Live data from Hacker News

Technical analysis of the Signal clone used by Trump officials

micahflee.com

221–230 of 387 posts

Re: Technical analysis of the Signal clone used by Trump officials

#221
post #3

The big part of this story which nobody is talking about is the fact that the app is literally controlled by a bunch of “former” Israeli intelligence officers. Who now have what is arguably the worlds most valuable access out of anyone.

I don't think it's that big: USG procures defense and intelligence tech more or less constantly from Israel. It's unlikely that Israel would threaten that relationship (and the value they extract from it in terms of favorable relations) in exchange for military intelligence that's already shared with them. (I feel like I have to say this in every thread that insinuates something sinister about being a "former Israeli…

I’m saying this as someone who almost certainly has a lot more knowledge about intelligence and the US / Israeli relationship than you do.

While some of the points you make are indeed correct it actually paints an inaccurate overall picture.

For example: not widely known but 100% true, Israel is and has been for a long time classified as the highest level of counterintelligence threat to the US on par with China, Russia, Cuba and others.

I assure you, this is a big fucking deal and not something to be waved away with “everyone’s intel, don’t worry it’s probably nothing”.

Re: Technical analysis of the Signal clone used by Trump officials

#222
post #219

Earlier quoted context omitted.

> What am I missing here? OK, say you're a bank. The SEC states you need to keep archives of every discussion your traders have with anyone at any time (I'm simplifying things but you get the point). You keep getting massive fines because traders were whatsapping about deals So now you've got several options - you can use MS Teams, which of course offers archival, compliance monitoring etc. But that means trusting MS…

Huh? If the goal is compliance, you wouldn't use something that's worse for compliance - which is why the Legal and Security wouldn't like it. If it helped with compliance, they'd love it! So the reason can't be compliance.

The goal is the appearance of compliance, not actual compliance. Check the boxes.

Re: Technical analysis of the Signal clone used by Trump officials

#223
post #216
post #72

Still trying to grasp the idea of archiving messages from E2E encrypted communication system into a storage that entirely breaks the purpose of using something like Signal. It’s like encashing on the trust of Signal protocol, app while breaking its security model so that someone else can search through all messages. What am I missing here?

One of the most popular “e2ee” communication systems, iMessage, does exactly this each night when the iMessage user’s phone backs up its endpoint keys or its iMessage history to Apple in a non-e2ee fashion. This allows Apple (and the US intelligence community, including FBI/DHS) to surveil approximately 100% of all non-China iMessages in close to realtime (in the usual case where it’s set to backup cross-device iMess…

I suppose if both you and the recipient have cloud backups disabled, then Apple can no longer view your messages.

But outside of that scenario, is there any advantage to iMessage using e2ee instead of just regular TLS?

Edit: Apparently it's up to you whether you want your iCloud backups to use e2ee. There's an account setting: https://support.apple.com/en-us/102651. Standard protection is a sensible default for regular who aren't tech-savvy, as with e2ee they're at risk of losing all their iCloud data if they lose their key.

Re: Technical analysis of the Signal clone used by Trump officials

#224
post #167

Earlier quoted context omitted.

[flagged]

>Some minor spying would not even register. I mean, they stole weapons grade Uranium from United States along with nuclear secrets and we just shrugged our shoulders: https://www.theguardian.com/world/2014/jan/15/truth-israels-...

People here will flag easily searchable/verifiable information about what Israel did to the US in the past, just to protect the image of the US or whatever.

Well, guess what, it doesn't work. It's just stupid.

Re: Technical analysis of the Signal clone used by Trump officials

#225
post #216
post #72

Still trying to grasp the idea of archiving messages from E2E encrypted communication system into a storage that entirely breaks the purpose of using something like Signal. It’s like encashing on the trust of Signal protocol, app while breaking its security model so that someone else can search through all messages. What am I missing here?

One of the most popular “e2ee” communication systems, iMessage, does exactly this each night when the iMessage user’s phone backs up its endpoint keys or its iMessage history to Apple in a non-e2ee fashion. This allows Apple (and the US intelligence community, including FBI/DHS) to surveil approximately 100% of all non-China iMessages in close to realtime (in the usual case where it’s set to backup cross-device iMess…

That's an old article. According to Apple docs, Advanced Data Protection covers Device and Messages backups, which means they are E2EE.

Re: Technical analysis of the Signal clone used by Trump officials

#226
post #167

Earlier quoted context omitted.

[flagged]

I would absolutely put "Israel taps the National Security Advisor's phone" in a different category of risk to the two country's relationship than previous activities. This, again, isn't a normative argument. (A piece of context that's often missing from - typically charged - discussions about US/Israel relationships is the degree of dependence between the two, and how that's varied over the years. Israel's defense po…

What makes you think it didn't already do so in the past and thus is a new thing? Allies spy on each other all the time.

