Live data from Hacker News

Technical analysis of the Signal clone used by Trump officials

micahflee.com

111–120 of 387 posts

Re: Technical analysis of the Signal clone used by Trump officials

#111

So this whole app exists because Signal doesn't have a way to archive messages on iPhone. Maybe they should take the hint and see that this is actually something a lot of people would find useful, instead of keeping it the backlog for a decade.

It's not a question of archiving on the device - it's a question of your employer being able to archive/monitor your conversations

Re: Technical analysis of the Signal clone used by Trump officials

#112

So this whole app exists because Signal doesn't have a way to archive messages on iPhone. Maybe they should take the hint and see that this is actually something a lot of people would find useful, instead of keeping it the backlog for a decade.

Well no, then you could just use Messenger or WhatsApp. The point of Signal is to be as secure as possible

TeleMessage/Smarsh also sell a cracked WhatsApp :)

Re: Technical analysis of the Signal clone used by Trump officials

#113
post #72

Still trying to grasp the idea of archiving messages from E2E encrypted communication system into a storage that entirely breaks the purpose of using something like Signal. It’s like encashing on the trust of Signal protocol, app while breaking its security model so that someone else can search through all messages. What am I missing here?

> What am I missing here?

OK, say you're a bank. The SEC states you need to keep archives of every discussion your traders have with anyone at any time (I'm simplifying things but you get the point). You keep getting massive fines because traders were whatsapping about deals

So now you've got several options - you can use MS Teams, which of course offers archival, compliance monitoring etc. But that means trusting MSFT, and making sure your traders only use Teams and nothing else. You can use a dedicated application for the financial industry, like Symphony or ICE Chat or Bloomberg, but they're clunkier than B2C apps.

And then the Smarsh (owners of Telemessage) salesman calls you, and says "your users can keep using the apps they love - WhatsApp, Signal - but we make it compliant". And everyone loves it (as long as no-one in your Security or Legal teams are looking too hard at the implications of distributing a cracked version of WhatsApp through your MDM...)

Edit: here's the install document for their cracked WhatsApp binary https://smarsh.my.salesforce.com/sfc/p/#30000001FgxH/a/Pb000...

Re: Technical analysis of the Signal clone used by Trump officials

#114
post #109

Earlier quoted context omitted.

[flagged]

You're leaving out crucial information. Obama didn't keep his BlackBerry for classified information, he was given the then-standard government secure mobile communications device, a Secure Mobile Environment Personal Encryption Device (SME-PED). More specifically, the device Obama was given was a Sectéra Edge [0][1] by General Dynamics, a device specifically designed to be able to operate on Top Secret voice and Secr…

Your reference [0] appears to contradict what you've said here. It speaks at length about several NSA approved options as alternatives, but says Obama used a BlackBerry.

The photo attached to the article captioned "President-elect Barack Obama checks his BlackBerry while riding on his campaign bus in Pennsylvania last March." appears to show a blackberry.

I take it from the article that this was as controversial as I remember it being at the time. Thanks for posting it.

Re: Technical analysis of the Signal clone used by Trump officials

#115

Earlier quoted context omitted.

It was incontrovertibly approved as it is only installable via MDM. A likely explanation is that the communications director (or the people informing her) wouldn’t know to distinguish between Signal the app, and a Signal compatible app that is nearly indistinguishable from Signal. A lot like Kleenex is a common term for tissue paper regardless of brand. When the leak was first revealed, there was loud speculation abo…

> It was incontrovertibly approved as it is only installable via MDM. Only if this his standard govt issued phone. It's also been shown they are also using their own personal phones. The could easily be using unapproved phones some random DOGE'er bought gave them with an MDM setup, without any real oversight.

The device would have to be jailbroken right? These apps are (obviously) not in the App Store, I mean one of them is a cracked WhatsApp ...

Re: Technical analysis of the Signal clone used by Trump officials

#116
post #110

Earlier quoted context omitted.

