Earlier quoted context omitted.
I doubt that’s the point either. The government should have cipher text they are able to decrypt in an approved archive location with rigorously managed key material and a careful cryptographically variable chain of custody from its inception. Plain text should never factor into this.
The point is that it was supposed to be end-to-end encrypted by this company all the way to the government's archive. That's what they claimed, but their service did no such thing.
TeleMessage, used by Trump officials, can access plaintext chat logs
61–70 of 92 posts
Re: TeleMessage, used by Trump officials, can access plaintext chat logs
#62Earlier quoted context omitted.
Have you found info on the chat texts? Referring to “a leak” as in these chats go public in some form vs into a RU SCIF somewhere, and that there’s some verification of what the clear text chats were/who’s in it. I am speculating it’ll be the latter scenario, with periodic strategic leaks.
A leak to the press is one of the least damaging (relatively speaking) categories of leak, because intelligence officials quickly become aware. What's far more damaging is when secret communications are leaked to outside intelligence.
All I have found is putting 2 and 2 together that this Signal variant has been used for months, the vendor was exploited and lost data, and vendor worked with clear texts logs.
That leaves a lot of room for interpretation still. certain agencies on certain tenants, certain tenants were hacked but others, technical info like that.
Re: TeleMessage, used by Trump officials, can access plaintext chat logs
#63Earlier quoted context omitted.
I doubt that’s the point either. The government should have cipher text they are able to decrypt in an approved archive location with rigorously managed key material and a careful cryptographically variable chain of custody from its inception. Plain text should never factor into this.
The US government does have storage facilities and secure messaging tools with escrow, all designed for exactly this use-case (secure messaging amongst DoD personnel.) But the whole point of Signal+TeleMessage was to route around that "clunky stuff" by outsourcing it to a vendor.
It seems likely to me that this was the "whole point of Signal+TeleMessage" and then in addition to being a bad solution, it got misused for communications that shouldn't have left the DoD's networks anyway.
Re: TeleMessage, used by Trump officials, can access plaintext chat logs
#64Earlier quoted context omitted.
The point is that it was supposed to be end-to-end encrypted by this company all the way to the government's archive. That's what they claimed, but their service did no such thing.
How, in Signal's security model, could there be "end to end encryption all the way to the government archive"?
Re: TeleMessage, used by Trump officials, can access plaintext chat logs
#65Earlier quoted context omitted.
It’s not end-to-end, but that seems a bit exaggerated. An organization will still want encryption in transit, encryption at rest for its archive, and good access control.
In secure messaging as a cryptographic discipline, this is like saying you don't want secure messaging. Secure messaging is end-to-end secure, and the basic core threat modeling of a secure messaging service includes adversaries who defeat transit-only encryption. All this is to say: it's unremarkable to me that the Signal compliance fork government officials are using, which is premised on the capability of archivin…
The threat model would cover the risk of intercepting messages on the way to the archive and unauthorized access to the archive.
Re: TeleMessage, used by Trump officials, can access plaintext chat logs
#66Earlier quoted context omitted.
It’s not end-to-end, but that seems a bit exaggerated. An organization will still want encryption in transit, encryption at rest for its archive, and good access control.
In secure messaging as a cryptographic discipline, this is like saying you don't want secure messaging. Secure messaging is end-to-end secure, and the basic core threat modeling of a secure messaging service includes adversaries who defeat transit-only encryption. All this is to say: it's unremarkable to me that the Signal compliance fork government officials are using, which is premised on the capability of archivin…
Curious what the best way of archiving with Signal's security model would be.
Re: TeleMessage, used by Trump officials, can access plaintext chat logs
#67These are the guys trying to jail Krebs for being honest. They earned the “experts” they deserve.
Re: TeleMessage, used by Trump officials, can access plaintext chat logs
#68This may be a factual but not truthful article. This was initially framed to appear like the Trump Administration was doing something out of the ordinary by using Signal. There were also accusations that they were using Signal's disappearing message feature to conceal their activities from the authorities, and that they were breaking the Presidential Records Act, etc. Now it's revealed that they are using a version t…
Without more technical details about telemessage it isn't clear how archive servers are actually selected by the app, where they are hosted, or how they are secured. For example, while it's possible that DoD phones would only connect to Signal via proxies from within a VPN to a private network, direct Internet connectivity could lead to a potential leak of archived messages to any Internet-connected telemessage serve…
Re: TeleMessage, used by Trump officials, can access plaintext chat logs
#69Isn't that the point?
On top of that the company TeleMessage has access, and that is bad.
Re: TeleMessage, used by Trump officials, can access plaintext chat logs
#70Earlier quoted context omitted.
The point is that it was supposed to be end-to-end encrypted by this company all the way to the government's archive. That's what they claimed, but their service did no such thing.
How, in Signal's security model, could there be "end to end encryption all the way to the government archive"?
And that's what the actual quote says. End to end from phone to archive.