Live data from Hacker News

TeleMessage Explorer: a new open source research tool

micahflee.com

51–60 of 65 posts

Re: TeleMessage Explorer: a new open source research tool

#51

Earlier quoted context omitted.

> if a company knows something about you, so does the government(s) The constant litigation between the government and private companies over records requests should put this hypothesis to bed.

The black box rooms in the telecom forms two decades ago beg to differ What you are talking about is small fry law enforcement. If you don't think the new has total access to the databases of the thousands of social network and advertising/data collection firms, I don't know what to tell you. Maybe something totally encrypted, but even then there is hardware backdoors, and the NSA can simply pay an employee to legall…

They only need to pay off or install a single employee to get total or near-total access. Consider this chart from 2013 showing when various tech companies were added to PRISM:

https://upload.wikimedia.org/wikipedia/commons/c/c7/Prism_sl...

A lot of the companies embattled in the "constant litigation" mentioned by the GP are featured in this very chart.

Re: TeleMessage Explorer: a new open source research tool

#52
post #51

Earlier quoted context omitted.

The black box rooms in the telecom forms two decades ago beg to differ What you are talking about is small fry law enforcement. If you don't think the new has total access to the databases of the thousands of social network and advertising/data collection firms, I don't know what to tell you. Maybe something totally encrypted, but even then there is hardware backdoors, and the NSA can simply pay an employee to legall…

They only need to pay off or install a single employee to get total or near-total access. Consider this chart from 2013 showing when various tech companies were added to PRISM: https://upload.wikimedia.org/wikipedia/commons/c/c7/Prism_sl... A lot of the companies embattled in the "constant litigation" mentioned by the GP are featured in this very chart.

> lot of the companies embattled in the "constant litigation" mentioned by the GP are featured in this very chart

Yup. A great first step towards understanding these systems is to disaggregate the monoliths of these enterprises and the U.S. government into their power centres.

Re: TeleMessage Explorer: a new open source research tool

#53

Earlier quoted context omitted.

> the only way to do that is to have a modified client My firm requires screenshots. If the concern is that someone would bypass that, well, someone could bypass TeleMessage, too.

One has to wonder what type of legal requirement this satisfies. It certainly wouldn’t hold up to the “beyond a reasonable doubt” standard for US criminal prosecution. I’ve been exposed to “lit holds” for various document management system before and usually a third party such as Box or Microsoft can attest to the immutability of files placed under lit hold, and/or there is an audit trail to make sure the chain of cu…

> what type of legal requirement this satisfies

Typically between commercially reasonable and best efforts.

> been exposed to “lit holds” for various document management system before

I think these are held to a higher standard than run-of-the-mill securities compliance.

Re: TeleMessage Explorer: a new open source research tool

#54
post #51

Earlier quoted context omitted.

They only need to pay off or install a single employee to get total or near-total access. Consider this chart from 2013 showing when various tech companies were added to PRISM: https://upload.wikimedia.org/wikipedia/commons/c/c7/Prism_sl... A lot of the companies embattled in the "constant litigation" mentioned by the GP are featured in this very chart.

> lot of the companies embattled in the "constant litigation" mentioned by the GP are featured in this very chart Yup. A great first step towards understanding these systems is to disaggregate the monoliths of these enterprises and the U.S. government into their power centres.

Do you believe the disaggregation of those monoliths helps to put the "hypothesis to bed"? It sure seems like you were listing "constant litigation" over "records request" as counterevidence of the claim that "if a company knows something about you, so does the government(s)".

If anyone in the U.S. government is extracting data from companies in a manner which is unlawful or should be (and they sure are), I see that as strong evidence of the hypothesis. Pointing out that local agencies may have to fight for their access in court doesn't change that it "is exactly the state of affairs the government prefers".

Re: TeleMessage Explorer: a new open source research tool

#55

I don’t understand the value proposition of TeleMessage. Uses Signal but defeats the point of using Signal. Why not use a proper centralized chat with actual retention and encryption?

