This article is written by Christine Runnegar, senior director for internet trust, The Internet Society.
It’s simply not practical to only convey classified or confidential information by hand in a locked briefcase. Meanwhile, the Covid-19 pandemic has made face-to-face meetings difficult or impossible. That means secure communications that use end-to-end encryption are essential, especially for government communications and when sensitive information is at stake.
Why public servants are securing internal communications
Encryption secures government electronic communications against eavesdropping spies, tampering and theft. Essentially, it works by making sure communications, file transfers, and the many other ways we exchange data stay private between the sender and receiver. This guards against the risk of communication service providers being hacked, persuaded or otherwise compelled to provide the decrypted content to another government, to organised crime, or to anyone else. Which is great for public servants who don’t want to have to follow the example of Russia’s Federal Guard Service, and use typewriters.
• Want to write for us? Take a look at Apolitical’s guide for contributors
Recognising the threat that insecure communications pose to national security, several governments, politicians and militaries have instructed their personnel to only use messaging apps that are end-to-end encrypted. This growing list includes the staff of the European Commission, the UK’s Prime Minister, the UK’s Conservative Party, the US Senate, and the US Army’s 82nd Airborne Task Force.
Some are going a step further, like Germany’s federal government, and choosing services such as Signal that minimise metadata exposure. This is important because, while metadata does not contain the content of a message, it can include confidential or sensitive information about who you are communicating with and when you sent the message.
Securing communications with the public is also a priority for governments
Encryption is an essential tool for securing the confidentiality and integrity of government electronic communications. But encryption is not just useful for keeping official secrets. It’s also crucial for protecting the integrity of emergency alerts and other public service announcements.
Imagine if a prankster thought it would be amusing to intercept a bushfire evacuation alert and alter the information, leaving those at risk unaware or sending safe residents into panic. Or what if an adversary disrupted time-sensitive Covid-19 communications? What if a malicious group hijacked official communications to spread disinformation about election results? If there’s any risk of interference, encryption is the best way to assure audiences that public communications are official and secure.
Read the privacy policy and terms of service carefully before choosing a service.
Encrypted Internet protocols like HTTPS for websites and end-to-end messaging apps enable governments to communicate securely with the public. During the Covid-19 pandemic, institutions such as the World Health Organisation and national governments in Australia, India, the UK, and Niger quickly embraced encrypted services to share information on the virus.
But not all encrypted communications services offer the same level of encryption. Millions of Zoom users learned this when reporters revealed in March 2020 that the video conferencing service it offered at that time was not actually end-to-end encrypted.
So here are five tips for governments who want to use end-to-end electronic communications services.
Choose a service that has been well vetted by security researchers
Correctly implementing encryption, particularly for group conversations, is not straightforward. You should be wary about trying to build your own service. Also, as apps don’t tend to work with each other easily, a bespoke app designed for one organisation is unlikely to be useful for external communications.
Make sure encryption is turned on by default
People don’t often change default settings. So choose encrypted services that apply end-to-end encryption by default.
Choose a service that minimises metadata exposure
Read the privacy policy and terms of service carefully before choosing a service. Pay attention to what metadata is exposed and how it will be used by the service. Examine what personal data the service collects from the people who use it and their devices, and what data it pulls in from other sources.
Make sure backups are secure
It’s often important to keep backups of data for official records. These should be stored in an encrypted format, such as on an encrypted device or in encrypted cloud storage. If you use an external cloud storage service for backups, make sure others cannot decrypt the backup. Only you should have the keys to do this.
Have clear and enforceable guidelines on using messaging services and record-keeping
Information that’s been shared through end-to-end encrypted services may need to be disclosed in the future. It might be used in legal proceedings, to fulfil a Freedom of Information or privacy law request, or because a public access period has started. Government organisations should have clear and enforceable guidelines on the appropriate use of these services, and how they manage electronic records. These policies should include rules on who can access the information, how long information should be retained, and whether to allow the use of ‘disappearing messages’. — Christine Runnegar
We want to hear what you think about this article. Pitch an article to us or send your comments to hello@apolitical.co
(Picture Credit: Pexels)

Log in or sign up to continue the conversation