Live data from Hacker News

Technical analysis of the Signal clone used by Trump officials

micahflee.com

251–260 of 387 posts

Re: Technical analysis of the Signal clone used by Trump officials

#251

To me the shocking thing about the USA Gov't is that they manage to lose trillions in the defense dept that they can't account for, but somehow are unable to develop their own communications apps? What? Signing messages with a crypto key takes like 4 lines of code. It's not rocket science. Yet they use some corporate app? My only theory is that they're pretending to have only 'Signal' so that when they want to they c…

There are 2 secure messaging apps in the US govt according to reporting. But I dunno maybe they didn't have emojis....

Re: Technical analysis of the Signal clone used by Trump officials

#252

To me the shocking thing about the USA Gov't is that they manage to lose trillions in the defense dept that they can't account for, but somehow are unable to develop their own communications apps? What? Signing messages with a crypto key takes like 4 lines of code. It's not rocket science. Yet they use some corporate app? My only theory is that they're pretending to have only 'Signal' so that when they want to they c…

There are 2 secure messaging apps in the US govt according to reporting. But I dunno maybe they didn't have emojis....

I heard they use "Signal" as an official app. That blew my mind. Sure they must have others, but why are they even allowed to use commercial apps at all? That's insane.

Re: Technical analysis of the Signal clone used by Trump officials

#253
Is Signal allowing arbitrary apps to connect to its network? How do I know that my correspondent is using TM Sgnl or another unofficial app?

Doesn't that break Signal's security guarantees? For example, what if I set my message to delete in 1 hour but TM Sgnl archives it, or some other app simply ignores the retention setting?

If Signal allows it, it seems like a major vulnerability? I suppose I must trust other users - they could always screenshot a conversation. But while I trust them not to intentionally cheat me, I shouldn't have to trust them to accurately evaluate the security implementation of a software application - something most people can't do, Mike Waltz being the most famous example.

Maybe Signal should identify users unofficial clients. A downside is that it would provide significant identifying information - few people use unofficial apps.

Re: Technical analysis of the Signal clone used by Trump officials

#254

Earlier quoted context omitted.

I don't think it follows that they selected the archiving messenger because they wanted disappearing messages. The whole disappearing messages thing was just internet speculation.

No it was reported by the journalist who was in the chat. > Waltz set some of the messages in the Signal group to disappear after one week https://www.theatlantic.com/politics/archive/2025/03/trump-a...

[deleted]

Re: Technical analysis of the Signal clone used by Trump officials

#255
post #253

Is Signal allowing arbitrary apps to connect to its network? How do I know that my correspondent is using TM Sgnl or another unofficial app? Doesn't that break Signal's security guarantees? For example, what if I set my message to delete in 1 hour but TM Sgnl archives it, or some other app simply ignores the retention setting? If Signal allows it, it seems like a major vulnerability? I suppose I must trust other user…

> Doesn't that break Signal's security guarantees? For example, what if I set my message to delete in 1 hour but TM Sgnl archives it, or some other app simply ignores the retention setting?

Disappearing messages has never been a security guarantee of Signal. People can always archive things their own way (screenshots in the worst case). It's just a convenience feature, not a security thing.

Re: Technical analysis of the Signal clone used by Trump officials

#256
post #181
post #141

See also: " The Signal Clone the Trump Admin Uses Was Hacked " https://www.404media.co/the-signal-clone-the-trump-admin-use...

See also https://news.ycombinator.com/item?id=43890179 for discussion of whether that article should count as a follow-up or SNI. Normally I wouldn't link to meta discussion but this was such a weird borderline case that I spent over an hour trying to figure it out. Maybe that makes it interesting. Edit: in case anyone's confused about the sequence here, micahflee posted the current thread 2 days ago. The timestamp a…

FWIW, I never clicked into this when I originally saw it because I'm not that interested in a "technical analysis", but gained interest when the other title said that the app was hacked. To me, that's worth discussing, but here that lede is a bit buried. And I now only know about it because a friend sent me the link.

I do feel there's a pattern of me reading some interesting tech news, then thinking "wait, why didn't I see this discussed on HN?", to searching for it and finding a buried/flagged HN discussion due to it being somewhat tied to politics (what isn't?)

Re: Technical analysis of the Signal clone used by Trump officials

#257

Earlier quoted context omitted.

> I don't think it's that big: USG procures defense and intelligence tech more or less constantly from Israel. It's unlikely that Israel would threaten that relationship (and the value they extract from it in terms of favorable relations) in exchange for military intelligence that's already shared with them. Correct - they would not use that intelligence to threaten that relationship, but to maintain it. Knowing the…

The over/under there doesn't make sense: the US hasn't had a meaningfully hostile-to-Israel policy ever , so pervasively tapping some of the most sensitive USG communications would be a stunning risk to take with a very safe ally. (It also beggars belief in the current climate -- I would be hard-pressed to name a single member of the current administration who hasn't yelled until purple in the face about their suppor…

Really?

https://en.wikipedia.org/wiki/Jonathan_Pollard

Re: Technical analysis of the Signal clone used by Trump officials

#258

Earlier quoted context omitted.

A few decades ago, the Republican party had one foot in the anti-intellectual camp, but only one. They were the party of young-earth creationists, religious pro-lifers, climate-deniers and gun-lovers - but also of educated fiscally conservative folks. The party would welcome economics professors and leaders of medium-sized businesses, promising no radical changes, no big increases in spending or regulation, and a gen…

What's anti-intellectual about religious pro-lifers?

Their take on scripture is deliberately anachronistic. We didn’t have the medicine or sanitation 2000 years ago to place their kind of value on a fetus.

Re: Technical analysis of the Signal clone used by Trump officials

#259

Earlier quoted context omitted.

It would have to be approved; there is no way for lay-users to install/configure TM-SGNL in their own; it needs to be deployed via MDM. Source: I'm the admin who installs TM-SGNL for many users.

> Source: I'm the admin who installs TM-SGNL for many users. So... is it properly open source?

I felt the writer implied open source code was a bad/insecure thing, since they downloaded a zip file from some WordPress upload folder. I'm guessing the code was being made available to companies that "legally" obtained TM-SGNL.

His repo, not theirs: https://github.com/micahflee/TM-SGNL-Android/commits/master/

He points out that "You must license the entire work, as a whole, under this License to anyone who comes into possession of a copy."

Re: Technical analysis of the Signal clone used by Trump officials

#260

Earlier quoted context omitted.

The over/under there doesn't make sense: the US hasn't had a meaningfully hostile-to-Israel policy ever , so pervasively tapping some of the most sensitive USG communications would be a stunning risk to take with a very safe ally. (It also beggars belief in the current climate -- I would be hard-pressed to name a single member of the current administration who hasn't yelled until purple in the face about their suppor…

Really? https://en.wikipedia.org/wiki/Jonathan_Pollard

You'll note that this case caused exactly the kind of outcome I'm talking about: Pollard was an anomaly (to my knowledge, the only recorded case of a US citizen spying for a US ally) whose activities caused a massive intelligence break between US and Israel that lasted for years and probably did more damage than "good" it served for Israel's intelligence apparatus[1]. That kind of lesson is hard-learned and probably not forgotten, regardless of the fact that Pollard is a poster-boy in Israel's version of a culture war.

[1]: https://www.thedailybeast.com/israeli-spies-arent-exactly-re...

Post reply on HN