Live data from Hacker News

Technical analysis of the Signal clone used by Trump officials

micahflee.com

171–180 of 387 posts

Re: Technical analysis of the Signal clone used by Trump officials

#171
post #167

Earlier quoted context omitted.

I don't think it's that big: USG procures defense and intelligence tech more or less constantly from Israel. It's unlikely that Israel would threaten that relationship (and the value they extract from it in terms of favorable relations) in exchange for military intelligence that's already shared with them. (I feel like I have to say this in every thread that insinuates something sinister about being a "former Israeli…

[flagged]

I would absolutely put "Israel taps the National Security Advisor's phone" in a different category of risk to the two country's relationship than previous activities. This, again, isn't a normative argument.

(A piece of context that's often missing from - typically charged - discussions about US/Israel relationships is the degree of dependence between the two, and how that's varied over the years. Israel's defense policies have historically been informed by a desire to be fully self-sufficient during wartime, i.e. not require active support from countries like the U.S. That policy has been deprioritized over the last 20-30 years, to the point where the US is now a significant active defense provider for Israel, rather than just an arms supplier. This is a dependency relationship that's new to the ongoing conflict, and should color any analysis of Israel's willingness to do things that would threaten its relationship with the U.S.)

Re: Technical analysis of the Signal clone used by Trump officials

#172

White House communications director previously revealed (after “Signalgate”) that Signal was an approved and whitelisted app for gov’t officials to have on work phones and even discuss top-secret matters on. But I haven’t heard that TeleMessage was approved (and I’d have serious questions if it were given the foreign intelligence factor). Anyone know if there is a clear answer to whether it’s been approved?

It would have to be approved; there is no way for lay-users to install/configure TM-SGNL in their own; it needs to be deployed via MDM. Source: I'm the admin who installs TM-SGNL for many users.

Would be interesting to dump the app binaries so people can take a look at how its put together, I suspect its a minefield of sloppy injection functions into how signal works.

Re: Technical analysis of the Signal clone used by Trump officials

#173
post #16

> 404 Media journalist Joseph Cox published a story pointing out that Waltz was not using the official Signal app, but rather "an obscure and unofficial version of Signal that is designed to archive messages" Wow. And that's while their entire point of using Signal is to have conversations scrapped after a week to leave no no traces of criminal activity.

I don't think it follows that they selected the archiving messenger because they wanted disappearing messages. The whole disappearing messages thing was just internet speculation.

[deleted]

Re: Technical analysis of the Signal clone used by Trump officials

#174

Earlier quoted context omitted.

Why do you say "everything said on those phones" - did you mean "on this app"? If the backend of an app was compromised, that wouldn't mean the phone itself was rooted?

By installing MDM you’re effectively chaining your security to the security of the MDM. The MDM gives you the ability to install arbitrary code via a blessed backdoor. There’s no reason currently not to suspect that anything said on that phone (signal or not) is compromised.

The MDM admin can do whatever the user can do (or more), sure. So yes the MDM admin can potentially read/hear/see stuff, but everyone knows that. That's not a vulnerability, that's by design.

The compromise is only wrt the admin. Are you claiming the admin itself is compromised? What's the evidence for that?

Re: Technical analysis of the Signal clone used by Trump officials

#175
post #155
post #149

Earlier quoted context omitted.

But how could he have created accidentally a conversation for discussing targets during military attack with a journalist if secret communication was not done on his clear-text device ?

I think you're misunderstanding me, I'm referring to Obama's use of an NSA-hardened BlackBerry for unclassified communication with a select group of people, while using a purpose-built and NSA-cleared secure phone for classified communication. All of which was done correctly in terms of information security processes. Secretary of Defence Hegseth sent Secret or Top Secret information over a channel (Signal/TM Signal…

Thank you for the clarification

Re: Technical analysis of the Signal clone used by Trump officials

#176
post #170

I thought the only client allowed on Signal was the official build provided by Signal itself? Does this mean Signal does officially allow another build (Telemark's TM SGNL) access to the Signal network?

From what I know, Signal tries to block known bad clients. But guaranteeing such blocks is impossibly hard short of forcing attestations via things like SafetyNet that would legitimately impact users as well.

There was a case where a teenager in India rose to news media popularity by publishing a messaging app, which was a simple rebranding of Signal he made using some other tool which patches assets iirc.

It was blocked by Signal, but only after reports surfacing about it being an insecure rebrand.

Re: Technical analysis of the Signal clone used by Trump officials

#177
post #140

Earlier quoted context omitted.

My statements were complete. You were not completing them, but trying to spin them in a way that implies wrongdoing when no evidence exists of it. I can only presume you're doing so for partisan reasons, to try to defend the actions of the current administration. Whatever the reason, I have made my case. Feel free to make yours with a similar level of evidence.

[flagged]

How is your voting record public? Who anyone voted for is not a matter of public record, and even if you claimed to disclose it, nobody would be able to fact check that..

Re: Technical analysis of the Signal clone used by Trump officials

#178

Earlier quoted context omitted.

> What am I missing here? OK, say you're a bank. The SEC states you need to keep archives of every discussion your traders have with anyone at any time (I'm simplifying things but you get the point). You keep getting massive fines because traders were whatsapping about deals So now you've got several options - you can use MS Teams, which of course offers archival, compliance monitoring etc. But that means trusting MS…

Is it a coincidence that it reads almost exactly like SMERSH? https://en.wikipedia.org/wiki/SMERSH

[dead]

Re: Technical analysis of the Signal clone used by Trump officials

#179
post #170

I thought the only client allowed on Signal was the official build provided by Signal itself? Does this mean Signal does officially allow another build (Telemark's TM SGNL) access to the Signal network?

From what I know, Signal tries to block known bad clients. But guaranteeing such blocks is impossibly hard short of forcing attestations via things like SafetyNet that would legitimately impact users as well. There was a case where a teenager in India rose to news media popularity by publishing a messaging app, which was a simple rebranding of Signal he made using some other tool which patches assets iirc. It was blo…

[dead]

Re: Technical analysis of the Signal clone used by Trump officials

#180
post #64

There’s chatter on bsky. But tl;dr anything said on those phones is assumed to be compromised until proven otherwise by time or a whole lot of very interesting security verifications. So far the evidence that this is a very large leak looks probable based on the evidence presented.

(this was originally a reply to https://news.ycombinator.com/item?id=43890827 but since it's an on-topic comment, I moved it to the merged thread)
Post reply on HN