Live data from Hacker News

Technical analysis of the Signal clone used by Trump officials

micahflee.com

101–110 of 387 posts

Re: Technical analysis of the Signal clone used by Trump officials

#102
post #72

Still trying to grasp the idea of archiving messages from E2E encrypted communication system into a storage that entirely breaks the purpose of using something like Signal. It’s like encashing on the trust of Signal protocol, app while breaking its security model so that someone else can search through all messages. What am I missing here?

Any client-side limitations are not part of the security model because you don't control other people's devices. Even with an unmodified app, they're trivially bypassed using a rooted/jailbroken device.

Re: Technical analysis of the Signal clone used by Trump officials

#103
post #20

There is new reporting that a hacker has breached the parent company, TeleMessage, including live data being passed across servers in production. https://www.404media.co/the-signal-clone-the-trump-admin-use... It was marked as a DUPE of this discussion, despite being a major new development https://news.ycombinator.com/item?id=43890034 Hopefully that decision can be reconsidered

> The data includes apparent message contents; the names and contact information for government officials; usernames and passwords for TeleMessage’s backend panel; and indications of what agencies and companies might be TeleMessage customers.

Re: Technical analysis of the Signal clone used by Trump officials

#105

what is going on in the US gov IT? They took an Israeli app, that is a modified version of signal. the modification BREAKS the one thing signal is excellent at (keeping your messages encrypted so that only the desired endpoints can read them), then distributed it within the US Gov. This is insanity! US's enemy's couldn't manufacture a better result themselves!

It's not just the US gov - TeleMessage/Smarsh sell to everyone: banks, corporations etc. Their USP is that your employees get to "keep using their apps" but still comply with all the boring data retention stuff - instead of using a dedicated corporate chat app

What's interesting is that they also sell a hacked version of WhatsApp, and the Meta legal team haven't steamrolled them yet

Re: Technical analysis of the Signal clone used by Trump officials

#106

We should all feel relieved that trump admin are following law to archive their chats after all. Unfortunately this Israeli company is just incompetent, should try something from Russia next time, given that’s all the data end up to be anyway.

I wonder if they were using it from the start, or if after the first SignalGate, someone scrmabled to find a supplier who could "make their Signal compliant" (which is exactly what TeleMessage/Smarsh are selling)

Re: Technical analysis of the Signal clone used by Trump officials

#107
post #83

Earlier quoted context omitted.

In August last year I got this from dang when reporting a dead 404 link: "The site 404media.co is banned on HN because it has been the source of too many low-quality posts and because many (most?) of their articles are behind a signup wall." Not that I've really seen the low quality and the signup requirement doesn't stop other domains. There's quite a few things that originated from 404, so I hope HN gets over whate…

The main issue is the (sometimes) hard signup wall. I've been a moderator on HN for longer than 404media has existed, and I know from experience that this changes from time to time or article to article. Other paywalled sites that appear on HN (WSJ, NYT etc) have a porous paywall; you can (almost) always get around it by using an archive site like Archive.today. If it's a good article (contains significant new inform…

If they do their own, original, investigative reporting, you may want to be a bit more permissive.

Re: Technical analysis of the Signal clone used by Trump officials

#108

So this whole app exists because Signal doesn't have a way to archive messages on iPhone. Maybe they should take the hint and see that this is actually something a lot of people would find useful, instead of keeping it the backlog for a decade.

Well no, then you could just use Messenger or WhatsApp. The point of Signal is to be as secure as possible

Re: Technical analysis of the Signal clone used by Trump officials

#109

Earlier quoted context omitted.

>> Signal was an approved and whitelisted app for ... discuss top-secret matters on. No. Just no. Anyone who has handled TS information would know how nutz that sounds. Irrespective of software, TS stuff is only ever displayed in special rooms with big doors and a man with a gun outside. The concept of having TS on an everyday-use cellphone is just maddening.

[flagged]

You're leaving out crucial information. Obama didn't keep his BlackBerry for classified information, he was given the then-standard government secure mobile communications device, a Secure Mobile Environment Personal Encryption Device (SME-PED).

More specifically, the device Obama was given was a Sectéra Edge [0][1] by General Dynamics, a device specifically designed to be able to operate on Top Secret voice and Secret data networks. It had hardware-level separation between the unclassified and classified sides, even having separate flash memory for both. [2]

The NSA contributed to the design and certified it and another device (L3's Guardian) on the SCIP, HAIPE, Suite A/B, Type 1, and non-Type 1 security protocols.

It was absolutely not a regular BlackBerry, it didn't run any RIM software, no data ever went through RIM's servers, and secure calls were encrypted and didn't use SS7. It was a clunky purpose-designed device for the entire US government to be able to access Secret information and conduct Top Secret voice calls on the go.

Even then, there were limitations to when and where it could be used and when a SCIF was required.

The current equivalent of the SME-PED programme is the DoD's Mobility Classified Capability[3], which are specially customised smartphones again made by General Dynamics.

There is no excuse whatsoever for the current administration's use of Signal, let alone TeleMessage Signal, for Secret and Top Secret discussions on regular consumer and personal devices. It's deeply irresponsible and worse than any previous administration has done.

[0] https://www.cnet.com/tech/tech-industry/obamas-new-blackberr...

[1] https://gdmissionsystems.com/discontinued-products/sectera-e...

[2] https://apps.dtic.mil/sti/tr/pdf/ADA547816.pdf

[3] https://www.disa.mil/~/media/files/disa/fact-sheets/dmcc-s.p...

Re: Technical analysis of the Signal clone used by Trump officials

#110

Earlier quoted context omitted.

There are already government e2e apps. The only reason to use something else is to have selective auto-deletion and/or to use personal devices for official classified data.

Do you have the link to this alleged government-produced e2e software so we can inspect ourselves? I realize they have an incentive to appear incompetent, but surely there must be evidence (further than your testimony) of such gossip popping up somewhere

There are not just government e2e apps, but government-provided and customised smartphones specifically for them, like the DMCC-S programme. [0]

Some of the apps are listed in that brochure.

There's no excuse for using Signal on personal devices for classified conversations.

[0] https://www.disa.mil/~/media/files/disa/fact-sheets/dmcc-s.p...

Post reply on HN