Live data from Hacker News

Technical analysis of the Signal clone used by Trump officials

micahflee.com

311–320 of 387 posts

Re: Technical analysis of the Signal clone used by Trump officials

#311

enjoyed this but not sure how technical it is if you can't actually look at or disassemble the app in question.

You can. The author made the source code of the app itself available: https://micahflee.com/heres-the-source-code-for-the-unoffici...

oh a bigger analysis is inbound from the author! Excellent.

Re: Technical analysis of the Signal clone used by Trump officials

#312
post #233

Earlier quoted context omitted.

Probably not. It's trendy to give edgy names to companies. See: Palintir.

You mean Palantir

And the name is not very edgy and a pretty exact mission description - it describes exactly what it grows from. Seeing stones aka cellphone data of everyone, collected, analyzed and turned into predictions for kings.

Re: Technical analysis of the Signal clone used by Trump officials

#314

Earlier quoted context omitted.

My wild speculation is that someone wants to use AI to monitor everyone’s communication.

What they should have done is write a bot that you invite to every conversation for "archival purposes". No new app.

Then you have a new attack surface. It's still missing the point of signal.

Re: Technical analysis of the Signal clone used by Trump officials

#317

Earlier quoted context omitted.

What they should have done is write a bot that you invite to every conversation for "archival purposes". No new app.

Then you have a new attack surface. It's still missing the point of signal.

If your institution has to log the messages, they are a third party to the conversation, I would rather they were "in the chat" than the lowest bidder third party.

A chat participant bot would also be handy if you wanted to feed everything through your Ai bot at the same time.

Re: Technical analysis of the Signal clone used by Trump officials

#318
post #296

Earlier quoted context omitted.

The question is - how do you intend to verify whether an application is official or unofficial? What's stopping the official application to be 'patched' with a fake signature feigning validity?

Asymmetric cryptography?

How? If you're validating a server, sure. But a server validating a client?

Anything you ship with the app can be extracted.

Re: Technical analysis of the Signal clone used by Trump officials

#319

Earlier quoted context omitted.

Really? https://en.wikipedia.org/wiki/Jonathan_Pollard

You'll note that this case caused exactly the kind of outcome I'm talking about: Pollard was an anomaly (to my knowledge, the only recorded case of a US citizen spying for a US ally) whose activities caused a massive intelligence break between US and Israel that lasted for years and probably did more damage than "good" it served for Israel's intelligence apparatus[1]. That kind of lesson is hard-learned and probably…

Julius and Ethel Rosenberg were also US citizens spying for a US ally, at least in theory. Though the Soviet Union had stopped being an ally before they were convicted, of course.

Re: Technical analysis of the Signal clone used by Trump officials

#320
post #302

Earlier quoted context omitted.

> What makes you say that? Has Signal posted something about it? I mean, if you want Signal's blog post where they introduced it, it's here: https://signal.org/blog/disappearing-messages/ But also, of course Signal hasn't promised that if they're remotely competent, because that's impossible. You can't stop people from retaining messages if they want to. Now perhaps they're not remotely competent, but in reality they…

> Your recipient could get out a camera and take a photograph if that's what it comes to. You are making the perfect the enemy of the good. As I said, two comments up: "I suppose I must trust other users - they could always screenshot a conversation. But while I trust them not to intentionally cheat me, I shouldn't have to trust them to accurately evaluate the security implementation of a software application - somet…

> You are making the perfect the enemy of the good.

They merely said: "Disappearing messages has never been a security guarantee of Signal".

Signal guarantees end-to-end encryption in transit. They don't guarantee anything that happens on the phones, because they can't. They try to help where they can, e.g. with disappearing messages. But that is a convenience tool, not a security guarantee by Signal.

Post reply on HN