Do you have the link to this alleged government-produced e2e software so we can inspect ourselves? I realize they have an incentive to appear incompetent, but surely there must be evidence (further than your testimony) of such gossip popping up somewhere

There are not just government e2e apps, but government-provided and customised smartphones specifically for them, like the DMCC-S programme. [0] Some of the apps are listed in that brochure. There's no excuse for using Signal on personal devices for classified conversations. [0] https://www.disa.mil/~/media/files/disa/fact-sheets/dmcc-s.p...

Are the apps usable? The jargon seems intentionally impenetrable. The editor of that document should be shot every time they used an acronym. Like i get the DOD is a profitable dick to suck but this is just embarrassing for a document intended for the public.

Anyway can you link the source? That's presumably the useful half. The marketing bit doesn't add anything.

Re: Technical analysis of the Signal clone used by Trump officials

#117
post #95

Earlier quoted context omitted.

There's compelling evidence that the messages all pass through TM servers before being archived. The question is where the E2E encryption goes between.

The E2E encryption is likely not even relevant, unless I'm missing something? The builds that are distributed would likely just send the plaintext un-encrypted message separately to the archive, and I'm guessing that means it goes right to TM servers before being dispatched elsewhere.

Ah yes, it's end-to-end alright, end-to-end cleartext.

Re: Technical analysis of the Signal clone used by Trump officials

#118
post #109

Earlier quoted context omitted.

You're leaving out crucial information. Obama didn't keep his BlackBerry for classified information, he was given the then-standard government secure mobile communications device, a Secure Mobile Environment Personal Encryption Device (SME-PED). More specifically, the device Obama was given was a Sectéra Edge [0][1] by General Dynamics, a device specifically designed to be able to operate on Top Secret voice and Secr…

Your reference [0] appears to contradict what you've said here. It speaks at length about several NSA approved options as alternatives, but says Obama used a BlackBerry. The photo attached to the article captioned "President-elect Barack Obama checks his BlackBerry while riding on his campaign bus in Pennsylvania last March." appears to show a blackberry. I take it from the article that this was as controversial as I…

He was allowed to keep his BlackBerry for personal communication only, not classified communication, and had to use a Sectéra Edge for classified communication. [0]

The Blackberry for personal use wasn't a stock BlackBerry, but hardened by the NSA and fitted with the SecurVoice software package to encrypt voice calls, emails, and messages. The few people he had on his approved communication list were given the same devices.[1]

That BlackBerry was, again, not used for classified communication. So it's not the same thing as the current scandal.

[0] https://www.spokesman.com/stories/2009/jan/24/obamas-other-p...

[1] https://www.wired.com/2009/04/obama-to-get-back-blackberry-a...

Re: Technical analysis of the Signal clone used by Trump officials

#119
post #110

Earlier quoted context omitted.

There are not just government e2e apps, but government-provided and customised smartphones specifically for them, like the DMCC-S programme. [0] Some of the apps are listed in that brochure. There's no excuse for using Signal on personal devices for classified conversations. [0] https://www.disa.mil/~/media/files/disa/fact-sheets/dmcc-s.p...

Are the apps usable? The jargon seems intentionally impenetrable. The editor of that document should be shot every time they used an acronym. Like i get the DOD is a profitable dick to suck but this is just embarrassing for a document intended for the public. Anyway can you link the source? That's presumably the useful half. The marketing bit doesn't add anything.

I don't care how usable they are, this is the DoD and NSA-approved mechanism for conducting classified conversations and viewing classified data on mobile devices. The adversaries here are other countries who are very good at what they do, security is far more important than convenience.

As for further research, there's plenty online about his programme and these devices. Feel free to Google it yourself. You're asking to be spoonfed.

Re: Technical analysis of the Signal clone used by Trump officials

#120
post #64

There’s chatter on bsky. But tl;dr anything said on those phones is assumed to be compromised until proven otherwise by time or a whole lot of very interesting security verifications. So far the evidence that this is a very large leak looks probable based on the evidence presented.

Why do you say "everything said on those phones" - did you mean "on this app"? If the backend of an app was compromised, that wouldn't mean the phone itself was rooted?
Post reply on HN