Live data from Hacker News

Technical analysis of the Signal clone used by Trump officials

micahflee.com

281–290 of 387 posts

Re: Technical analysis of the Signal clone used by Trump officials

#281
post #3

The big part of this story which nobody is talking about is the fact that the app is literally controlled by a bunch of “former” Israeli intelligence officers. Who now have what is arguably the worlds most valuable access out of anyone.

I don't think it's that big: USG procures defense and intelligence tech more or less constantly from Israel. It's unlikely that Israel would threaten that relationship (and the value they extract from it in terms of favorable relations) in exchange for military intelligence that's already shared with them. (I feel like I have to say this in every thread that insinuates something sinister about being a "former Israeli…

[flagged]

Re: Technical analysis of the Signal clone used by Trump officials

#282

what is going on in the US gov IT? They took an Israeli app, that is a modified version of signal. the modification BREAKS the one thing signal is excellent at (keeping your messages encrypted so that only the desired endpoints can read them), then distributed it within the US Gov. This is insanity! US's enemy's couldn't manufacture a better result themselves!

[flagged]

Re: Technical analysis of the Signal clone used by Trump officials

#283
post #271

OK, so now a foreign power has dirt on senior US officials as well as operational details about their plans. The first possibility leads to blackmail, the second to defeat, and both to scandal.

As far as I know, there is no mechanism in the US for this to be a scandal or a -gate, or for punitive accountability, due to the parties involved. It will be a bit of a story for a few days then swept under the rug based on precedent.

Re: Technical analysis of the Signal clone used by Trump officials

#284
post #220

Earlier quoted context omitted.

> cracked WhatsApp binaries On a more meta note, I wonder who even works at companies founded on ideas that are just... bad. On average, I expect good engineers to push back on such business requirements and also have better job mobility so they can leave and work elsewhere. The researcher found the vulnerabilities "in less than 30 minutes" so it seems there's some lack of competence here. Unfortunately, misguided bu…

Casinos, scams (both of these Web3 as well as traditional), game hack developers, ransomware and database hackers. Adtech, which thousands of HNers work in (anyone at Google). Temu, Shein, gacha/lootbox games, dopamine drug dealers (Meta, Bytedance). NSO group, spyware. Policeware, Clearview, surveillance tech. You could name defense as well, but I find that more ambiguous. I wouldn't be surprised if it at least 25%…

The reality is that its a dog eat dog world out there. I know people who worked in adtech. Yeah, they thought it sucked too and was boring stupid work compared to doing something cool. But it paid the bills, and interesting work is hard to land even without having to pivot into it mid career.

Re: Technical analysis of the Signal clone used by Trump officials

#285

Earlier quoted context omitted.

> What am I missing here? OK, say you're a bank. The SEC states you need to keep archives of every discussion your traders have with anyone at any time (I'm simplifying things but you get the point). You keep getting massive fines because traders were whatsapping about deals So now you've got several options - you can use MS Teams, which of course offers archival, compliance monitoring etc. But that means trusting MS…

Is it a coincidence that it reads almost exactly like SMERSH? https://en.wikipedia.org/wiki/SMERSH

[deleted]

Re: Technical analysis of the Signal clone used by Trump officials

#286

Earlier quoted context omitted.

Is it a coincidence that it reads almost exactly like SMERSH? https://en.wikipedia.org/wiki/SMERSH

Probably coincidence. The founder of the company was named Stephen Marsh.

There's a point at which coincidence and opportunity meet.

Re: Technical analysis of the Signal clone used by Trump officials

#287
post #181
post #141

See also: " The Signal Clone the Trump Admin Uses Was Hacked " https://www.404media.co/the-signal-clone-the-trump-admin-use...

See also https://news.ycombinator.com/item?id=43890179 for discussion of whether that article should count as a follow-up or SNI. Normally I wouldn't link to meta discussion but this was such a weird borderline case that I spent over an hour trying to figure it out. Maybe that makes it interesting. Edit: in case anyone's confused about the sequence here, micahflee posted the current thread 2 days ago. The timestamp a…

Imo it's a brand new thing so it deserves this technical analysis, the follow up also deserves its own post because of its both importance and political/security nature (government app attacked).

It would be if Google announced Gmail and there was a technical analysis and then it was hacked the same day, I would hope there would be a post for that.

Re: Technical analysis of the Signal clone used by Trump officials

#288
post #253

Is Signal allowing arbitrary apps to connect to its network? How do I know that my correspondent is using TM Sgnl or another unofficial app? Doesn't that break Signal's security guarantees? For example, what if I set my message to delete in 1 hour but TM Sgnl archives it, or some other app simply ignores the retention setting? If Signal allows it, it seems like a major vulnerability? I suppose I must trust other user…

If it quacks like the official Signal client, there's no way for the Signal network to know that it's otherwise.

Re: Technical analysis of the Signal clone used by Trump officials

#289
Speculation, as no 'technical' analysis could be performed without access to the actual binaries. These aplications are unlisted and otherwise assigned to organisations using device management. This analysis is based on documentation and how this assignment process works. There is no way to determine if an original application got modified, as this would be the same for the WeChat, WhatsApp applications, or that they recompiled the open source version?

Re: Technical analysis of the Signal clone used by Trump officials

#290
post #253

Is Signal allowing arbitrary apps to connect to its network? How do I know that my correspondent is using TM Sgnl or another unofficial app? Doesn't that break Signal's security guarantees? For example, what if I set my message to delete in 1 hour but TM Sgnl archives it, or some other app simply ignores the retention setting? If Signal allows it, it seems like a major vulnerability? I suppose I must trust other user…

> Doesn't that break Signal's security guarantees? For example, what if I set my message to delete in 1 hour but TM Sgnl archives it, or some other app simply ignores the retention setting? Disappearing messages has never been a security guarantee of Signal. People can always archive things their own way (screenshots in the worst case). It's just a convenience feature, not a security thing.

I see responses like yours quite often. They are correct, of course, but if users keep getting confused about it, may be the UX is bad.

People have been requesting various changes to this feature for years, but hear crickets from Signal.

Post reply on HN