Live data from Hacker News

Technical analysis of the Signal clone used by Trump officials

micahflee.com

291–300 of 387 posts

Re: Technical analysis of the Signal clone used by Trump officials

#291
post #289

Speculation, as no 'technical' analysis could be performed without access to the actual binaries. These aplications are unlisted and otherwise assigned to organisations using device management. This analysis is based on documentation and how this assignment process works. There is no way to determine if an original application got modified, as this would be the same for the WeChat, WhatsApp applications, or that they…

There are images from the user's screen, with him on the photograph using the application, showing the chats from the app reproduced verbatim (forwarded) to a GMail account.

The article states that "at least one line of code must've been added" to support such a feature, which I believe to be an honest and accurate assessment.

Re: Technical analysis of the Signal clone used by Trump officials

#292
post #288
post #253

Is Signal allowing arbitrary apps to connect to its network? How do I know that my correspondent is using TM Sgnl or another unofficial app? Doesn't that break Signal's security guarantees? For example, what if I set my message to delete in 1 hour but TM Sgnl archives it, or some other app simply ignores the retention setting? If Signal allows it, it seems like a major vulnerability? I suppose I must trust other user…

If it quacks like the official Signal client, there's no way for the Signal network to know that it's otherwise.

There are many solutions to this problem, such as cryptographic signatures.

Re: Technical analysis of the Signal clone used by Trump officials

#293
post #253

Is Signal allowing arbitrary apps to connect to its network? How do I know that my correspondent is using TM Sgnl or another unofficial app? Doesn't that break Signal's security guarantees? For example, what if I set my message to delete in 1 hour but TM Sgnl archives it, or some other app simply ignores the retention setting? If Signal allows it, it seems like a major vulnerability? I suppose I must trust other user…

There's no way for Signal to prevent any piece of code that can make a TCP connection and speak its protocol from using the service.

Why not require keys signed with Signal's private key?

Re: Technical analysis of the Signal clone used by Trump officials

#294
post #253

Is Signal allowing arbitrary apps to connect to its network? How do I know that my correspondent is using TM Sgnl or another unofficial app? Doesn't that break Signal's security guarantees? For example, what if I set my message to delete in 1 hour but TM Sgnl archives it, or some other app simply ignores the retention setting? If Signal allows it, it seems like a major vulnerability? I suppose I must trust other user…

> Doesn't that break Signal's security guarantees? For example, what if I set my message to delete in 1 hour but TM Sgnl archives it, or some other app simply ignores the retention setting? Disappearing messages has never been a security guarantee of Signal. People can always archive things their own way (screenshots in the worst case). It's just a convenience feature, not a security thing.

> Disappearing messages has never been a security guarantee of Signal.

What makes you say that? Has Signal posted something about it?

Retention settings are widely used for messaging security.

Also, I just used retention as an example. There could be many other holes in the unofficial client, including how it communicates with the Signal network. Maybe my messages aren't E2EE when communicating with that client. Maybe the mess up the encrytion implementation.

Re: Technical analysis of the Signal clone used by Trump officials

#296
post #253

Is Signal allowing arbitrary apps to connect to its network? How do I know that my correspondent is using TM Sgnl or another unofficial app? Doesn't that break Signal's security guarantees? For example, what if I set my message to delete in 1 hour but TM Sgnl archives it, or some other app simply ignores the retention setting? If Signal allows it, it seems like a major vulnerability? I suppose I must trust other user…

The question is - how do you intend to verify whether an application is official or unofficial? What's stopping the official application to be 'patched' with a fake signature feigning validity?

Asymmetric cryptography?

