Live data from Hacker News

TeleMessage, used by Trump officials, can access plaintext chat logs

micahflee.com

31–40 of 92 posts

Re: TeleMessage, used by Trump officials, can access plaintext chat logs

#32
post #16
post #10

Isn't that the point?

Presumably, in the spectrum of secure network protocols, something exists between "delete the message before it can leave this machine" and "send this message to a cloud provider and have them email it in plain text to another cloud provider".

And Email protocol backbone itself was not designed to be secure.

It's worse than internet packets over HTTPS -- the secure connection is established between client and server, so man-in-the-middle cannot decrypt it. In email, connections are only secure between relays, so any relay can decrypt read your email. You cannot guarantee what relays are used. Similar to SMS.

Re: TeleMessage, used by Trump officials, can access plaintext chat logs

#33

Earlier quoted context omitted.

No, the point is for the government to have access the plaintext after it is securely delivered to an approved archive location, not TeleMessage having access on AWS-hosted servers exposed to the public internet. TeleMessage pitched their service as using end-to-end encryption of the message into the corporate archive. > End-to-End encryption from the mobile phone through to the corporate archive Apparently the plain…

I doubt that’s the point either. The government should have cipher text they are able to decrypt in an approved archive location with rigorously managed key material and a careful cryptographically variable chain of custody from its inception. Plain text should never factor into this.

The US government does have storage facilities and secure messaging tools with escrow, all designed for exactly this use-case (secure messaging amongst DoD personnel.) But the whole point of Signal+TeleMessage was to route around that "clunky stuff" by outsourcing it to a vendor.

Re: TeleMessage, used by Trump officials, can access plaintext chat logs

#34

These are the guys trying to jail Krebs for being honest. They earned the “experts” they deserve.

And still there is ample support for the administration, also here. I am curious how much of it is through cognitive dissonance and how much not thinking too hard about the stuff a particular supporter don't like, and how much of it is with eyes open, embracing the crazy and the incompetence for some "higher goal" whatever that may be.

(It also probably is very different, all from "own the libs" through "escalate the second coming of Christ" or any combination thereof.)

Re: TeleMessage, used by Trump officials, can access plaintext chat logs

#38

Earlier quoted context omitted.

I doubt that’s the point either. The government should have cipher text they are able to decrypt in an approved archive location with rigorously managed key material and a careful cryptographically variable chain of custody from its inception. Plain text should never factor into this.

The US government does have storage facilities and secure messaging tools with escrow, all designed for exactly this use-case (secure messaging amongst DoD personnel.) But the whole point of Signal+TeleMessage was to route around that "clunky stuff" by outsourcing it to a vendor.

I understand the point - the point is people who believe the size of their bank account is proportional to their intelligence and aptitude at everything making flat dumb decisions because, if anything, the relationship is none of not inversely proportional. Their arrogance and eschewing of expertise in favor of magical thinking will end up with a lot of people dead.

Re: TeleMessage, used by Trump officials, can access plaintext chat logs

#39

Earlier quoted context omitted.

No, the point is for the government to have access the plaintext after it is securely delivered to an approved archive location, not TeleMessage having access on AWS-hosted servers exposed to the public internet. TeleMessage pitched their service as using end-to-end encryption of the message into the corporate archive. > End-to-End encryption from the mobile phone through to the corporate archive Apparently the plain…

I doubt that’s the point either. The government should have cipher text they are able to decrypt in an approved archive location with rigorously managed key material and a careful cryptographically variable chain of custody from its inception. Plain text should never factor into this.

The point is that it was supposed to be end-to-end encrypted by this company all the way to the government's archive.

That's what they claimed, but their service did no such thing.

Re: TeleMessage, used by Trump officials, can access plaintext chat logs

#40

Earlier quoted context omitted.

I doubt that’s the point either. The government should have cipher text they are able to decrypt in an approved archive location with rigorously managed key material and a careful cryptographically variable chain of custody from its inception. Plain text should never factor into this.

The US government does have storage facilities and secure messaging tools with escrow, all designed for exactly this use-case (secure messaging amongst DoD personnel.) But the whole point of Signal+TeleMessage was to route around that "clunky stuff" by outsourcing it to a vendor.

There are PIV creds for more than just DoD.
Post reply on HN