Live data from Hacker News

Technical analysis of the Signal clone used by Trump officials

micahflee.com

161–170 of 387 posts

Re: Technical analysis of the Signal clone used by Trump officials

#161
post #3

The big part of this story which nobody is talking about is the fact that the app is literally controlled by a bunch of “former” Israeli intelligence officers. Who now have what is arguably the worlds most valuable access out of anyone.

I don't think it's that big: USG procures defense and intelligence tech more or less constantly from Israel. It's unlikely that Israel would threaten that relationship (and the value they extract from it in terms of favorable relations) in exchange for military intelligence that's already shared with them.

(I feel like I have to say this in every thread that insinuates something sinister about being a "former Israeli intelligence officer": the structure of Israel's military and mandatory service is such that just about everybody with technical skills serves in some kind of "intelligence" capacity. It's not a very big country. This is, of course, independent from any normative claims about Israel's government, politics, etc. -- it's what you'd expect in any small country that has mandatory military service with a significant intelligence component.)

Re: Technical analysis of the Signal clone used by Trump officials

#162

Earlier quoted context omitted.

A few decades ago, the Republican party had one foot in the anti-intellectual camp, but only one. They were the party of young-earth creationists, religious pro-lifers, climate-deniers and gun-lovers - but also of educated fiscally conservative folks. The party would welcome economics professors and leaders of medium-sized businesses, promising no radical changes, no big increases in spending or regulation, and a gen…

[flagged]

It's probably closer to the truth than not.

Re: Technical analysis of the Signal clone used by Trump officials

#163
post #67

Earlier quoted context omitted.

This is so frightening. I worked in corporate security, and that was occasionally a leaking ship, but this wouldn’t even fly with our engineers even if we wanted their message history. This is negligence.

The scariest part? They also sell to corporations... Read their install guide and weep at the idea of pushing cracked WhatsApp binaires through MDM https://smarsh.my.salesforce.com/sfc/p/#30000001FgxH/a/Pb000...

> cracked WhatsApp binaries

On a more meta note, I wonder who even works at companies founded on ideas that are just... bad. On average, I expect good engineers to push back on such business requirements and also have better job mobility so they can leave and work elsewhere. The researcher found the vulnerabilities "in less than 30 minutes" so it seems there's some lack of competence here.

Unfortunately, misguided business requirements like this won't simply disappear and I get that those can be niche offerings that attract juicy contracts.

Re: Technical analysis of the Signal clone used by Trump officials

#164

Here is the thing about e2e encrypted messengers: They lock you and your data in and do not allow you control of your life. There is a right to data portability (at least in the eu) that they violate and there is no one fighting for it. Whenever i engage in conversation about this i get empty faces, hostility and vague references to features that are crippled or just don't work at all. There are people and institutio…

There's a difference between data transport and data hosting. Modern expectations of messengers seem to blur this line and it's better if it's not blurred.

Incidentally: The reason why they blur it is because of 2 network asymmetries prevalent since the 1990's that enforced a disempowering "all-clients-must-go-through-a-central-server model" of communications. Those 2 asymmetries are A) clients have lower bandwidth than servers and B) IPv4 address exhaustion and the need/insistence on NAT. It's definitely not practical to have a phone directly host the pictures posted in its group chats, but it would be awesome if the role of a messaging app's servers was one of caching instead of hosting.

In the beginning though: the very old IRC was clear on this; it was a transport only, and didn't host anything. Anything relating to message history was 100% a client responsibility.

And really I have stuck with that. My primary expectation with messaging apps is message transport. Syncing my message history on disparate devices is cool, and convenient, but honestly I don't really need it in a personal capacity if each client is remembering messages. I don't understand how having to be responsibile for the management of my own data is "less control of my life," it seems like more control. And ... I'm not sure I care about institutional entitlement to archive stuff that is intended to be totally personal.

I understand companies like to have group chats, and history may be more useful and convenient there, but that's why I'm not ever going to use Teams for personal purposes. But I'm not going to scroll back 10 years later on my messaging apps to view old family pictures. I'm going to have those saved somewhere.

Re: Technical analysis of the Signal clone used by Trump officials

#165

Here is the thing about e2e encrypted messengers: They lock you and your data in and do not allow you control of your life. There is a right to data portability (at least in the eu) that they violate and there is no one fighting for it. Whenever i engage in conversation about this i get empty faces, hostility and vague references to features that are crippled or just don't work at all. There are people and institutio…

Molly is a fork of signal that is allowed to access Signals APIs and their APIs are much more open than any other similar service [1] . Signal is not really designed for communicating with people that you don't know in real life such that you can be beyond suspicion that they would be archiving messages but it is basically impossible to monitor if your conversations are being archived if someone is just taking pictures of their phone with another device.

[1] https://github.com/mollyim/mollyim-android

Re: Technical analysis of the Signal clone used by Trump officials

#166
post #72

Still trying to grasp the idea of archiving messages from E2E encrypted communication system into a storage that entirely breaks the purpose of using something like Signal. It’s like encashing on the trust of Signal protocol, app while breaking its security model so that someone else can search through all messages. What am I missing here?

> What am I missing here? OK, say you're a bank. The SEC states you need to keep archives of every discussion your traders have with anyone at any time (I'm simplifying things but you get the point). You keep getting massive fines because traders were whatsapping about deals So now you've got several options - you can use MS Teams, which of course offers archival, compliance monitoring etc. But that means trusting MS…

ok, this absolutely reminds me of using indian whatsapp mods years ago. stickers, more features, local and portable backups... wouldn't try that as a member of the government though

Re: Technical analysis of the Signal clone used by Trump officials

#167
post #3

The big part of this story which nobody is talking about is the fact that the app is literally controlled by a bunch of “former” Israeli intelligence officers. Who now have what is arguably the worlds most valuable access out of anyone.

I don't think it's that big: USG procures defense and intelligence tech more or less constantly from Israel. It's unlikely that Israel would threaten that relationship (and the value they extract from it in terms of favorable relations) in exchange for military intelligence that's already shared with them. (I feel like I have to say this in every thread that insinuates something sinister about being a "former Israeli…

[flagged]

Re: Technical analysis of the Signal clone used by Trump officials

#168
post #72

Still trying to grasp the idea of archiving messages from E2E encrypted communication system into a storage that entirely breaks the purpose of using something like Signal. It’s like encashing on the trust of Signal protocol, app while breaking its security model so that someone else can search through all messages. What am I missing here?

> What am I missing here? OK, say you're a bank. The SEC states you need to keep archives of every discussion your traders have with anyone at any time (I'm simplifying things but you get the point). You keep getting massive fines because traders were whatsapping about deals So now you've got several options - you can use MS Teams, which of course offers archival, compliance monitoring etc. But that means trusting MS…

Is it a coincidence that it reads almost exactly like SMERSH?

https://en.wikipedia.org/wiki/SMERSH

Re: Technical analysis of the Signal clone used by Trump officials

#169
post #167

Earlier quoted context omitted.

I don't think it's that big: USG procures defense and intelligence tech more or less constantly from Israel. It's unlikely that Israel would threaten that relationship (and the value they extract from it in terms of favorable relations) in exchange for military intelligence that's already shared with them. (I feel like I have to say this in every thread that insinuates something sinister about being a "former Israeli…

[flagged]

>Some minor spying would not even register.

I mean, they stole weapons grade Uranium from United States along with nuclear secrets and we just shrugged our shoulders: https://www.theguardian.com/world/2014/jan/15/truth-israels-...

Post reply on HN