Live data from Hacker News

Technical analysis of the Signal clone used by Trump officials

micahflee.com

181–190 of 387 posts

Re: Technical analysis of the Signal clone used by Trump officials

#181
post #141

See also: " The Signal Clone the Trump Admin Uses Was Hacked " https://www.404media.co/the-signal-clone-the-trump-admin-use...

See also https://news.ycombinator.com/item?id=43890179 for discussion of whether that article should count as a follow-up or SNI.

Normally I wouldn't link to meta discussion but this was such a weird borderline case that I spent over an hour trying to figure it out. Maybe that makes it interesting.

Edit: in case anyone's confused about the sequence here, micahflee posted the current thread 2 days ago. The timestamp at the top of this page is an artifact of us re-upping it (https://hn.algolia.com/?dateRange=all&page=0&prefix=true&que...).

Re: Technical analysis of the Signal clone used by Trump officials

#182
post #72

Still trying to grasp the idea of archiving messages from E2E encrypted communication system into a storage that entirely breaks the purpose of using something like Signal. It’s like encashing on the trust of Signal protocol, app while breaking its security model so that someone else can search through all messages. What am I missing here?

> What am I missing here? OK, say you're a bank. The SEC states you need to keep archives of every discussion your traders have with anyone at any time (I'm simplifying things but you get the point). You keep getting massive fines because traders were whatsapping about deals So now you've got several options - you can use MS Teams, which of course offers archival, compliance monitoring etc. But that means trusting MS…

> say you're a bank. The SEC states you need to keep archives of every discussion your traders have with anyone at any time

These records are encrypted in storage.

Re: Technical analysis of the Signal clone used by Trump officials

#183
post #38

Earlier quoted context omitted.

There's no "don't change titles" rule, though it's interesting how the actual rule gets truncated to that in people's minds! Here's the actual rule: " Please use the original title, unless it is misleading or linkbait; don't editorialize. " - https://news.ycombinator.com/newsguidelines.html In this case I was thinking of both the 'misleading' and 'linkbait' bits of that 'unless'. (By the way, this is common HN modera…

the "use" assume nothing happened after the report (app still in managed domain). "used" assume an extra action taking place, which is a stretch imo. but i assumed wrong that you added the "d", not that you're only exempting the submitter title. thanks for the insight into your always nice moderation. follow up question: you work seven days a week??

I did add the 'd' but I am sorry to say that all information associated with that instance of that letter has already been flushed out of my memory.

> you work seven days a week??

By no means all day every day, but yes in the sense that my hours get distributed semi-randomly.

Re: Technical analysis of the Signal clone used by Trump officials

#184
post #3

The big part of this story which nobody is talking about is the fact that the app is literally controlled by a bunch of “former” Israeli intelligence officers. Who now have what is arguably the worlds most valuable access out of anyone.

It's not like Israel doesn't already have the highest level of access to the administration's plans. Canada could be made the 51st state and Israel would still have more access to the Trump administrations plans. There is some sort of strong connection between the USA and Israel. What that is, I don't know.

Re: Technical analysis of the Signal clone used by Trump officials

#185
post #72

Still trying to grasp the idea of archiving messages from E2E encrypted communication system into a storage that entirely breaks the purpose of using something like Signal. It’s like encashing on the trust of Signal protocol, app while breaking its security model so that someone else can search through all messages. What am I missing here?

Maybe someone wanted to please the procedure of law but also had to please the bros. The result is a hack of a secure program that adds conversation archiving.

Re: Technical analysis of the Signal clone used by Trump officials

#186

what is going on in the US gov IT? They took an Israeli app, that is a modified version of signal. the modification BREAKS the one thing signal is excellent at (keeping your messages encrypted so that only the desired endpoints can read them), then distributed it within the US Gov. This is insanity! US's enemy's couldn't manufacture a better result themselves!

> US's enemy's couldn't manufacture a better result themselves!

in the game of nationalist geopolitics, it's only a matter of time before a current strategic ally becomes an enemy. it's the natural order of nationalism at global scale.

Re: Technical analysis of the Signal clone used by Trump officials

#188
post #83

Earlier quoted context omitted.

In August last year I got this from dang when reporting a dead 404 link: "The site 404media.co is banned on HN because it has been the source of too many low-quality posts and because many (most?) of their articles are behind a signup wall." Not that I've really seen the low quality and the signup requirement doesn't stop other domains. There's quite a few things that originated from 404, so I hope HN gets over whate…

The main issue is the (sometimes) hard signup wall. I've been a moderator on HN for longer than 404media has existed, and I know from experience that this changes from time to time or article to article. Other paywalled sites that appear on HN (WSJ, NYT etc) have a porous paywall; you can (almost) always get around it by using an archive site like Archive.today. If it's a good article (contains significant new inform…

Even porous paywalls can have a marked effect on story performance on HN.

The New York Times tightened its paywall markedly in August 2019, with a net effect that appearances in the top-30 stories on HN's front-page archive (the "Past" links in the site header) fell to ~25% of their previous level.

I'd asked dang at the time if HN had changed any of its own processes at the time. Apparently not.

I suspect then that this reflects frustrations and/or inability to access posted articles behind the paywall.

See: https://news.ycombinator.com/item?id=36918251> (July 2023)

Re: Technical analysis of the Signal clone used by Trump officials

#189

Earlier quoted context omitted.

You can never control what I do on my device with the message received- I can make screenshots, or, if the app prevents that, take a picture of the screen. The goal of signal is trusted end-to-end encrypted communication. Device/Message security on either end is not in scope for Signals threat model.

TM SGNL changes the security model from "I trust the people in the chat" to "I trust the people in the chat and also the company archiving the chat". If you don't trust the people in your chat, they shouldn't be in your chat.

> If you don't trust the people in your chat, they shouldn't be in your chat.

I assure you, none of these people trust each other. Backstabbing is normal.

They're also likely using it to talk to foreign counterparts. Again, most of whom they don't trust a bit.

Encryption isn't just about "do I trust the recipient".

Re: Technical analysis of the Signal clone used by Trump officials

#190

Earlier quoted context omitted.

Any client-side limitations are not part of the security model because you don't control other people's devices. Even with an unmodified app, they're trivially bypassed using a rooted/jailbroken device.

Not part of Signal's security model, but trusting people in that chat very much can and should be part of the user's security model. If you don't trust them, why are they in the chat in the first place?

> If you don't trust them, why are they in the chat in the first place?

Journalist? Taliban negotiator? Ex-wife?

Post reply on HN