have to deal with the dehumanizing aspects of corporate "customer service", there is zero reason to be with anything other than a small local bank/credit union.
My credit union on the other hand could not understand why I wouldn't give them my card number over the phone whenthey called me.
Of course, trust would be a huge issue, but assuming that could be resolved, I feel like switching banks should be something people do all the time.
You're leaving money on the table during a time where interest rates just keep going up and banks are becoming more and more competitive with each other on rates. You should be earning at least 5.15% on a market savings account today. I doubt WF would pay anywhere near that.
It's seems crazy to me that that's so difficult in the US.
In the UK, you can open an account with a new bank and just tell them to switch over all your direct debits and give them the account number/sort code.
They'll contact your old bank, get everything moved across and get your old account closed on your behalf. The old bank is also obliged to reroute any payments from your old account for 6 months afterwards too IIRC
There is a good chance a credit union might offer that, but they aren't available to everyone as they often have membership requirements.
What others have suggested is the better route, minimize direct debits by using credit cards (which gets you 'free' CC points).
The other thing is to just use multiple banks... I have my 'debit' bank and then I move my savings around to whichever bank I can find with the highest savings rates (either cd's or money market accounts). I link just those two accounts together and can transfer funds as needed. I find that to be pretty easy now, but it took some getting used to.
I think a lot of people are afraid of opening a bunch of accounts in various places and having to track it all. The open account friction is pretty high... you generally have to do a two small deposit dance, which can take days. I have a theory that part of the fear could also stem from the fact that we penalize people's credit scores for opening too many credit card accounts... but the reality is that we don't do that with bank accounts.
We also have a culture of being afraid of touching our money. You're supposed to just put it in an account and forget about it. I think the mental barriers override the actual barriers.
I tend to have operating funds in my credit union checking account. This is where most bills are paid from. Savings moves to which never institution has the best rates.
That convenience sucks to give up out of principle but it's long overdue in my case.
It's wild how entrenched it is in every aspects of society, from social to business.
Goes to show you how far good UX, simplicity and ease of use can take you.
[1] ICO reprimands NHS Lanarkshire for sharing patient data via WhatsApp - https://ico.org.uk/about-the-ico/media-centre/news-and-blogs...
Why the extra steps?
But it appears that there is a face recognition app https://youtu.be/l8R6ZwSTLzU?t=105 the guy who is using the app in the video was the interior minister.
But it looks like this lawsuit is exactly about the opposite, that messages cannot be accessed and reviewed easily. It's also easy to understand why banks prefer using secured applications like Signal when discussing secret deals rather than taking the risk that such conversations leak to e.g. competitors...
If you ask most people how can they be sure that meta is really encrypting end to end, most shrug off saying that meta already knows everything about their lives through FB, Instagram anyway.
so they claim… not that fb has ever given us a reason to trust them.
Since the forward is instantaneous and not involve a reupload, it looks to me the files are cached on the servers. If the recipient can see thee files and they are encrypted, it means that the server itself encrypted it using their public cryptographic key. If the server can do that, it means it either: - can decrypt your own files - cache them unencrypted
Correct me if I am wrong.
It is easy to test by sending a large video recording over a crappy connection, then forwarding it to another recipient. First upload can literally take a minute or more, the second action is immediate.
You encrypt and upload the media to the storage server.
You share the download URL and key with person #1
Now how long would it take to forward that same message with the url and key to person #2...n?
https://theintercept.com/2020/03/31/zoom-meeting-encryption/
https://newatlas.com/computers/facebook-not-secretly-listeni...
And this:
https://www.pcmag.com/news/facebook-app-caught-activating-ph...
And this:
https://www.wired.com/story/whatsapp-facebook-data-share-not...
And of course this:
https://www.propublica.org/article/how-facebook-undermines-p...
>WhatsApp reviewers gain access to private content when users hit the “report” button on the app, identifying a message as allegedly violating the platform’s terms of service. This forwards five messages — the allegedly offending one along with the four previous ones in the exchange ...
