Live data from Hacker News

Technical analysis of the Signal clone used by Trump officials

micahflee.com

71–80 of 387 posts

Re: Technical analysis of the Signal clone used by Trump officials

#71
post #57

Earlier quoted context omitted.

Another reason: all of the folks on that group chat have legitimate reasons to have contacts on their phone that would be outside government apps. Foreign leadership. Journalists. Etc. Signal is likely to be one of the main ways of communicating with those.

Using separate apps for government and external communication might have prevented the recent scandal.

It wouldn't actually. The contact in his phone (incorrectly added by Apple AI from a forwarded email) would be the same regardless which app he was using.

Instead, Signal (and this forked version) would have to do its own independent contact management, maybe based on in-person scanning of QR codes plus web-of-trust.

Re: Technical analysis of the Signal clone used by Trump officials

#72
Still trying to grasp the idea of archiving messages from E2E encrypted communication system into a storage that entirely breaks the purpose of using something like Signal.

It’s like encashing on the trust of Signal protocol, app while breaking its security model so that someone else can search through all messages.

What am I missing here?

Re: Technical analysis of the Signal clone used by Trump officials

#73
post #57

Earlier quoted context omitted.

Another reason: all of the folks on that group chat have legitimate reasons to have contacts on their phone that would be outside government apps. Foreign leadership. Journalists. Etc. Signal is likely to be one of the main ways of communicating with those.

Using separate apps for government and external communication might have prevented the recent scandal.

[deleted]

Re: Technical analysis of the Signal clone used by Trump officials

#74
post #57

Earlier quoted context omitted.

Using separate apps for government and external communication might have prevented the recent scandal.

It wouldn't actually. The contact in his phone (incorrectly added by Apple AI from a forwarded email) would be the same regardless which app he was using. Instead, Signal (and this forked version) would have to do its own independent contact management, maybe based on in-person scanning of QR codes plus web-of-trust.

The contact (a journalist) wouldn't be reachable on a government messaging app.

Re: Technical analysis of the Signal clone used by Trump officials

#75
post #58

Earlier quoted context omitted.

The US and many other countries have been buying Israeli surveillance tools for years or decades. I would hope that any message archiving is being done on an organization-owned server though.

> I would hope that any message archiving is being done on an organization-owned server though. There's compelling evidence that the messages all pass through TM servers before being archived. https://www.404media.co/the-signal-clone-the-trump-admin-use...

There's compelling evidence that the messages all pass through TM servers before being archived.

The question is where the E2E encryption goes between.

Re: Technical analysis of the Signal clone used by Trump officials

#76

White House communications director previously revealed (after “Signalgate”) that Signal was an approved and whitelisted app for gov’t officials to have on work phones and even discuss top-secret matters on. But I haven’t heard that TeleMessage was approved (and I’d have serious questions if it were given the foreign intelligence factor). Anyone know if there is a clear answer to whether it’s been approved?

The correct answer is no one outside US Government IT knows for sure what is or isn't approved per their own rules. Every article (and comments therein) are just speculation and people trying to confirm their own biases, desperately looking for something to blame someone for, to produce more rage-bait and thus feed more ad clicks. Every single article is written with the presumption that there are no actual IT people…

[flagged]

Re: Technical analysis of the Signal clone used by Trump officials

#77
post #72

Still trying to grasp the idea of archiving messages from E2E encrypted communication system into a storage that entirely breaks the purpose of using something like Signal. It’s like encashing on the trust of Signal protocol, app while breaking its security model so that someone else can search through all messages. What am I missing here?

There are compliance reasons where you want the communications encrypted in flight, but need them retained at rest for compliance reasons. Federal record keeping laws would otherwise prohibit the use of a service like Signal. I'm honestly impressed that the people involved actually took the extra effort for compliance when nothing else they did was above board...

Re: Technical analysis of the Signal clone used by Trump officials

#78
post #16

> 404 Media journalist Joseph Cox published a story pointing out that Waltz was not using the official Signal app, but rather "an obscure and unofficial version of Signal that is designed to archive messages" Wow. And that's while their entire point of using Signal is to have conversations scrapped after a week to leave no no traces of criminal activity.

[deleted]

Re: Technical analysis of the Signal clone used by Trump officials

#79
post #16

> 404 Media journalist Joseph Cox published a story pointing out that Waltz was not using the official Signal app, but rather "an obscure and unofficial version of Signal that is designed to archive messages" Wow. And that's while their entire point of using Signal is to have conversations scrapped after a week to leave no no traces of criminal activity.

[deleted]
Post reply on HN