Re: Technical analysis of the Signal clone used by Trump officials

#297
post #289

Speculation, as no 'technical' analysis could be performed without access to the actual binaries. These aplications are unlisted and otherwise assigned to organisations using device management. This analysis is based on documentation and how this assignment process works. There is no way to determine if an original application got modified, as this would be the same for the WeChat, WhatsApp applications, or that they…

There are images from the user's screen, with him on the photograph using the application, showing the chats from the app reproduced verbatim (forwarded) to a GMail account. The article states that "at least one line of code must've been added" to support such a feature, which I believe to be an honest and accurate assessment.

But it is unknown if the current version was modified to do so. As the name "TM SGNL" looks shortened to fit after hex editing the app. This can all have been achieved by library overloads etc.

> One line

This can also be a single JMP and RTS statement, to a function that makes a screenshot, or something that takes the message.

No technical analysis of a working application has been performed. Just speculation of how this could work. I am not saying Micah is wrong. I just hoped more was available, so an actual disassemble was possible.

I would speculate that they did not recompile from source, but used the same process as used by the other applications. Intrusive by modification of the code execution, by injection, etc. That is speculation from my end, but reuses similar approaches across all of their applications.

Re: Technical analysis of the Signal clone used by Trump officials

#298
post #287
post #181

Earlier quoted context omitted.

See also https://news.ycombinator.com/item?id=43890179 for discussion of whether that article should count as a follow-up or SNI. Normally I wouldn't link to meta discussion but this was such a weird borderline case that I spent over an hour trying to figure it out. Maybe that makes it interesting. Edit: in case anyone's confused about the sequence here, micahflee posted the current thread 2 days ago. The timestamp a…

Imo it's a brand new thing so it deserves this technical analysis, the follow up also deserves its own post because of its both importance and political/security nature (government app attacked). It would be if Google announced Gmail and there was a technical analysis and then it was hacked the same day, I would hope there would be a post for that.

See https://news.ycombinator.com/item?id=43896978 for why we didn't do that.

Short version: it's not possible to have separate discussions in the way you describe. They would just get totally blended.

I like your Gmail analogy but I don't think it applies here. The "technical analysis" article is driven by the same political/security concerns as the "hacked" update.

Re: Technical analysis of the Signal clone used by Trump officials

#299
post #294

Earlier quoted context omitted.

> Doesn't that break Signal's security guarantees? For example, what if I set my message to delete in 1 hour but TM Sgnl archives it, or some other app simply ignores the retention setting? Disappearing messages has never been a security guarantee of Signal. People can always archive things their own way (screenshots in the worst case). It's just a convenience feature, not a security thing.

> Disappearing messages has never been a security guarantee of Signal. What makes you say that? Has Signal posted something about it? Retention settings are widely used for messaging security. Also, I just used retention as an example. There could be many other holes in the unofficial client, including how it communicates with the Signal network. Maybe my messages aren't E2EE when communicating with that client. Mayb…

> What makes you say that? Has Signal posted something about it?

I mean, if you want Signal's blog post where they introduced it, it's here: https://signal.org/blog/disappearing-messages/

But also, of course Signal hasn't promised that if they're remotely competent, because that's impossible. You can't stop people from retaining messages if they want to. Now perhaps they're not remotely competent, but in reality they do know better.

> Retention settings are widely used for messaging security.

I mean, maybe people think they're using it for that, but regardless of the context, it will not provide any actual security, because that's impossible! Your recipient could get out a camera and take a photograph if that's what it comes to.

Re: Technical analysis of the Signal clone used by Trump officials

#300
post #219

Earlier quoted context omitted.

> What am I missing here? OK, say you're a bank. The SEC states you need to keep archives of every discussion your traders have with anyone at any time (I'm simplifying things but you get the point). You keep getting massive fines because traders were whatsapping about deals So now you've got several options - you can use MS Teams, which of course offers archival, compliance monitoring etc. But that means trusting MS…

Huh? If the goal is compliance, you wouldn't use something that's worse for compliance - which is why the Legal and Security wouldn't like it. If it helped with compliance, they'd love it! So the reason can't be compliance.

Sounds like you've never done compliance.
Post reply on HN