[flagged]
TeleMessage, used by Trump officials, can access plaintext chat logs
71–80 of 92 posts
Re: TeleMessage, used by Trump officials, can access plaintext chat logs
#72So far, no especially substantive analysis in this HN thread. What can anyone say at this point? A large portion of HN's commenters wouldn't make this mistake in a quickly written offhand comment.
Re: TeleMessage, used by Trump officials, can access plaintext chat logs
#73Earlier quoted context omitted.
How, in Signal's security model, could there be "end to end encryption all the way to the government archive"?
By saying that chatting and logging are separate processes, and each one has end to end encryption. Only the clients and the archive can see the text. And that's what the actual quote says. End to end from phone to archive.
Re: TeleMessage, used by Trump officials, can access plaintext chat logs
#74Earlier quoted context omitted.
In secure messaging as a cryptographic discipline, this is like saying you don't want secure messaging. Secure messaging is end-to-end secure, and the basic core threat modeling of a secure messaging service includes adversaries who defeat transit-only encryption. All this is to say: it's unremarkable to me that the Signal compliance fork government officials are using, which is premised on the capability of archivin…
Hypothetically, wouldn't the best Signal archiving be to make the custom client auto-add an archiving "user" to all chats, with that user only connected from secure archiving machines? Then convert archive user client text to whatever government encrypted form on that machine for long term storage? Curious what the best way of archiving with Signal's security model would be.
Re: TeleMessage, used by Trump officials, can access plaintext chat logs
#75Earlier quoted context omitted.
By saying that chatting and logging are separate processes, and each one has end to end encryption. Only the clients and the archive can see the text. And that's what the actual quote says. End to end from phone to archive.
But the entity we're saying has access to the plaintext is the archive .
The "Archive Destination" is the actual archive and the only thing that should have decryption keys.
Re: TeleMessage, used by Trump officials, can access plaintext chat logs
#76Re: TeleMessage, used by Trump officials, can access plaintext chat logs
#77Earlier quoted context omitted.
A leak to the press is one of the least damaging (relatively speaking) categories of leak, because intelligence officials quickly become aware. What's far more damaging is when secret communications are leaked to outside intelligence.
Right. What evidence is out there on the leak contents? All I have found is putting 2 and 2 together that this Signal variant has been used for months, the vendor was exploited and lost data, and vendor worked with clear texts logs. That leaves a lot of room for interpretation still. certain agencies on certain tenants, certain tenants were hacked but others, technical info like that.
Re: TeleMessage, used by Trump officials, can access plaintext chat logs
#78Anyone can change the client name and build it to mislead baddies when photographed in public.
Re: TeleMessage, used by Trump officials, can access plaintext chat logs
#79I'd find it useful if I could access my Signal chat logs in plaintext. The software offers no facility to do this on any platform, and on Desktop the programs that have allowed me to take proper backups are (by necessity) a moving target because of changes to the database, so I am constantly having to get around to updating them and occasionally even that's a pain.
It's usually impossible to regularly export your chats to a machine you own in a format you can use. Same with photo apps.
Re: TeleMessage, used by Trump officials, can access plaintext chat logs
#80Earlier quoted context omitted.
Hypothetically, wouldn't the best Signal archiving be to make the custom client auto-add an archiving "user" to all chats, with that user only connected from secure archiving machines? Then convert archive user client text to whatever government encrypted form on that machine for long term storage? Curious what the best way of archiving with Signal's security model would be.
There's a reason Signal doesn't archive, and you have to fork it to make that happen.