> Why not use a proper centralized chat with actual retention and encryption?

This is the right question to ask. It might be that such a thing doesn't quite exist in the way that the customers want (doubtful; Slack should work just fine), or more likely it might be a cultural issue (that Signal is ingrained in some of these executives' minds as _the_ secure system to use, and/or that they don't want Slack/Whatever to be the service provider for IM _and_ the service provider for retention, or that they don't want Slack/Whatever with on-prem services because they don't trust their own IT, etc.).

Obviously TeleMessage's value add is to add retention to Signal, which defeats the point of Signal. That leads me to think that the motivation is cultural.

Re: TeleMessage Explorer: a new open source research tool

#56

I don’t understand the value proposition of TeleMessage. Uses Signal but defeats the point of using Signal. Why not use a proper centralized chat with actual retention and encryption?

I wonder if it is just organizations that don't really care about anything other than brand name (signal is known as pretty good, right) and CYA. Like it might legitimately be the case that you personally have expended more brainpower trying to understand the decision than they put into making it.

This is probably it.

Or there might be an issue with trusting their own IT departments. With Signal they don't even have to trust Signal (haha, but they might think that you know).

There's another possibility: NSA told them to use Signal w/ TeleMessage so that NSA could see everything because they have an agreement with TeleMessage or because NSA knows about all these vulns in TeleMessage.

There's other possibilities too.

Re: TeleMessage Explorer: a new open source research tool

#57
post #54

Earlier quoted context omitted.

> lot of the companies embattled in the "constant litigation" mentioned by the GP are featured in this very chart Yup. A great first step towards understanding these systems is to disaggregate the monoliths of these enterprises and the U.S. government into their power centres.

Do you believe the disaggregation of those monoliths helps to put the "hypothesis to bed"? It sure seems like you were listing "constant litigation" over "records request" as counterevidence of the claim that "if a company knows something about you, so does the government(s)". If anyone in the U.S. government is extracting data from companies in a manner which is unlawful or should be (and they sure are), I see that…

> sure seems like you were listing "constant litigation" over "records request" as counterevidence of the claim that "if a company knows something about you, so does the government(s)"

Yes. Just because the NSA can access some data doesn’t mean the entire federal government, including the NSA, has it.

> local agencies may have to fight for their access

The White House is fighting Harvard for student records. I don’t think people appreciate the degree to which information is siloed, intentionally and unintentionally, in the federal government. (It’s what led to DOGE likely committing multiple felonies.)

Re: TeleMessage Explorer: a new open source research tool

#59

Signal is licensed under GNU AGPLv3 - think there will be any action against the company for license violations? I suppose it's the least of their liabilities, but just wondering.

The signal protocol is public, using their servers is frowned upon but its not a source code license violation.

Re: TeleMessage Explorer: a new open source research tool

#60
post #54

Earlier quoted context omitted.

Do you believe the disaggregation of those monoliths helps to put the "hypothesis to bed"? It sure seems like you were listing "constant litigation" over "records request" as counterevidence of the claim that "if a company knows something about you, so does the government(s)". If anyone in the U.S. government is extracting data from companies in a manner which is unlawful or should be (and they sure are), I see that…

> sure seems like you were listing "constant litigation" over "records request" as counterevidence of the claim that "if a company knows something about you, so does the government(s)" Yes. Just because the NSA can access some data doesn’t mean the entire federal government, including the NSA, has it. > local agencies may have to fight for their access The White House is fighting Harvard for student records. I don’t…

>I don’t think people appreciate the degree to which information is siloed, intentionally and unintentionally, in the federal government.

Thanks for that. Information can be completely siloed and the statements "If a company knows something about you, so does the government(s)" and "This is exactly the state of affairs the government prefers" still be correct.

Is your belief that the federal government has not actually purchased hordes of corporate surveillance data? Or is it that because there are examples of information being siloed or not available, that means it's okay or a non-issue that Americans' data that was once unlawfully collected is now still unlawfully collected but also collected by corporations and purchased wholesale by the federal government?

Post reply on HN