This may not have much to do with the more specific abuse case of criminal financial conspiracies.
I guess people don't care unless someone sues
So everything is recorded, encrypted, some is monitored in near RT by engines, and only accessed by human employees when necessary. A full log of who accessed what is kept.
This falls under Fair Use (not sure about the exact term) under GDPR, as is a sensible way for the bank to uphold their legal obligations.
The term you're likely looking for is "Legitimate Interest", but that's not quite the same. You're looking for the bigger picture.
Full disclosure: I was the DPO of a gambling company and had to interpret the cross-regulation conflicts quite routinely. One of the big things with GDPR is that it can not overrule industry or domain-specific regulations. It will certainly influence how the data may be accessed, but as far as internal collection and storage goes, GDPR changes nothing material in finance.
Banks and trading shops are required to record and store all work-related communications. No exceptions, no excuses. The reasons are as you stated. To prove (or disprove) cases of insider trading, collusion, price fixing, front running, and all the other forms of fraud/abuse that would allow the financial outfits and/or their traders to break the rules and fleece their customers and/or counterparties. (They still manage, but at least it's not as blatant.)
The main impact of GDPR is that the financial industry has one additional reason to purge old records once the statute of limitations has expired.
It's still crazy to me how people use Viber en masse in a lot of those places. The UX is abysmal and it's full of manipulative ads. Habits are hard to change.
Never heard of Whatsapp? Try removing the comments where you talk about it then.
* I’m barely using hyperbole
The offense here is that no effort was done to keep records of the communication. It would have been ok to use WhatsApp if they somehow would have archived all communications. Records of communications have to be kept so that auditors can verify that no inside trading secrets were communicated to others, for instance.
This absolutely happens. Usually, however, the regulators are interpreting the law in a way that the legislators agree with. In those cases, there is no need for new legislation.
One, not every securities professional trades at a bank. Two, this is not true for any of them. Broadly speaking, work-related written communications must be logged. But there is nuance and exception to that.
any change to any banking system is then done via a banking order (payment order, deposit order, etc) and is documented and signed.
so there is plenty of trail evidence for each transaction with each customer
Employees are reminded not to use these lines for personal reasons (imagine an employee using the phone line to discuss their health with their doctor, and the employer just recorded extremely sensitive information from an employee), but the alternative means a strong fine from the regulators (usually the local AML authority).
People will just get a second private device that is not managed by the organization, and if there is a mutually beneficial advantage to doing so, the other party will do the same as well.
This has been going on forever, I remember when they kicked up a huge fuss when they found out that people were doing direct pin-to-pin messages on the blackberry (was not logged for boss to read at the time).
It's not an overall waste of time, because the goal is to reduce the enormous wastes caused by fraud, crime, and other malfeasance.
I know somebody who worked at a bank. The bank had a mandatory vacation policy: you had to be 100% gone for at least two solid weeks every year. When outsiders heard about this, they were often indignant. Who is the company to tell me how I spend my vacation? I know best when I need to rest. Why are they trying to regulate and control so much?
But the policy was about preventing crime. There are kinds of fraud where one person can keep it going a long time if they're around to fiddle things manually. But a couple of weeks of absence, plus the cross-training that goes with it, can keep those kinds of frauds from ever happening. And when they do happen, they stay much smaller.
As an example of why fighting fraud is vital to a bank, you could look at the failure of Barings Bank. One guy was able to fiddle the accounts to hide his losses, gaining a reputation as a trading genius. He started with a little deception, and it spiraled out of control over the years, eventually destroying a bank that had survived more than two centuries.
When compared with the destruction of the bank, making sure that supervisors can see what an employee is getting up to is a pretty small waste in comparison.
Take the pharmaceutical industry in the US. One reason it's so expensive for them to operate is the massive amount of rules and regulations that surround their work and cause them to hire tons more highly skilled personnel in order to meet those regulations just to get work done.
