I'd find it useful if I could access my Signal chat logs in plaintext. The software offers no facility to do this on any platform, and on Desktop the programs that have allowed me to take proper backups are (by necessity) a moving target because of changes to the database, so I am constantly having to get around to updating them and occasionally even that's a pain.
> I'd find it useful if I could access my Signal chat logs in plaintext I'd probably also find it useful if I could access your Signal chat logs in plaintext. That's the problem.
TeleMessage, used by Trump officials, can access plaintext chat logs
41–50 of 92 posts
Re: TeleMessage, used by Trump officials, can access plaintext chat logs
#42Earlier quoted context omitted.
> I'd find it useful if I could access my Signal chat logs in plaintext I'd probably also find it useful if I could access your Signal chat logs in plaintext. That's the problem.
If someone has enough control of the app to utilize its export-to-plaintext button you were SOL anyway, there are plenty of use cases for “export a password protected encrypted blob of chat history so I don’t lose everything every time I switch devices”
Or find the lowest-paid, most-indebted and/or most-adulterous member of the TeleMessage team and bribe and blackmail them.
Re: TeleMessage, used by Trump officials, can access plaintext chat logs
#43Earlier quoted context omitted.
No, the point is for the government to have access the plaintext after it is securely delivered to an approved archive location, not TeleMessage having access on AWS-hosted servers exposed to the public internet. TeleMessage pitched their service as using end-to-end encryption of the message into the corporate archive. > End-to-End encryption from the mobile phone through to the corporate archive Apparently the plain…
I doubt that’s the point either. The government should have cipher text they are able to decrypt in an approved archive location with rigorously managed key material and a careful cryptographically variable chain of custody from its inception. Plain text should never factor into this.
Re: TeleMessage, used by Trump officials, can access plaintext chat logs
#44Isn't that the point?
Presumably, in the spectrum of secure network protocols, something exists between "delete the message before it can leave this machine" and "send this message to a cloud provider and have them email it in plain text to another cloud provider".
Re: TeleMessage, used by Trump officials, can access plaintext chat logs
#45These are the guys trying to jail Krebs for being honest. They earned the “experts” they deserve.
Chris Krebs is unrelated to Brian Krebs of Krebs on Security.
[0] https://en.wikipedia.org/wiki/Chris_Krebs
[1] https://www.whitehouse.gov/fact-sheets/2025/04/fact-sheet-pr...
Re: TeleMessage, used by Trump officials, can access plaintext chat logs
#46First and foremost, the Signal infrastructure was setup in most cases by the previous administration! Even a cursory search of USA Spending reveals millions were spent on telemessage before Trump was elected. https://www.usaspending.gov/search?hash=d900bda0a5eccae47ba7... I'm not a journalist, but look for yourself.
As for accusations that what the Biden Administration procured and configured is insecure: it's not. TeleMessage has a configuration approved for CUI that integrates with GCC-high (IL4) and O365 DoD (IL5). Thus they are fine to collect and archive unclassified CUI, ITAR, NSS data, command and control/ISR, tactical data, etc.
"TeleMessage can go a long way in enabling regulatory compliance by working with Microsoft to capture, archive, and maintain text messages, voice calls, and other files, leading to stress-free adherence to all the security controls required as per FedRAMP. Crucially, the mobile archiver supports Microsoft 365 Government Community Cloud, Government Community Cloud High, and Department of Defense solutions across all devices, carriers, and instant messengers.
Federal agencies and contractors can issue their own phones to personnel or have their employees use their own BYOD devices because TeleMessage can still securely retain all the communication within its servers or have it forwarded to a data storage vendor of choice. There is also the option of cross-carrier and international mobile text and calls archiving." -- https://web.archive.org/web/20250502041804/https://www.telem...
So far they're good in theory. They decrypted messages are transmitted in at least 1 encrypted wrapper (TLS) to mobile archiver, then ultimately landing in the DoD Azure cloud environment. The question is whether the whole chain after the phone is in the DoD environment, or if it routes through Telemessage's systems.
If you look at the hack (https://archive.ph/yyyLg), initially it leads you to believe that the message archiver doesn't live in the DoD environment and instead lives in AWS commercial or some lesser rated cloud. I think this is only true some of the time. Note in the hack, they only have messages from CPB. They don't appear to have any .mil, cia.gov, eop.gov, etc. CBP doesn't have access to the IL5 DoD Tenant in the first place and their archiver is likely hosted in AWS Commercial or AWS East/West (IL2).
Frankly, I don't think that any of the higher sensitivity organizations will be routing through a TeleMessage controlled server, or any server lower than IL4. They host that piece on their own infrastructure.
Re: TeleMessage, used by Trump officials, can access plaintext chat logs
#47Re: TeleMessage, used by Trump officials, can access plaintext chat logs
#48A large portion of HN's commenters wouldn't make this mistake in a quickly written offhand comment.
Re: TeleMessage, used by Trump officials, can access plaintext chat logs
#49Earlier quoted context omitted.
I doubt that’s the point either. The government should have cipher text they are able to decrypt in an approved archive location with rigorously managed key material and a careful cryptographically variable chain of custody from its inception. Plain text should never factor into this.
We're using words like "should" have access or whatever, but my understanding of the point of these apps is that they allow users to use Signal while keeping compliance archives of messages. They're not cryptographically interesting (or really cryptographic at all). This is more like e-discovery software than secure messaging. If you're using it, cryptography is out the window.
Re: TeleMessage, used by Trump officials, can access plaintext chat logs
#50However, when this first broke, select HN users were claiming this was OPSEC 4D chess and not deeply irresponsible cybersec practices.
That was a terrible take then, and it’s a terrible take now.
Clear as day when this started there was a nasty vendor supply chain risk lurking, and if it was 4D cybersec chess it was done by some absolute muppets.
Bad setups get exploited in natsec.
A bad setup exploited.
Sounds like a brutal US natsec leak is brewing.