Live data from Hacker News

Technical analysis of the Signal clone used by Trump officials

micahflee.com

211–220 of 387 posts

Re: Technical analysis of the Signal clone used by Trump officials

#211

White House communications director previously revealed (after “Signalgate”) that Signal was an approved and whitelisted app for gov’t officials to have on work phones and even discuss top-secret matters on. But I haven’t heard that TeleMessage was approved (and I’d have serious questions if it were given the foreign intelligence factor). Anyone know if there is a clear answer to whether it’s been approved?

The correct answer is no one outside US Government IT knows for sure what is or isn't approved per their own rules. Every article (and comments therein) are just speculation and people trying to confirm their own biases, desperately looking for something to blame someone for, to produce more rage-bait and thus feed more ad clicks. Every single article is written with the presumption that there are no actual IT people…

> The correct answer is no one outside US Government IT knows for sure what is or isn't approved per their own rules

Veterans Affairs actually publishes a list of approved software as part of their Technical Reference Model: https://www.oit.va.gov/services/trm/ (don’t know how complete it is)

But I’m not aware of other agencies doing this. I suppose that VA, given the nature of what they do, likely feels that there is less risk in publicising this information

There’s also the FedRAMP program for centralized review of cloud services - fedramp.gov - I haven’t looked to see if Telemessage is listed as approved but I see some references to FedRAMP and Telemessage online suggesting that it may be

Another source of info is SAM.gov - https://sam.gov/opp/ab5e8a486e074d73bfe09b383ba819ab/view (that’s for NIH) - if there is an agency paying for it, you can assume they’ve approved it for use (or are in the process of doing so) even if they haven’t otherwise publicly said they are. But, not all contracts are public, so just because you can’t find it on SAM.gov doesn’t mean it doesn’t exist

Re: Technical analysis of the Signal clone used by Trump officials

#212
post #3

The big part of this story which nobody is talking about is the fact that the app is literally controlled by a bunch of “former” Israeli intelligence officers. Who now have what is arguably the worlds most valuable access out of anyone.

I know it's pretty fun to do the espionage angle with this comment.

But is this really just evidence that a mandatory draft is actually good economic policy? Having a forced networking event where a bunch of similar skilled individual meet each other seems to be producing a ton of economic value for Israel.

Re: Technical analysis of the Signal clone used by Trump officials

#213

Earlier quoted context omitted.

TM SGNL changes the security model from "I trust the people in the chat" to "I trust the people in the chat and also the company archiving the chat". If you don't trust the people in your chat, they shouldn't be in your chat.

> If you don't trust the people in your chat, they shouldn't be in your chat. I assure you, none of these people trust each other. Backstabbing is normal. They're also likely using it to talk to foreign counterparts. Again, most of whom they don't trust a bit. Encryption isn't just about "do I trust the recipient".

You are conflating levels of trust.

The trust level required with Signal is, "do I trust the people in this chat not to share the specific communications I am sending to them with some other party whom I do not want to have a copy".

There are many many situations where this level of trust applies that "trust" in the general sense does not apply. It is a useful property.

And if you don't have that level of trust, don't put it in writing.

TM SGNL changes the trust required to, "do I also trust this 3rd party not to share the contents of any of my communications, possibly inadvertently due to poor security practices".

This is a categorical and demonstrably material difference in security model. I do not understand why so many are claiming it is not.

Re: Technical analysis of the Signal clone used by Trump officials

#214
post #148

We should all feel relieved that trump admin are following law to archive their chats after all. Unfortunately this Israeli company is just incompetent, should try something from Russia next time, given that’s all the data end up to be anyway.

According to this tweet the government contract for the software was originally from 8/24 during the Biden administration: https://x.com/_MG_/status/1918148557670105354

Can you quote the contents of this tweet for those of us without Twitter accounts?

Re: Technical analysis of the Signal clone used by Trump officials

#215

Earlier quoted context omitted.

> What am I missing here? OK, say you're a bank. The SEC states you need to keep archives of every discussion your traders have with anyone at any time (I'm simplifying things but you get the point). You keep getting massive fines because traders were whatsapping about deals So now you've got several options - you can use MS Teams, which of course offers archival, compliance monitoring etc. But that means trusting MS…

Is it a coincidence that it reads almost exactly like SMERSH? https://en.wikipedia.org/wiki/SMERSH

Probably not. It's trendy to give edgy names to companies. See: Palintir.

