Live data from Hacker News

Technical analysis of the Signal clone used by Trump officials

micahflee.com

141–150 of 387 posts

Re: Technical analysis of the Signal clone used by Trump officials

#142

Earlier quoted context omitted.

> What am I missing here? OK, say you're a bank. The SEC states you need to keep archives of every discussion your traders have with anyone at any time (I'm simplifying things but you get the point). You keep getting massive fines because traders were whatsapping about deals So now you've got several options - you can use MS Teams, which of course offers archival, compliance monitoring etc. But that means trusting MS…

Seems like it doesnt resolve the trust issue it just shifts it to a smaller firm with more to lose.

[deleted]

Re: Technical analysis of the Signal clone used by Trump officials

#143
post #140

Earlier quoted context omitted.

[flagged]

My statements were complete. You were not completing them, but trying to spin them in a way that implies wrongdoing when no evidence exists of it. I can only presume you're doing so for partisan reasons, to try to defend the actions of the current administration. Whatever the reason, I have made my case. Feel free to make yours with a similar level of evidence.

[flagged]

Re: Technical analysis of the Signal clone used by Trump officials

#144
post #134

Earlier quoted context omitted.

No, you can distribute custom managed apps through Apple's MDM programme. https://support.apple.com/en-gb/guide/deployment/dep575bfed8...

Sorry yes I meant for personal devices. These are designed to be deployed under MDM on corporate devices edit: found their install doc! https://smarsh.my.salesforce.com/sfc/p/#30000001FgxH/a/Pb000...

You can put personal devices on an MDM, many have special modes for this too.

Re: Technical analysis of the Signal clone used by Trump officials

#145
post #72

Still trying to grasp the idea of archiving messages from E2E encrypted communication system into a storage that entirely breaks the purpose of using something like Signal. It’s like encashing on the trust of Signal protocol, app while breaking its security model so that someone else can search through all messages. What am I missing here?

You can never control what I do on my device with the message received- I can make screenshots, or, if the app prevents that, take a picture of the screen. The goal of signal is trusted end-to-end encrypted communication. Device/Message security on either end is not in scope for Signals threat model.

TM SGNL changes the security model from "I trust the people in the chat" to "I trust the people in the chat and also the company archiving the chat".

If you don't trust the people in your chat, they shouldn't be in your chat.

Re: Technical analysis of the Signal clone used by Trump officials

#146
post #72

Still trying to grasp the idea of archiving messages from E2E encrypted communication system into a storage that entirely breaks the purpose of using something like Signal. It’s like encashing on the trust of Signal protocol, app while breaking its security model so that someone else can search through all messages. What am I missing here?

Any client-side limitations are not part of the security model because you don't control other people's devices. Even with an unmodified app, they're trivially bypassed using a rooted/jailbroken device.

Not part of Signal's security model, but trusting people in that chat very much can and should be part of the user's security model. If you don't trust them, why are they in the chat in the first place?

Re: Technical analysis of the Signal clone used by Trump officials

#147
post #64

There’s chatter on bsky. But tl;dr anything said on those phones is assumed to be compromised until proven otherwise by time or a whole lot of very interesting security verifications. So far the evidence that this is a very large leak looks probable based on the evidence presented.

Why do you say "everything said on those phones" - did you mean "on this app"? If the backend of an app was compromised, that wouldn't mean the phone itself was rooted?

By installing MDM you’re effectively chaining your security to the security of the MDM. The MDM gives you the ability to install arbitrary code via a blessed backdoor. There’s no reason currently not to suspect that anything said on that phone (signal or not) is compromised.

Re: Technical analysis of the Signal clone used by Trump officials

#148

We should all feel relieved that trump admin are following law to archive their chats after all. Unfortunately this Israeli company is just incompetent, should try something from Russia next time, given that’s all the data end up to be anyway.

According to this tweet the government contract for the software was originally from 8/24 during the Biden administration: https://x.com/_MG_/status/1918148557670105354

Re: Technical analysis of the Signal clone used by Trump officials

#149
post #127

Earlier quoted context omitted.

> He was allowed to keep his BlackBerry for personal communication only, not classified communication Presence of the senior staff on his (very limited) contact list would seem to contradict that statement. Communication with them would be, by definition, not personal. I agree with you that our government officials should be using the secure infrastructure our patriotic service members and civil servants work so hard…

If you’d prefer, we can call it unclassified communication rather than personal communication. The point is that it was not used for Secret, Top Secret, or other classified communications. For that, he had the SME-PED device. So, again, it’s not a parallel to the current situation. Nobody is saying the SecDef and other staff shouldn’t have unclassified devices as well as their classified devices, the issue is that th…

But how could he have created accidentally a conversation for discussing targets during military attack with a journalist if secret communication was not done on his clear-text device ?

Re: Technical analysis of the Signal clone used by Trump officials

#150

White House communications director previously revealed (after “Signalgate”) that Signal was an approved and whitelisted app for gov’t officials to have on work phones and even discuss top-secret matters on. But I haven’t heard that TeleMessage was approved (and I’d have serious questions if it were given the foreign intelligence factor). Anyone know if there is a clear answer to whether it’s been approved?

It would have to be approved; there is no way for lay-users to install/configure TM-SGNL in their own; it needs to be deployed via MDM.

Source: I'm the admin who installs TM-SGNL for many users.

Post reply on HN