Live data from Hacker News

TeleMessage, used by Trump officials, can access plaintext chat logs

micahflee.com

61–70 of 92 posts

Re: TeleMessage, used by Trump officials, can access plaintext chat logs

#61

Earlier quoted context omitted.

I doubt that’s the point either. The government should have cipher text they are able to decrypt in an approved archive location with rigorously managed key material and a careful cryptographically variable chain of custody from its inception. Plain text should never factor into this.

The point is that it was supposed to be end-to-end encrypted by this company all the way to the government's archive. That's what they claimed, but their service did no such thing.

How, in Signal's security model, could there be "end to end encryption all the way to the government archive"?

Re: TeleMessage, used by Trump officials, can access plaintext chat logs

#62

Earlier quoted context omitted.

Have you found info on the chat texts? Referring to “a leak” as in these chats go public in some form vs into a RU SCIF somewhere, and that there’s some verification of what the clear text chats were/who’s in it. I am speculating it’ll be the latter scenario, with periodic strategic leaks.

A leak to the press is one of the least damaging (relatively speaking) categories of leak, because intelligence officials quickly become aware. What's far more damaging is when secret communications are leaked to outside intelligence.

Right. What evidence is out there on the leak contents?

All I have found is putting 2 and 2 together that this Signal variant has been used for months, the vendor was exploited and lost data, and vendor worked with clear texts logs.

That leaves a lot of room for interpretation still. certain agencies on certain tenants, certain tenants were hacked but others, technical info like that.

Re: TeleMessage, used by Trump officials, can access plaintext chat logs

#63

Earlier quoted context omitted.

I doubt that’s the point either. The government should have cipher text they are able to decrypt in an approved archive location with rigorously managed key material and a careful cryptographically variable chain of custody from its inception. Plain text should never factor into this.

The US government does have storage facilities and secure messaging tools with escrow, all designed for exactly this use-case (secure messaging amongst DoD personnel.) But the whole point of Signal+TeleMessage was to route around that "clunky stuff" by outsourcing it to a vendor.

The DoD obviously has a need to message with people who don't have access to their hardware. Signal can basically do this on its own if you link a Signal account to an Internet-connected PC and back up those messages, I don't see why you would want a third party app involved.

It seems likely to me that this was the "whole point of Signal+TeleMessage" and then in addition to being a bad solution, it got misused for communications that shouldn't have left the DoD's networks anyway.

Re: TeleMessage, used by Trump officials, can access plaintext chat logs

#64
post #61

Earlier quoted context omitted.

The point is that it was supposed to be end-to-end encrypted by this company all the way to the government's archive. That's what they claimed, but their service did no such thing.

How, in Signal's security model, could there be "end to end encryption all the way to the government archive"?

This actually seems pretty trivial to me, without a custom Signal client. You link a secure PC with the secure archival software to your Signal account and it will receive all messages E2E encrypted.

Re: TeleMessage, used by Trump officials, can access plaintext chat logs

#65
post #51

Earlier quoted context omitted.

It’s not end-to-end, but that seems a bit exaggerated. An organization will still want encryption in transit, encryption at rest for its archive, and good access control.

In secure messaging as a cryptographic discipline, this is like saying you don't want secure messaging. Secure messaging is end-to-end secure, and the basic core threat modeling of a secure messaging service includes adversaries who defeat transit-only encryption. All this is to say: it's unremarkable to me that the Signal compliance fork government officials are using, which is premised on the capability of archivin…

Secure group chat is possible. If saving messages to an archive is what you want, Why isn’t the archive just another endpoint to deliver messages to?

The threat model would cover the risk of intercepting messages on the way to the archive and unauthorized access to the archive.

Re: TeleMessage, used by Trump officials, can access plaintext chat logs

#66
post #51

Earlier quoted context omitted.

It’s not end-to-end, but that seems a bit exaggerated. An organization will still want encryption in transit, encryption at rest for its archive, and good access control.

In secure messaging as a cryptographic discipline, this is like saying you don't want secure messaging. Secure messaging is end-to-end secure, and the basic core threat modeling of a secure messaging service includes adversaries who defeat transit-only encryption. All this is to say: it's unremarkable to me that the Signal compliance fork government officials are using, which is premised on the capability of archivin…

Hypothetically, wouldn't the best Signal archiving be to make the custom client auto-add an archiving "user" to all chats, with that user only connected from secure archiving machines? Then convert archive user client text to whatever government encrypted form on that machine for long term storage?

Curious what the best way of archiving with Signal's security model would be.

Re: TeleMessage, used by Trump officials, can access plaintext chat logs

#68
post #46

This may be a factual but not truthful article. This was initially framed to appear like the Trump Administration was doing something out of the ordinary by using Signal. There were also accusations that they were using Signal's disappearing message feature to conceal their activities from the authorities, and that they were breaking the Presidential Records Act, etc. Now it's revealed that they are using a version t…

Without more technical details about telemessage it isn't clear how archive servers are actually selected by the app, where they are hosted, or how they are secured. For example, while it's possible that DoD phones would only connect to Signal via proxies from within a VPN to a private network, direct Internet connectivity could lead to a potential leak of archived messages to any Internet-connected telemessage serve…

Reading through the guide, organizations have to compile their own apk/ipa and deploy via MDM. I'd suspect that "archive server" variable is set at build time. Maybe not and dozens of agencies ATO'd a setup where the data was running in the clear to a vendor, and to a low security cloud environment. I just don't see that happening at the DoD level.

Re: TeleMessage, used by Trump officials, can access plaintext chat logs

#70
post #61

Earlier quoted context omitted.

The point is that it was supposed to be end-to-end encrypted by this company all the way to the government's archive. That's what they claimed, but their service did no such thing.

How, in Signal's security model, could there be "end to end encryption all the way to the government archive"?

By saying that chatting and logging are separate processes, and each one has end to end encryption. Only the clients and the archive can see the text.

And that's what the actual quote says. End to end from phone to archive.

Post reply on HN