Live data from Hacker News

TeleMessage Explorer: a new open source research tool

micahflee.com

11–20 of 65 posts

Re: TeleMessage Explorer: a new open source research tool

#11

I don’t understand the value proposition of TeleMessage. Uses Signal but defeats the point of using Signal. Why not use a proper centralized chat with actual retention and encryption?

Considering they accidentally included a journalist, compatibility with the existing user network. If you need logged chat with normal Signal users, TeleMessage would probably be the way to do this.

Re: TeleMessage Explorer: a new open source research tool

#12

I don’t understand the value proposition of TeleMessage. Uses Signal but defeats the point of using Signal. Why not use a proper centralized chat with actual retention and encryption?

You might be subject to compliance requirements for archival but also want to talk to other people who use signal.

Re: TeleMessage Explorer: a new open source research tool

#14

I don’t understand the value proposition of TeleMessage. Uses Signal but defeats the point of using Signal. Why not use a proper centralized chat with actual retention and encryption?

I wonder if it is just organizations that don't really care about anything other than brand name (signal is known as pretty good, right) and CYA.

Like it might legitimately be the case that you personally have expended more brainpower trying to understand the decision than they put into making it.

Re: TeleMessage Explorer: a new open source research tool

#16
post #12

I don’t understand the value proposition of TeleMessage. Uses Signal but defeats the point of using Signal. Why not use a proper centralized chat with actual retention and encryption?

You might be subject to compliance requirements for archival but also want to talk to other people who use signal.

For example DC Police may have confidential informants who would be best to use Signal because that isn't unusual. But the people there are communicating need to retain the communication.

Re: TeleMessage Explorer: a new open source research tool

#18

I don’t understand the value proposition of TeleMessage. Uses Signal but defeats the point of using Signal. Why not use a proper centralized chat with actual retention and encryption?

Most people don’t care about anonymous communication. The agendas of those who do vary.

Signal is essentially iMessage that works in Android for all intents. Supporting it lets you communicate with outside entities. Otherwise the only mechanism to do so is email, which is problematic at best.

Government and finance are required by law to archive and audit communications. Some companies do anyway to keep tabs on staff.

Re: TeleMessage Explorer: a new open source research tool

#19

I don’t understand the value proposition of TeleMessage. Uses Signal but defeats the point of using Signal. Why not use a proper centralized chat with actual retention and encryption?

If you need your partners/bankers/salespeople/cabinet-level officials etc. to be able to converse with their clients on the E2E encrypted systems those clients already use, like WhatsApp and Signal, but maintain retention for legal or internal data-mining reasons, the only way to do that is to have a modified client, perhaps cracked or forked from an official client, that speaks the same wire protocol, but copies messages to separate storage.

Now, such a system could be set up to route those copied messages in a separately E2E-encrypted way to the client's in-house/on-prem archival systems, and have the client be responsible for implementing decryption and secure storage at rest. But it's far easier to just sell a centralized cloud-based archival/retrieval system - which must necessarily be able to decrypt messages, and thus makes for an incredibly juicy target.

Given the supply-chain risks of the provider offering the customized clients anyways, one would expect them to have a strong security focus... but it certainly seems this was not the case.

Re: TeleMessage Explorer: a new open source research tool

#20
post #12

Earlier quoted context omitted.

You might be subject to compliance requirements for archival but also want to talk to other people who use signal.

For example DC Police may have confidential informants who would be best to use Signal because that isn't unusual. But the people there are communicating need to retain the communication.

So basically, you tell at-risk people they're E2E, but keep a copy on whatever storage system you want to use and send another to your friends.
Post reply on HN