Live data from Hacker News

TeleMessage, used by Trump officials, can access plaintext chat logs

micahflee.com

51–60 of 92 posts

Re: TeleMessage, used by Trump officials, can access plaintext chat logs

#51
post #43

Earlier quoted context omitted.

We're using words like "should" have access or whatever, but my understanding of the point of these apps is that they allow users to use Signal while keeping compliance archives of messages. They're not cryptographically interesting (or really cryptographic at all). This is more like e-discovery software than secure messaging. If you're using it, cryptography is out the window.

It’s not end-to-end, but that seems a bit exaggerated. An organization will still want encryption in transit, encryption at rest for its archive, and good access control.

In secure messaging as a cryptographic discipline, this is like saying you don't want secure messaging. Secure messaging is end-to-end secure, and the basic core threat modeling of a secure messaging service includes adversaries who defeat transit-only encryption.

All this is to say: it's unremarkable to me that the Signal compliance fork government officials are using, which is premised on the capability of archiving messages, defeats secure messaging. That's literally what it's for.

Re: TeleMessage, used by Trump officials, can access plaintext chat logs

#52

It’s probably against the rules to self-link old comments. And it’s hard to be remotely proud about having a good take on this news as it unfolded. However, when this first broke, select HN users were claiming this was OPSEC 4D chess and not deeply irresponsible cybersec practices. That was a terrible take then, and it’s a terrible take now. Clear as day when this started there was a nasty vendor supply chain risk lu…

> It’s probably against the rules to self-link old comments

It's not against the rules to link past comments - in fact it's preferred to repeating the same or similar content across stories.

At the same time, does 'look, I had the right take once in the past' make for interesting conversation? I'm keen to see it unfold!

Re: TeleMessage, used by Trump officials, can access plaintext chat logs

#53
post #52

It’s probably against the rules to self-link old comments. And it’s hard to be remotely proud about having a good take on this news as it unfolded. However, when this first broke, select HN users were claiming this was OPSEC 4D chess and not deeply irresponsible cybersec practices. That was a terrible take then, and it’s a terrible take now. Clear as day when this started there was a nasty vendor supply chain risk lu…

> It’s probably against the rules to self-link old comments It's not against the rules to link past comments - in fact it's preferred to repeating the same or similar content across stories. At the same time, does 'look, I had the right take once in the past' make for interesting conversation? I'm keen to see it unfold!

I think it's good to compare and contrast the items you got right and wrong in the take and discuss why it did or did not play out that way.

Re: TeleMessage, used by Trump officials, can access plaintext chat logs

#54

It’s probably against the rules to self-link old comments. And it’s hard to be remotely proud about having a good take on this news as it unfolded. However, when this first broke, select HN users were claiming this was OPSEC 4D chess and not deeply irresponsible cybersec practices. That was a terrible take then, and it’s a terrible take now. Clear as day when this started there was a nasty vendor supply chain risk lu…

Brewing? This is it. All of these messages have been leaking; that's what the article is about.

Re: TeleMessage, used by Trump officials, can access plaintext chat logs

#56

It’s probably against the rules to self-link old comments. And it’s hard to be remotely proud about having a good take on this news as it unfolded. However, when this first broke, select HN users were claiming this was OPSEC 4D chess and not deeply irresponsible cybersec practices. That was a terrible take then, and it’s a terrible take now. Clear as day when this started there was a nasty vendor supply chain risk lu…

Brewing? This is it. All of these messages have been leaking; that's what the article is about.

Have you found info on the chat texts?

Referring to “a leak” as in these chats go public in some form vs into a RU SCIF somewhere, and that there’s some verification of what the clear text chats were/who’s in it.

I am speculating it’ll be the latter scenario, with periodic strategic leaks.

Re: TeleMessage, used by Trump officials, can access plaintext chat logs

#57
post #52

It’s probably against the rules to self-link old comments. And it’s hard to be remotely proud about having a good take on this news as it unfolded. However, when this first broke, select HN users were claiming this was OPSEC 4D chess and not deeply irresponsible cybersec practices. That was a terrible take then, and it’s a terrible take now. Clear as day when this started there was a nasty vendor supply chain risk lu…

> It’s probably against the rules to self-link old comments It's not against the rules to link past comments - in fact it's preferred to repeating the same or similar content across stories. At the same time, does 'look, I had the right take once in the past' make for interesting conversation? I'm keen to see it unfold!

No, I rarely think self-referential comments are useful, let alone interesting.

I do think it’s useful however to claim information space on a serious topic before, interestingly, various apologists show up as is happening ITT now.

Re: TeleMessage, used by Trump officials, can access plaintext chat logs

#58
post #46

This may be a factual but not truthful article. This was initially framed to appear like the Trump Administration was doing something out of the ordinary by using Signal. There were also accusations that they were using Signal's disappearing message feature to conceal their activities from the authorities, and that they were breaking the Presidential Records Act, etc. Now it's revealed that they are using a version t…

Without more technical details about telemessage it isn't clear how archive servers are actually selected by the app, where they are hosted, or how they are secured.

For example, while it's possible that DoD phones would only connect to Signal via proxies from within a VPN to a private network, direct Internet connectivity could lead to a potential leak of archived messages to any Internet-connected telemessage server if the app is misconfigured or the wrong app installed.

Given the debug logs shown by the attacker it sounds like the archive server has vulnerabilities exploitable over any connected network which wouldn't protect self-hosted version in govcloud from exploitation from within those networks.

Re: TeleMessage, used by Trump officials, can access plaintext chat logs

#59

Earlier quoted context omitted.

Brewing? This is it. All of these messages have been leaking; that's what the article is about.

Have you found info on the chat texts? Referring to “a leak” as in these chats go public in some form vs into a RU SCIF somewhere, and that there’s some verification of what the clear text chats were/who’s in it. I am speculating it’ll be the latter scenario, with periodic strategic leaks.

A leak to the press is one of the least damaging (relatively speaking) categories of leak, because intelligence officials quickly become aware. What's far more damaging is when secret communications are leaked to outside intelligence.

Re: TeleMessage, used by Trump officials, can access plaintext chat logs

#60

Earlier quoted context omitted.

No, the point is for the government to have access the plaintext after it is securely delivered to an approved archive location, not TeleMessage having access on AWS-hosted servers exposed to the public internet. TeleMessage pitched their service as using end-to-end encryption of the message into the corporate archive. > End-to-End encryption from the mobile phone through to the corporate archive Apparently the plain…

Why would they need to hire a foreign Israeli firm for that? Through this procurement decision, the government has displayed gross incompetence.

US owned since Feb 2024
Post reply on HN