Live data from Hacker News

Technical analysis of the Signal clone used by Trump officials

micahflee.com

151–160 of 387 posts

Re: Technical analysis of the Signal clone used by Trump officials

#151

Earlier quoted context omitted.

It was incontrovertibly approved as it is only installable via MDM. A likely explanation is that the communications director (or the people informing her) wouldn’t know to distinguish between Signal the app, and a Signal compatible app that is nearly indistinguishable from Signal. A lot like Kleenex is a common term for tissue paper regardless of brand. When the leak was first revealed, there was loud speculation abo…

> It was incontrovertibly approved as it is only installable via MDM. Only if this his standard govt issued phone. It's also been shown they are also using their own personal phones. The could easily be using unapproved phones some random DOGE'er bought gave them with an MDM setup, without any real oversight.

> The could easily be using unapproved phones some random DOGE'er bought gave them with an MDM setup, without any real oversight.

No. Even if you managed to get the app and push it to devices, you can't just use TM-SGNL without having an archiving account from Telemessage.

Source: I manage this exact setup for several clients.

Re: Technical analysis of the Signal clone used by Trump officials

#152
post #140

Earlier quoted context omitted.

My statements were complete. You were not completing them, but trying to spin them in a way that implies wrongdoing when no evidence exists of it. I can only presume you're doing so for partisan reasons, to try to defend the actions of the current administration. Whatever the reason, I have made my case. Feel free to make yours with a similar level of evidence.

[flagged]

[deleted]

Re: Technical analysis of the Signal clone used by Trump officials

#154
post #16

> 404 Media journalist Joseph Cox published a story pointing out that Waltz was not using the official Signal app, but rather "an obscure and unofficial version of Signal that is designed to archive messages" Wow. And that's while their entire point of using Signal is to have conversations scrapped after a week to leave no no traces of criminal activity.

Maybe they wanted to use Signal to thwart eavesdropping but they had to modify it in order to comply with govt record retention requirements?

this appears to be the most concise answer. TM SGNL provides interop with Signal users in the field, but also includes FOIA archiving.

who manages the archiving service is a general government problem, and less of one for Signal or appointees. NSA should have been operating the archiving service and not a foreign country imo.

Re: Technical analysis of the Signal clone used by Trump officials

#155
post #149
post #127

Earlier quoted context omitted.

If you’d prefer, we can call it unclassified communication rather than personal communication. The point is that it was not used for Secret, Top Secret, or other classified communications. For that, he had the SME-PED device. So, again, it’s not a parallel to the current situation. Nobody is saying the SecDef and other staff shouldn’t have unclassified devices as well as their classified devices, the issue is that th…

But how could he have created accidentally a conversation for discussing targets during military attack with a journalist if secret communication was not done on his clear-text device ?

I think you're misunderstanding me, I'm referring to Obama's use of an NSA-hardened BlackBerry for unclassified communication with a select group of people, while using a purpose-built and NSA-cleared secure phone for classified communication. All of which was done correctly in terms of information security processes.

Secretary of Defence Hegseth sent Secret or Top Secret information over a channel (Signal/TM Signal and a regular mobile phone) that was never cleared for classified communications. The person I was replying to was trying to equate Obama's actions to those of Hegseth (and Waltz and others), I was providing context showing that to be a false equivalence.

What Hegseth did was indefensible.

Re: Technical analysis of the Signal clone used by Trump officials

#156
Here is the thing about e2e encrypted messengers: They lock you and your data in and do not allow you control of your life. There is a right to data portability (at least in the eu) that they violate and there is no one fighting for it. Whenever i engage in conversation about this i get empty faces, hostility and vague references to features that are crippled or just don't work at all. There are people and institutions that have to archive the communication centrally and they don't have control over how they are contacted and cannot have conversation about the channel used in every interaction all the time. The solution is to finally force messengers to allow api access to all communication data and then show a sign similar to ssl warnings in browsers to the other side that this user is using an archival api service.