Now all those rules exist because someone did something bad and the rules prevent those bad things from happening again, which is a good thing. However, it increases the cost of doing business, and over time, as these rules and regulations pile up, everything gets more and more expensive and complex.
It's unfortunate that we as a society now have to pay for the actions of a bad actor in perpetuity. I don't know of a good alternative, because again these rules exist for a reason. Fraud is obviously bad, and people will constantly take advantage of the system until we regulate it more and more, but then normal rule followers pay the price.
But to answer your direct question, I think the answer is a pretty clear no. Financial companies invest a ton in communications. If there's a buck to be made from improving their tools so that their employees can communicate faster, they'll get around to it eventually. They'll just do it with tools that provide the sort of proper records that they've been obliged to keep since forever.
And the safety is probably correct. It's a problem that I'm not sure how to address
Two, you're ignoring the externalities here. Most regulations exist to account for negative externalities. If I sell big cookies on the street for $5 each and 1 person in 10 dies from eating my cookies, then my $50 in revenue has to be compared against the cost of the death. Food safety regulations have costs to be sure, but we have to measure them against the harm averted.
If a product is more expensive because its makers have to be more careful, then that's not inefficient. It's people having to pay the true costs of the product, which is more efficient overall.
It's also true that regulation can be inefficient, of course. But the solution for that is primarily for producers to be responsible members of society, and secondarily for them to work closely with regulators to find effective regulation at minimal cost.
But if effective regulation that properly places costs kills a company or an industry, I'd argue that industry should not exist in the first place. Something we're seeing rediscovered in real time with people like Sam Bankman-Fried.
in "free market" conditions, there should be players who can compete by not increasing prices, but due to the increasing number of regulations, it becomes impossible for smaller players to enter the market or exist in the market, so nobody can come in and take advantage of lowering prices, so prices just go up and up
Again these regulations usually exist for good reason, it just makes the market less efficient and drives prices up over time
In a free market without regulation, the "rational" thing to do is to flood the market with fake "life saving drugs" and reap the (almost) infinite ROI.
In a less hyperbolic sense, the nature of "market" dictates we cut corners wherever possible. When it's a matter of life and death, the public chose to legislate which corners cannot be cut.
But they can't see this according to the comment to which you're responding; that's the problem.
They're the employer and get to set reasonable conditions for employment, that's who they are.
There is no "intent" here. What you are describing is an organized criminal conspiracy which is illegal no matter what device or system you're using. What I am talking about here is whether the employer should get to listen in to all your calls and read all your emails and text messages. Why do you think they like BYOD so much? Because they can get a window into your personal life, what apps you have installed, etc.
It is not illegal to have friends, but if you are in a job that has certain regulations it is illegal to communicate in a non approved way with business partners. This isn’t a wide scope - it’s people who have jobs that are covered by these regulations.
If it were totally allowed and widespread how would there be any pretence of fairness in the markets? Of course you could say that at least then people would be appreciating the reality of the situation . . .
Then attempting to enforce antitrust laws is likewise a waste of time.
You still need a secondary device if you want to have a private conversation.
The banks aren't being fined for using Signal or WhatsApp or any particular technology, they're being fined for failing to keep records of regulated communication they're required by law to present for auditing. Obviously if you use tools that don't keep records, you need to find a way to save it yourself.
[1] Bad in the CNBC original, but actually truncated here on HN to remove the explanatory clause. The original reads "Banks hit with $549 million in fines for use of Signal, WhatsApp to evade regulators’ reach"
As someone who currently performs information risk management for a financial institution, I'll say that private messaging doesn't need to be banned per-se. It's just that all company business is the responsibility of the leadership, so ultimately, business communications needed to be reserved for business communication platforms over which leadership can enforce policy. Privacy is a component of this. These banks needed processes and controls to ensure their requirements are being met: Records of electronic communication, technical security controls to ensure the privacy of protected communication, approved communication mediums/channels for different classifications of information, periodic reviews on the adequacy of these controls, etc.
