Live data from Hacker News

Technical analysis of the Signal clone used by Trump officials

micahflee.com

231–240 of 387 posts

Re: Technical analysis of the Signal clone used by Trump officials

#231

Earlier quoted context omitted.

> If you don't trust the people in your chat, they shouldn't be in your chat. I assure you, none of these people trust each other. Backstabbing is normal. They're also likely using it to talk to foreign counterparts. Again, most of whom they don't trust a bit. Encryption isn't just about "do I trust the recipient".

You are conflating levels of trust. The trust level required with Signal is, "do I trust the people in this chat not to share the specific communications I am sending to them with some other party whom I do not want to have a copy ". There are many many situations where this level of trust applies that "trust" in the general sense does not apply. It is a useful property. And if you don't have that level of trust, don…

> This is a categorical and demonstrably material difference in security model. I do not understand why so many are claiming it is not.

Because all it takes is one user to decide they trust the third party.

Right now you actually have to do more than trust everyone, you have to trust everyone they trust with their chat history. Which already can include this sort of third party.

Re: Technical analysis of the Signal clone used by Trump officials

#232

Earlier quoted context omitted.

Not part of Signal's security model, but trusting people in that chat very much can and should be part of the user's security model. If you don't trust them, why are they in the chat in the first place?

It's not a person in the chat, it's an account. The account is usually controlled by the person associated with it, but you can't assume that it's always controlled by that person.

Is it though? I think TM Signal is just emailing the chats to a server from the phone it's installed on.

Re: Technical analysis of the Signal clone used by Trump officials

#233

Earlier quoted context omitted.

Is it a coincidence that it reads almost exactly like SMERSH? https://en.wikipedia.org/wiki/SMERSH

Probably not. It's trendy to give edgy names to companies. See: Palintir.

You mean Palantir

Re: Technical analysis of the Signal clone used by Trump officials

#234

White House communications director previously revealed (after “Signalgate”) that Signal was an approved and whitelisted app for gov’t officials to have on work phones and even discuss top-secret matters on. But I haven’t heard that TeleMessage was approved (and I’d have serious questions if it were given the foreign intelligence factor). Anyone know if there is a clear answer to whether it’s been approved?

It would have to be approved; there is no way for lay-users to install/configure TM-SGNL in their own; it needs to be deployed via MDM. Source: I'm the admin who installs TM-SGNL for many users.

> Source: I'm the admin who installs TM-SGNL for many users.

So... is it properly open source?

Re: Technical analysis of the Signal clone used by Trump officials

#235
post #148

Earlier quoted context omitted.

According to this tweet the government contract for the software was originally from 8/24 during the Biden administration: https://x.com/_MG_/status/1918148557670105354

Can you quote the contents of this tweet for those of us without Twitter accounts?

Just replace x.com with xcancel.com

Re: Technical analysis of the Signal clone used by Trump officials

#236

Earlier quoted context omitted.

> I don't think it's that big: USG procures defense and intelligence tech more or less constantly from Israel. It's unlikely that Israel would threaten that relationship (and the value they extract from it in terms of favorable relations) in exchange for military intelligence that's already shared with them. Correct - they would not use that intelligence to threaten that relationship, but to maintain it. Knowing the…

The over/under there doesn't make sense: the US hasn't had a meaningfully hostile-to-Israel policy ever , so pervasively tapping some of the most sensitive USG communications would be a stunning risk to take with a very safe ally. (It also beggars belief in the current climate -- I would be hard-pressed to name a single member of the current administration who hasn't yelled until purple in the face about their suppor…

Everyone is tapping everyone else to the extent they can get away with it - especially allies, because they can get away with it more. You don't think the NSA monitors every single bit that flows in and out of the USA?

Periodically, someone gets caught red-handed, a fuss is made, some diplomats get thrown out and replaced with other ones, and then everyone continues doing it.

Re: Technical analysis of the Signal clone used by Trump officials

#237
post #227

Earlier quoted context omitted.

That's an old article. According to Apple docs, Advanced Data Protection covers Device and Messages backups, which means they are E2EE.

Correct, but nobody turns it on because it’s opt in, and even if you turn it on, 100% of your iMessages will still be escrowed in a form readable to Apple due to the fact that the other ends of your iMessage conversations won’t have ADP enabled because it’s off by default. Again, Apple gets to say “we have e2ee, any user who wants it can turn it on” and the FBI gets to read 100% of the texts in the country unimpeded.…

And yet, it's somehow so effective that it's illegal in the UK because it doesn't let the government read everyone's messages.

Re: Technical analysis of the Signal clone used by Trump officials

#238

Earlier quoted context omitted.

> I don't think it's that big: USG procures defense and intelligence tech more or less constantly from Israel. It's unlikely that Israel would threaten that relationship (and the value they extract from it in terms of favorable relations) in exchange for military intelligence that's already shared with them. Correct - they would not use that intelligence to threaten that relationship, but to maintain it. Knowing the…

The over/under there doesn't make sense: the US hasn't had a meaningfully hostile-to-Israel policy ever , so pervasively tapping some of the most sensitive USG communications would be a stunning risk to take with a very safe ally. (It also beggars belief in the current climate -- I would be hard-pressed to name a single member of the current administration who hasn't yelled until purple in the face about their suppor…

They have never had a hostile-to-Israel policy and never will because of the leverage Israel has over US politicians.

There's a reason the US bought this app from Israelis, and it wasn't because of improved security or archive compliance.

For how much they like to beat the "buy American" drum, this contradicts that.

Re: Technical analysis of the Signal clone used by Trump officials

#239
post #82
post #77

Earlier quoted context omitted.

There are compliance reasons where you want the communications encrypted in flight, but need them retained at rest for compliance reasons. Federal record keeping laws would otherwise prohibit the use of a service like Signal. I'm honestly impressed that the people involved actually took the extra effort for compliance when nothing else they did was above board...

> There are compliance reasons Makes sense. But still debatable if the compliance requirements are acting against the security model or perhaps there are biggest concerns here than just secure communication.

[deleted]

Re: Technical analysis of the Signal clone used by Trump officials

#240

Earlier quoted context omitted.

It would have to be approved; there is no way for lay-users to install/configure TM-SGNL in their own; it needs to be deployed via MDM. Source: I'm the admin who installs TM-SGNL for many users.

Would be interesting to dump the app binaries so people can take a look at how its put together, I suspect its a minefield of sloppy injection functions into how signal works.

Signal is open source for the client, no one is doing work they don't have to cracking a binary you can just compile.
Post reply on HN