Re: Technical analysis of the Signal clone used by Trump officials

#157
post #97

Earlier quoted context omitted.

What does conservative brain drain mean?

A few decades ago, the Republican party had one foot in the anti-intellectual camp, but only one. They were the party of young-earth creationists, religious pro-lifers, climate-deniers and gun-lovers - but also of educated fiscally conservative folks. The party would welcome economics professors and leaders of medium-sized businesses, promising no radical changes, no big increases in spending or regulation, and a gen…

[flagged]

Re: Technical analysis of the Signal clone used by Trump officials

#158

Earlier quoted context omitted.

Any client-side limitations are not part of the security model because you don't control other people's devices. Even with an unmodified app, they're trivially bypassed using a rooted/jailbroken device.

Not part of Signal's security model, but trusting people in that chat very much can and should be part of the user's security model. If you don't trust them, why are they in the chat in the first place?

It's not a person in the chat, it's an account. The account is usually controlled by the person associated with it, but you can't assume that it's always controlled by that person.

Re: Technical analysis of the Signal clone used by Trump officials

#159
post #118

Earlier quoted context omitted.

He was allowed to keep his BlackBerry for personal communication only, not classified communication, and had to use a Sectéra Edge for classified communication. [0] The Blackberry for personal use wasn't a stock BlackBerry, but hardened by the NSA and fitted with the SecurVoice software package to encrypt voice calls, emails, and messages. The few people he had on his approved communication list were given the same d…

> He was allowed to keep his BlackBerry for personal communication only, not classified communication Presence of the senior staff on his (very limited) contact list would seem to contradict that statement. Communication with them would be, by definition, not personal. I agree with you that our government officials should be using the secure infrastructure our patriotic service members and civil servants work so hard…

Obama wasn't allowed to keep his Blackberry; he requested a secure commercial-quality cellphone to communicate with his aides, and NSA (which was, to be sure, not really happy about the request) selected the Blackberry as their platform. The end solution was a highly pared-down device that could only communicate via a hosted encryption server (a commercial product, SecurVoice) to a small number of paired devices, which were distributed to Obama's inner circle. The Presidential devices had additional security limitations (e.g., they could only connect to WHCA-controlled base stations). End of the day, what they had was an encrypted closed network of devices, some of which communicated over public wireless infra, running a very limited, NSA-reviewed, approved, and altered, software suite.

What's clear is that NSA put a fair amount of effort into securing and maintaining that system, so much that its use was limited to the White House; Hillary Clinton wanted a similar setup (her predecessor, Condoleezza Rice, had been allowed to use unaltered "off the shelf" Blackberries under an NSA waiver, but NSA had declined to renew those waivers due to security concerns), but NSA slow-walked and effectively derailed the discussions with State's security team, perhaps because they wanted to limit the amount of technical detail discussed outside the White House, or because they were concerned that State would be unable to provide SecState with the kind of technical support necessary to secure the devices during global travel. (We all know what happened next, of course.)

Re: Technical analysis of the Signal clone used by Trump officials

#160

Here is the thing about e2e encrypted messengers: They lock you and your data in and do not allow you control of your life. There is a right to data portability (at least in the eu) that they violate and there is no one fighting for it. Whenever i engage in conversation about this i get empty faces, hostility and vague references to features that are crippled or just don't work at all. There are people and institutio…

I don't understand this: there's nothing intrinsic to e2e that makes interoperability particularly hard. There are multiple open-source e2e protocols that demonstrate this tidily, and my understanding is that there are governments in the EU that are adopting e.g. Matrix for this reason.

> show a sign similar to ssl warnings in browsers to the other side that this user is using an archival api service.

There is no sound way to do this and there probably never will be, especially if the protocol is interoperable and therefore the user can pick any client they please. The other client can always lie about what it's doing or circumvent detections through analogue means, e.g. pointing a camera at the screen.

Post reply on HN