Live data from Hacker News

Mike Waltz Accidentally Reveals App Govt Uses to Archive Signal Messages

404media.co

101–110 of 137 posts

Re: Mike Waltz Accidentally Reveals App Govt Uses to Archive Signal Messages

#101

Earlier quoted context omitted.

This is a good point - but at some point we have to trust someone. I feel that the Signal folks are worth trusting. Plus it's open source, so the more technie among us can meaningfully audit what's going on. That's not foolproof, but it does seem better than most alternatives. Certainly it's better for the gov't to pay Signal than to try to do it themselves.

> I feel that the Signal folks are worth trusting. The MobileCoin integration and the long standing refusal to support a way to use the messenger without using a phone number (or a smartphone at all) make me wary. To me they sit pretty much on the same level of trust as Meta's WhatsApp, which is a sad thing to have to conclude.

This. Session does desktop and mobile cheerfully without leaving metadata enabling government real-time location tracking.

Re: Mike Waltz Accidentally Reveals App Govt Uses to Archive Signal Messages

#103

[flagged]

Waltz was chosen for loyalty. He simply isn’t very smart. There is no grand plan behind getting your screen photographed while chatting with the VP, DNI and SecState.

Shouldn’t any government issued smartphone have privacy screen protectors at the very least?

Re: Mike Waltz Accidentally Reveals App Govt Uses to Archive Signal Messages

#104

It seems reasonable enough that the government may have built a forked version of signal with message archiving that meets documentation requirements. If its an app they wanted kept under wraps, it will make the while Hegseth situation seem a lot more benign. I use Molly Messenger on a secondary phone that doesn't have a SIM, its a fork of Signal with a few differences related to encryption at rest. It still works wi…

> If the government has a similarly forked version you could likely still accidentally invite the wrong user in from their normal Signal app and they wouldn't know you're on a forked version with government archiving features.

Is there no way Signal can prevent this in the official app?

Re: Mike Waltz Accidentally Reveals App Govt Uses to Archive Signal Messages

#105
post #34

Earlier quoted context omitted.

I didn't catch this in the article here. Is that well known elsewhere?

> But the message is slightly different: it asks Waltz to verify his “TM SGNL PIN.” This is not the message that is displayed on an official version of Signal. > Instead TM SGNL appears to refer to a piece of software from a company called TeleMessage which makes clones of popular messaging apps but adds an archiving capability to each of them. https://en.wikipedia.org/wiki/TeleMessage

Acquired by a US company, Smarsh, according to other comments

Re: Mike Waltz Accidentally Reveals App Govt Uses to Archive Signal Messages

#106
post #85

Earlier quoted context omitted.

Precisely. The security of a message endpoint ends at the point that the opposite party's leverage runs out. If I care more about my snapchat account than I do about saving your disappearing message minus your ability to leverage snapchat into banning my account or apply outside social pressure, then your disappearing message may actually disappear. As the stakes go up, so does the leverage required for “endpoint sec…

Is there a term for any application which offers full control of your messages then, ie, I send you messages on Signal, but I can make them self destruct and you cannot screenshot them? (Pretty sure Signal allows this?). Nothing stopping a user from taking photos of the screen using another device, of course. Or running their own fork of Signal (which, when run from the open source for Android at least, runs on produ…

Dunno. Like I said, there's no way to do this effectively without some form of leverage over the counter-party. This sort of thing is why SCIF's exist, and is an example of the more extreme ends of leverage, but it still ultimately comes down to leverage: they can make you delete the message and will throw you in jail if you figure out a way to evade it.

One-time secret, maybe?

Re: Mike Waltz Accidentally Reveals App Govt Uses to Archive Signal Messages

#107
post #66

Earlier quoted context omitted.

Even though Israel is our "Ally" -- we really shouldn't trust a foreign company with our sensitive messaging. If you're in the government, you should treat Hegseth and anyone who uses Signal and TMSIGNL as compromised.

It's not like Israel would ever spy on the US right? https://en.wikipedia.org/wiki/Jonathan_Pollard

US spy agencies are world famous weak and heavy relayed on UK and Israel communications.

Re: Mike Waltz Accidentally Reveals App Govt Uses to Archive Signal Messages

#108
post #76

Wouldn’t it be more effective for the government to develop a highly secure communication app, known only to individuals in top-level positions? This app would be discreetly installed upon appointment to a senior government role and automatically removed upon departure from office.

Yes and no.

No, not for classified comms. They already have secure comms and SCIFs but they're not using them. This is what they should be using. And they should be following sterile opsec so they don't carry tracking and listening devices into classified meetings or strategy discussions with decision makers.

They do need better opsec for unclassified and personal comms. It would be nice™ for them to have a Signal-like app controlled by the NSA because depending on Signal or WhatsApp is vulnerable to a malicious insider. Few Meta employees have security clearances, while I don't know about Signal.

Re: Mike Waltz Accidentally Reveals App Govt Uses to Archive Signal Messages

#110
So wait…

They are using a Signal clone that is run by a group of Israeli intelligence officers??

I don’t think that part of the story has broken yet properly. When you go to google maps for the address listed for that company you actually get a company called “Cyberint” which seems extremely not good.

https://maps.app.goo.gl/L7vVHw5x4VdgS8859?g_st=com.google.ma...

Worse.. when you take a look at the bios for the company on their website I see that it’s filled with supposedly “ex” Israeli intelligence officers including the CEO among others. https://www.telemessage.com/team/

That seems like a MUCH MUCH bigger deal than they currently known story.

Like several orders of magnitude bigger than the original signalgate story.

The implication here is that a bunch of Israeli intelligence officers have maybe the best access of anyone in the world right now in that they have a real time feed of every conversation that the US national security advisor is a part of.

Post reply on HN