These are the guys trying to jail Krebs for being honest. They earned the “experts” they deserve.
TeleMessage, used by Trump officials, can access plaintext chat logs
31–40 of 92 posts
Re: TeleMessage, used by Trump officials, can access plaintext chat logs
#32Isn't that the point?
Presumably, in the spectrum of secure network protocols, something exists between "delete the message before it can leave this machine" and "send this message to a cloud provider and have them email it in plain text to another cloud provider".
It's worse than internet packets over HTTPS -- the secure connection is established between client and server, so man-in-the-middle cannot decrypt it. In email, connections are only secure between relays, so any relay can decrypt read your email. You cannot guarantee what relays are used. Similar to SMS.
Re: TeleMessage, used by Trump officials, can access plaintext chat logs
#33Earlier quoted context omitted.
No, the point is for the government to have access the plaintext after it is securely delivered to an approved archive location, not TeleMessage having access on AWS-hosted servers exposed to the public internet. TeleMessage pitched their service as using end-to-end encryption of the message into the corporate archive. > End-to-End encryption from the mobile phone through to the corporate archive Apparently the plain…
I doubt that’s the point either. The government should have cipher text they are able to decrypt in an approved archive location with rigorously managed key material and a careful cryptographically variable chain of custody from its inception. Plain text should never factor into this.
Re: TeleMessage, used by Trump officials, can access plaintext chat logs
#34These are the guys trying to jail Krebs for being honest. They earned the “experts” they deserve.
(It also probably is very different, all from "own the libs" through "escalate the second coming of Christ" or any combination thereof.)
Re: TeleMessage, used by Trump officials, can access plaintext chat logs
#35Re: TeleMessage, used by Trump officials, can access plaintext chat logs
#36Re: TeleMessage, used by Trump officials, can access plaintext chat logs
#37Why bother hacking your phone and installing a keylogger when we can convince your IT department to buy it and install it for your entire team. Have to say, this is pretty epic.
Re: TeleMessage, used by Trump officials, can access plaintext chat logs
#38Earlier quoted context omitted.
I doubt that’s the point either. The government should have cipher text they are able to decrypt in an approved archive location with rigorously managed key material and a careful cryptographically variable chain of custody from its inception. Plain text should never factor into this.
The US government does have storage facilities and secure messaging tools with escrow, all designed for exactly this use-case (secure messaging amongst DoD personnel.) But the whole point of Signal+TeleMessage was to route around that "clunky stuff" by outsourcing it to a vendor.
Re: TeleMessage, used by Trump officials, can access plaintext chat logs
#39Earlier quoted context omitted.
No, the point is for the government to have access the plaintext after it is securely delivered to an approved archive location, not TeleMessage having access on AWS-hosted servers exposed to the public internet. TeleMessage pitched their service as using end-to-end encryption of the message into the corporate archive. > End-to-End encryption from the mobile phone through to the corporate archive Apparently the plain…
I doubt that’s the point either. The government should have cipher text they are able to decrypt in an approved archive location with rigorously managed key material and a careful cryptographically variable chain of custody from its inception. Plain text should never factor into this.
That's what they claimed, but their service did no such thing.
Re: TeleMessage, used by Trump officials, can access plaintext chat logs
#40Earlier quoted context omitted.
I doubt that’s the point either. The government should have cipher text they are able to decrypt in an approved archive location with rigorously managed key material and a careful cryptographically variable chain of custody from its inception. Plain text should never factor into this.
The US government does have storage facilities and secure messaging tools with escrow, all designed for exactly this use-case (secure messaging amongst DoD personnel.) But the whole point of Signal+TeleMessage was to route around that "clunky stuff" by outsourcing it to a vendor.