To me the shocking thing about the USA Gov't is that they manage to lose trillions in the defense dept that they can't account for, but somehow are unable to develop their own communications apps? What? Signing messages with a crypto key takes like 4 lines of code. It's not rocket science. Yet they use some corporate app? My only theory is that they're pretending to have only 'Signal' so that when they want to they c…
Technical analysis of the Signal clone used by Trump officials
251–260 of 387 posts
Re: Technical analysis of the Signal clone used by Trump officials
#252To me the shocking thing about the USA Gov't is that they manage to lose trillions in the defense dept that they can't account for, but somehow are unable to develop their own communications apps? What? Signing messages with a crypto key takes like 4 lines of code. It's not rocket science. Yet they use some corporate app? My only theory is that they're pretending to have only 'Signal' so that when they want to they c…
There are 2 secure messaging apps in the US govt according to reporting. But I dunno maybe they didn't have emojis....
Re: Technical analysis of the Signal clone used by Trump officials
#253Doesn't that break Signal's security guarantees? For example, what if I set my message to delete in 1 hour but TM Sgnl archives it, or some other app simply ignores the retention setting?
If Signal allows it, it seems like a major vulnerability? I suppose I must trust other users - they could always screenshot a conversation. But while I trust them not to intentionally cheat me, I shouldn't have to trust them to accurately evaluate the security implementation of a software application - something most people can't do, Mike Waltz being the most famous example.
Maybe Signal should identify users unofficial clients. A downside is that it would provide significant identifying information - few people use unofficial apps.
Re: Technical analysis of the Signal clone used by Trump officials
#254Earlier quoted context omitted.
I don't think it follows that they selected the archiving messenger because they wanted disappearing messages. The whole disappearing messages thing was just internet speculation.
No it was reported by the journalist who was in the chat. > Waltz set some of the messages in the Signal group to disappear after one week https://www.theatlantic.com/politics/archive/2025/03/trump-a...
Re: Technical analysis of the Signal clone used by Trump officials
#255Is Signal allowing arbitrary apps to connect to its network? How do I know that my correspondent is using TM Sgnl or another unofficial app? Doesn't that break Signal's security guarantees? For example, what if I set my message to delete in 1 hour but TM Sgnl archives it, or some other app simply ignores the retention setting? If Signal allows it, it seems like a major vulnerability? I suppose I must trust other user…
Disappearing messages has never been a security guarantee of Signal. People can always archive things their own way (screenshots in the worst case). It's just a convenience feature, not a security thing.
Re: Technical analysis of the Signal clone used by Trump officials
#256See also: " The Signal Clone the Trump Admin Uses Was Hacked " https://www.404media.co/the-signal-clone-the-trump-admin-use...
See also https://news.ycombinator.com/item?id=43890179 for discussion of whether that article should count as a follow-up or SNI. Normally I wouldn't link to meta discussion but this was such a weird borderline case that I spent over an hour trying to figure it out. Maybe that makes it interesting. Edit: in case anyone's confused about the sequence here, micahflee posted the current thread 2 days ago. The timestamp a…
I do feel there's a pattern of me reading some interesting tech news, then thinking "wait, why didn't I see this discussed on HN?", to searching for it and finding a buried/flagged HN discussion due to it being somewhat tied to politics (what isn't?)
Re: Technical analysis of the Signal clone used by Trump officials
#257Earlier quoted context omitted.
> I don't think it's that big: USG procures defense and intelligence tech more or less constantly from Israel. It's unlikely that Israel would threaten that relationship (and the value they extract from it in terms of favorable relations) in exchange for military intelligence that's already shared with them. Correct - they would not use that intelligence to threaten that relationship, but to maintain it. Knowing the…
The over/under there doesn't make sense: the US hasn't had a meaningfully hostile-to-Israel policy ever , so pervasively tapping some of the most sensitive USG communications would be a stunning risk to take with a very safe ally. (It also beggars belief in the current climate -- I would be hard-pressed to name a single member of the current administration who hasn't yelled until purple in the face about their suppor…
Re: Technical analysis of the Signal clone used by Trump officials
#258Earlier quoted context omitted.
A few decades ago, the Republican party had one foot in the anti-intellectual camp, but only one. They were the party of young-earth creationists, religious pro-lifers, climate-deniers and gun-lovers - but also of educated fiscally conservative folks. The party would welcome economics professors and leaders of medium-sized businesses, promising no radical changes, no big increases in spending or regulation, and a gen…
What's anti-intellectual about religious pro-lifers?
Re: Technical analysis of the Signal clone used by Trump officials
#259Earlier quoted context omitted.
It would have to be approved; there is no way for lay-users to install/configure TM-SGNL in their own; it needs to be deployed via MDM. Source: I'm the admin who installs TM-SGNL for many users.
> Source: I'm the admin who installs TM-SGNL for many users. So... is it properly open source?
His repo, not theirs: https://github.com/micahflee/TM-SGNL-Android/commits/master/
He points out that "You must license the entire work, as a whole, under this License to anyone who comes into possession of a copy."
Re: Technical analysis of the Signal clone used by Trump officials
#260Earlier quoted context omitted.
The over/under there doesn't make sense: the US hasn't had a meaningfully hostile-to-Israel policy ever , so pervasively tapping some of the most sensitive USG communications would be a stunning risk to take with a very safe ally. (It also beggars belief in the current climate -- I would be hard-pressed to name a single member of the current administration who hasn't yelled until purple in the face about their suppor…
Really? https://en.wikipedia.org/wiki/Jonathan_Pollard
[1]: https://www.thedailybeast.com/israeli-spies-arent-exactly-re...