I guess US gov would not like to have it be out publicly, but they must understand that this is being at least attempted and US likely does it to Israel, too.

https://www.timesofisrael.com/new-nsa-document-highlights-is...

Re: Technical analysis of the Signal clone used by Trump officials

#227
post #216

Earlier quoted context omitted.

One of the most popular “e2ee” communication systems, iMessage, does exactly this each night when the iMessage user’s phone backs up its endpoint keys or its iMessage history to Apple in a non-e2ee fashion. This allows Apple (and the US intelligence community, including FBI/DHS) to surveil approximately 100% of all non-China iMessages in close to realtime (in the usual case where it’s set to backup cross-device iMess…

That's an old article. According to Apple docs, Advanced Data Protection covers Device and Messages backups, which means they are E2EE.

Correct, but nobody turns it on because it’s opt in, and even if you turn it on, 100% of your iMessages will still be escrowed in a form readable to Apple due to the fact that the other ends of your iMessage conversations won’t have ADP enabled because it’s off by default.

Again, Apple gets to say “we have e2ee, any user who wants it can turn it on” and the FBI gets to read 100% of the texts in the country unimpeded.

If Apple really wanted to promote privacy, they’d have deployed the so-called “trust circle” system they designed and implemented which allowed a quorum of trusted contacts to use their own keys to allow you to recover your account e2ee keys without Apple being able to access it, rolled that out, and then slowly migrated their entire user base over to e2ee backups.

They have not, and they will not, because that will compromise the surveillance backdoor, and get them regulated upon, or worse. The current administration has already shown that they are willing to impose insanely steep tariffs on the iPhone.

You can’t fight city hall, you don’t need a weatherman to know which way the wind blows, etc. The US intelligence community has a heart attack gun. Tim Apple does not.

Separately it is an interesting aside that Apple’s 1A rights are being violated here by the presumptive retaliation should they publish such a migration feature (software code being protected speech).

Re: Technical analysis of the Signal clone used by Trump officials

#228
post #216

Earlier quoted context omitted.

One of the most popular “e2ee” communication systems, iMessage, does exactly this each night when the iMessage user’s phone backs up its endpoint keys or its iMessage history to Apple in a non-e2ee fashion. This allows Apple (and the US intelligence community, including FBI/DHS) to surveil approximately 100% of all non-China iMessages in close to realtime (in the usual case where it’s set to backup cross-device iMess…

That's an old article. According to Apple docs, Advanced Data Protection covers Device and Messages backups, which means they are E2EE.

Are there any stats as to the percentage of iPhone users that enable Advanced Data Protection? Defaults matter a lot, and I wouldn't be surprised if that number is (well) below 10%.

If you are the only person out of all the people you correspond with who has ADP enabled, then everyone you correspond with is uploading the plaintext of your messages to Apple.

Re: Technical analysis of the Signal clone used by Trump officials

#229
post #221

Earlier quoted context omitted.

I don't think it's that big: USG procures defense and intelligence tech more or less constantly from Israel. It's unlikely that Israel would threaten that relationship (and the value they extract from it in terms of favorable relations) in exchange for military intelligence that's already shared with them. (I feel like I have to say this in every thread that insinuates something sinister about being a "former Israeli…

I’m saying this as someone who almost certainly has a lot more knowledge about intelligence and the US / Israeli relationship than you do. While some of the points you make are indeed correct it actually paints an inaccurate overall picture. For example: not widely known but 100% true, Israel is and has been for a long time classified as the highest level of counterintelligence threat to the US on par with China, Rus…

I'm not saying it's not a big deal. It obviously is.

I'm saying that the fact that it's Israeli tech is not itself the biggest part of the story.

Re: Technical analysis of the Signal clone used by Trump officials

#230
post #226

Earlier quoted context omitted.

I would absolutely put "Israel taps the National Security Advisor's phone" in a different category of risk to the two country's relationship than previous activities. This, again, isn't a normative argument. (A piece of context that's often missing from - typically charged - discussions about US/Israel relationships is the degree of dependence between the two, and how that's varied over the years. Israel's defense po…

What makes you think it didn't already do so in the past and thus is a new thing? Allies spy on each other all the time. I guess US gov would not like to have it be out publicly, but they must understand that this is being at least attempted and US likely does it to Israel, too. https://www.timesofisrael.com/new-nsa-document-highlights-is...

I'm sure they do. I would expect a little bit more, uh, flair to it than "you bought the spyware from us," though.

My point here is pretty narrow: I'm sure Israel spies on the US, and we spy on them. My only doubt is whether TM SGNL itself is an element of that, or whether it's just another flavor of junk software sold to USG to paper over the gaps between technology and compliance requirements.

Post reply on HN