Live data from Hacker News

TeleMessage Explorer: a new open source research tool

micahflee.com

61–65 of 65 posts

Re: TeleMessage Explorer: a new open source research tool

#61
The TeleMessage dataset is massive and messy, and this tool lowers the barrier for journalists and researchers to extract meaningful insights. It’s also a reminder that “secure” enterprise tools often aren’t—especially when they’re built to satisfy compliance checkboxes rather than actual security principles. The fact that TM Signal was used by senior officials makes the plaintext logging and key exposure even more alarming. Kudos to Micah for not just reporting the breach but also enabling others to dig deeper.

Re: TeleMessage Explorer: a new open source research tool

#62

I don’t understand the value proposition of TeleMessage. Uses Signal but defeats the point of using Signal. Why not use a proper centralized chat with actual retention and encryption?

Only one person in the groupchat needs to be using Telemessage, ie. a CIA agent can use a government device with Telemessage to talk to sources on Signal. Signal has a great protocol & robust clients, and getting caught with Signal on your phone is probably a bit better than being caught with CIAChat on your phone.

The actual implementation here is atrocious though.

Re: TeleMessage Explorer: a new open source research tool

#63

I don’t understand the value proposition of TeleMessage. Uses Signal but defeats the point of using Signal. Why not use a proper centralized chat with actual retention and encryption?

> I don’t understand the value proposition of TeleMessage. Uses Signal but defeats the point of using Signal.

I kind of feel the same way about Signal itself due to its reliance on phone numbers.

Re: TeleMessage Explorer: a new open source research tool

#64

What seemed to be interesting from the email addresses disclosed is that there are a hell of a lot of people engaged in finance, investment or trading of one sort or another. There are a few there with enough emails for it to be relatively widespread within the institution: Scotiabank, JPMorgan, KKR and Jeffries stand out -- Scotiabank has hundreds of emails, I imagine they're having a bad week. Also a lot of energy…

I don't think a banks email being there indicates they use the service, more likely a customer of theirs uses TeleMessage and as a result the comms between that bank customer and the bank are in the breach

Re: TeleMessage Explorer: a new open source research tool

#65

Earlier quoted context omitted.

> the only way to do that is to have a modified client My firm requires screenshots. If the concern is that someone would bypass that, well, someone could bypass TeleMessage, too.

One has to wonder what type of legal requirement this satisfies. It certainly wouldn’t hold up to the “beyond a reasonable doubt” standard for US criminal prosecution. I’ve been exposed to “lit holds” for various document management system before and usually a third party such as Box or Microsoft can attest to the immutability of files placed under lit hold, and/or there is an audit trail to make sure the chain of cu…

Why not try a new Document Management system - comes witH AI oCr and Extraction module. Name - DocuSensa AI
Post reply on HN