Re: Technical analysis of the Signal clone used by Trump officials

#216
post #72

Still trying to grasp the idea of archiving messages from E2E encrypted communication system into a storage that entirely breaks the purpose of using something like Signal. It’s like encashing on the trust of Signal protocol, app while breaking its security model so that someone else can search through all messages. What am I missing here?

One of the most popular “e2ee” communication systems, iMessage, does exactly this each night when the iMessage user’s phone backs up its endpoint keys or its iMessage history to Apple in a non-e2ee fashion.

This allows Apple (and the US intelligence community, including FBI/DHS) to surveil approximately 100% of all non-China iMessages in close to realtime (in the usual case where it’s set to backup cross-device iMessage sync keys).

(China, cleverly, requires Apple to not only store all the Chinese iCloud data in China, but also requires that it happen on machines owned and operated by a joint venture with a Chinese-government-controlled entity, keeping them from having to negotiate continued access to the data the way the FBI did.)

https://www.reuters.com/article/us-apple-fbi-icloud-exclusiv...

Yet Apple can still legitimately claim that iMessage is e2ee, even though the plaintext is being backed up in a way that is readable to them. It’s a backdoor by another name.

Everyone wins: Apple gets to say E2EE, the state gets to surveil the texts of everyone in the whole country without a warrant thanks to FISA.

Re: Technical analysis of the Signal clone used by Trump officials

#217
post #196

Earlier quoted context omitted.

It's not really a knockoff, it's a deliberately cracked version of a B2C app to adapt it to a corporate setting

The Signal client app is open source; it's probably not reasonable to describe a modified version as "cracked". Signal does discourage the use of modified clients for security reasons, but does not actively block most of them.

You’re right for Signal! Their WhatsApp client, however… that’s definitely “cracked”

Re: Technical analysis of the Signal clone used by Trump officials

#218
post #3

The big part of this story which nobody is talking about is the fact that the app is literally controlled by a bunch of “former” Israeli intelligence officers. Who now have what is arguably the worlds most valuable access out of anyone.

I know it's pretty fun to do the espionage angle with this comment. But is this really just evidence that a mandatory draft is actually good economic policy? Having a forced networking event where a bunch of similar skilled individual meet each other seems to be producing a ton of economic value for Israel.

This isn’t a one or the other thing. You’re just bringing up an unrelated point.

Re: Technical analysis of the Signal clone used by Trump officials

#219
post #72

Still trying to grasp the idea of archiving messages from E2E encrypted communication system into a storage that entirely breaks the purpose of using something like Signal. It’s like encashing on the trust of Signal protocol, app while breaking its security model so that someone else can search through all messages. What am I missing here?

> What am I missing here? OK, say you're a bank. The SEC states you need to keep archives of every discussion your traders have with anyone at any time (I'm simplifying things but you get the point). You keep getting massive fines because traders were whatsapping about deals So now you've got several options - you can use MS Teams, which of course offers archival, compliance monitoring etc. But that means trusting MS…

Huh? If the goal is compliance, you wouldn't use something that's worse for compliance - which is why the Legal and Security wouldn't like it. If it helped with compliance, they'd love it! So the reason can't be compliance.

Re: Technical analysis of the Signal clone used by Trump officials

#220

Earlier quoted context omitted.

The scariest part? They also sell to corporations... Read their install guide and weep at the idea of pushing cracked WhatsApp binaires through MDM https://smarsh.my.salesforce.com/sfc/p/#30000001FgxH/a/Pb000...

> cracked WhatsApp binaries On a more meta note, I wonder who even works at companies founded on ideas that are just... bad. On average, I expect good engineers to push back on such business requirements and also have better job mobility so they can leave and work elsewhere. The researcher found the vulnerabilities "in less than 30 minutes" so it seems there's some lack of competence here. Unfortunately, misguided bu…

Casinos, scams (both of these Web3 as well as traditional), game hack developers, ransomware and database hackers. Adtech, which thousands of HNers work in (anyone at Google). Temu, Shein, gacha/lootbox games, dopamine drug dealers (Meta, Bytedance). NSO group, spyware. Policeware, Clearview, surveillance tech. You could name defense as well, but I find that more ambiguous.

I wouldn't be surprised if it at least 25% of HN has worked for such companies for at least 2 years of their career.

Post reply on HN