Sometimes the restriction of things like WhatsApp, Signal, etc. are seen as an affront to individual privacy. That's not what this is about. This is about preventing a lot of dangerous scenarios, like:
1. Employees at your bank do something evil that's also against the law, but because they used Signal/WhatsApp, no records of the communication can be used as evidence in court.
2. The bank has invested millions upon millions into an information security program. Someone decides to use Signal/WhatsApp to share sensitive account numbers. Signal/WhatsApp ends up with a vulnerability that exposes the information, rendering the InfoSec program protections ineffective.
3. Like #2, but the information in WhatsApp/Signal is super important. The employees who kept it there all leave and/or get into fatal accidents. How will that impact the bank?
4. Your manager starts a group chat for the team via text message and conversations about work occur. Turns out someone in the conversation is involved with a scandal. Because you talked about work stuff outside of the approved comms channels, your personal phone can now be taken and used as evidence in a court (even if they can't pull the encrypted messages from it!)
It's just better for everyone to keep work communications in one place that the company has control over, and your personal device/apps totally separate from it.
They could in theory run _e.g._ `sigtop` every couple of months and encrypt it (e.g. age or veracrypt).
It's a complicated workflow but I imagine they have a pipeline for emails that isnt much less complicated, but also isnt E2EE.
Was this used for nefarious purposes - possibly - but more likely it was general communications between team members using a platform that is more comfortable to them than either 1st party tools or something approved like teams. 99.9% of this was likely reminders for meetings, attendance and coverage messages, a message to a team member who timezone shifted from you and may be off any you need an answer etc. I'd guess most people involved didn't even consider the record keeping because their day to day jobs don't involve actual trading info, and the "encryption" of those services likely made them feel a more comfortable than they should.
Not trying to excuse the behavior - yes the record keeping is important - but I think it's also important to realize this was likely largely innocent.
I would tell people to fuck off if they wanted to invade my personal device with work chatter. Boundaries are good
I agree, one needs to keep work comms on approved software, I'm simply stating that while it's fun to be like "oohh big bad bank was hiding secret convos" it was more likely "janet i'm out today can you take the meeting with svp of <insert corp>"
Put another way context matters in terms of how the public should react to the news, not so much the result (fines) or the regulations / requirements.
Texting your coworker, would the usual path, not some secondary software that requires both people to set up ahead of time.
You do realize there are many places in the world where WhatsApp is the defacto standard tool to communicate correct?
The problem is no one has ever heard of Symphony, doesn't want to install it so they can ask a simple question, and the user experience is meh at best. If you do the right thing, clients would likely perceive you as difficult to work with and perhaps go elsewhere. To done extent, the inevitable fines might be seen as a necessary cost of doing business. So a pretty severe crackdown was necessary to ensure everyone is properly incentivized to inflict this pain upon clients.
Nobody should ever be "pleased" with knowingly breaking the law. When will we ever get serious about law enforcement for this type of crime?
If bureaucrats were on my ass about something so stupid, I would be very pleased once the matter was resolved.
Are you saying that we should not be able to require banks of a certain size to keep records, so that the highway patrol officers of finance can economically pull you over when you're speeding? Or should we allow everyone to use fuzzbusters effectively making the law pointless?
No. I'm saying this is just some boring, annoying regulation, and your grandstanding about wanting people to feel bad about breaking laws is misguided.
Every rule is written in blood. We recently saw guys fixing the LIBOR for a tray of leftover sushi. Thankfully we have records of that.
Not really. This rule was written when the only form of written communication was paper mail and office memos.
It wasn't written with instant messaging in mind.
In the 90s we had an IT contracter complaining the bank told him not to use a messaging app as the bank could not read it. The issue is the bank is at risk if communications were not recorded. At the time phones were already all recorded.
The stakes of financial crime rise as the amount of money at play increases.
Requiring big players to help us ensure that they are playing by the rules is a requisite for preventing larger SVB-like situations from festering.
No sooner than the day we abolish the profit motive.
Or that email will go to the "work phone" which isn't sitting on the sideboard somewhere rather than in the person's pocket.
That said, there aren't any banks that don't have a comprehensive employee training program on security and compliance, so "I didn't realise" isn't going to be a valid excuse.
That's not to say that there isn't any deliberately malicious use going on, but it's unlikely that malicious use would be uncovered.
It's far cheaper (and more deniable) to find a slightly different way round the regulations, see if/when you get fined for that, then move on to something else again...
"Firms may not permit the use of any type of electronic communication if they are unable to satisfy the applicable recordkeeping requirements with respect to that particular type of electronic communication."
- A banker answers honestly when interviewed by the regulator because they decide it's better for the Bank to take the fine than lie to regulator and risk personal criminal charges (unlikely, but why take that risk?).
- Regulator asks for evidence of some documentation (like trade confirmation), compliance asks banker, banker doesn't have it and admits it was over this app.
- Whistleblower or other source makes regulator believe there are prohibited communication and regulator demands phones be turned over.
- Other similar banks are caught in violation, and regulator does sweep of similar banks and demands phones be turned over.
The regulator has the ability to shut down the bank. The bank can easily tell the banker to turn over an unlocked phone or face legal action. The banker then turns over the phone.
Why should that be different if it's written?
Of course they are.
No offense: Where have you been?
Working in education the last 10 years. I mean all of that seems really unreasonable if that's the case.
Where I work they took my work phone away because I wasn't using it enough. Now if I need to make a call, it's just with my cell phone. No way that's being recorded.
> in person meetings
Presume you don't sit down at the table and set up mics before you start talking?
Obviously I can't show you.
Why do you presume that? Where I work every call is recorded.
Sweet!
"some bullshit MNPI to a coworker" != billion-dollar collusion/schemes
"fired" != "jailed"
I'm afraid I'll never understand this class of refutation that categorically misunderstands every component of a sentence.
Intent,
pattern of doing business this way.
> “We are pleased to resolve this matter,” said Wells Fargo spokeswoman Laurie Kight.
Unfortunate, penalty appears not big enough.
As another key responsibility, these individuals are forbidden from insider trading... which if they are not keeping records is basically not possible to police.
Big headline grabbing number. But what % of their quarterly profit is that?
Slap on the wrist, I suspect.
https://www08.wellsfargomedia.com/assets/pdf/about/investor-...
/s
Mr. Smith, please review the updated terms on WhatsApp.
I imagine a smaller fine would be a more effective deterrent if it was directed at the C-suite instead of the whole corporation. Maybe a little jail time too, as a treat.
These banks needed processes and controls to ensure their requirements are being met: Records of electronic communication, technical security controls to ensure the privacy of protected communication, approved communication mediums/channels for different classifications of information, periodic reviews on the adequacy of these controls, etc.
Sometimes the restriction of things like WhatsApp, Signal, etc. are seen as an affront to individual privacy. That's not what this is about. This is about preventing a lot of dangerous scenarios, like:
1. Employees at your bank do something evil that's also against the law, but because they used Signal/WhatsApp, no records of the communication can be used as evidence in court.
2. The bank has invested millions upon millions into an information security program. Someone decides to use Signal/WhatsApp to share sensitive account numbers. Signal/WhatsApp ends up with a vulnerability that exposes the information, rendering the InfoSec program protections ineffective.
3. Like #2, but the information in WhatsApp/Signal is super important. The employees who kept it there all leave and/or get into fatal accidents. How will that impact the bank?
4. Your manager starts a group chat for the team via text message and conversations about work occur. Turns out someone in the conversation is involved with a scandal. Because you talked about work stuff outside of the approved comms channels, your personal phone can now be taken and used as evidence in a court (even if they can't pull the encrypted messages from it!)
It's just better for everyone to keep work communications in one place that the company has control over, and your personal device/apps totally separate from it.