6 ms·
TeleMessage, used by Trump officials, can access plaintext chat logs
- theyknowitsxmas 1y agoAnyone can change the client name and build it to mislead baddies when photographed in public.
- deleted 1y ago[deleted]
- dang 1y agoRecent and related: Technical analysis of the Signal clone used by Trump officials - https://news.ycombinator.com/item?id=43875476 https://news.ycombinator.com/item?id=43875476 - May 2025 (313 comments)
- ChrisArchitect 1y agoMike Waltz Accidentally Reveals App Govt Uses to Archive Signal Messages https://news.ycombinator.com/item?id=43865103 https://news.ycombinator.com/item?id=43865103
- chipsrafferty 1y ago[flagged]
- deleted 1y ago[deleted]
- proactivesvcs 1y agoI'd find it useful if I could access my Signal chat logs in plaintext. The software offers no facility to do this on any platform, and on Desktop the programs that have allowed me to take proper backups are (by necessity) a moving target because of changes to the database, so I am constantly having to get around to updating them and occasionally even that's a pain.
- XorNot 1y agoIt'd also be useful if backups on Android actually streamed somewhere off the phone so they could be meaningfully appended to, kept. Or handled per channel (i.e. my baby pictures channel with family).
- proactivesvcs 1y ago...and if the restore process wasn't so fragile. The only time I needed to backup and restore it just crashed part-way through, so the backup process wasn't even doing any validation.
- hedora 1y agoThe lack of encrypted (and cross platform) backups is the biggest security hole I know of in Signal. People inevitably end up working around it, which can mean using SMS, copying the threads / screenshots / attachments to arbitrary other storage, or switching to things like TeleMessage because of record keeping requirements. I wish Signal were less hostile towards forks. I'd happily switch to a client that uses their network, but that's compatible with iCloud backup.
- Zambyte 1y agoThis comment confused me a lot, because Signal has encrypted backups, just not cross platform. Looking into it more, it seems that iOS only has a "transfer" option instead of allowing backups. It's hard not to suspect this is due to arbitrary limitations on filesystem access on iOS.
- csours 1y agoOh dear, this seems to be a bit of a footgun.
- deleted 1y ago[deleted]
- tptacek 1y agoIsn't that the point?
- deleted 1y ago[deleted]
- deleted 1y ago[deleted]
- Aurornis 1y agoNo, the point is for the government to have access the plaintext after it is securely delivered to an approved archive location, not TeleMessage having access on AWS-hosted servers exposed to the public internet. TeleMessage pitched their service as using end-to-end encryption of the message into the corporate archive. > End-to-End encryption from the mobile phone through to the corporate archive Apparently the plaintext messages were going to a TeleMessage server on AWS (not an approved government archive location) that was publicly accessible. Naturally it was hacked.
- fnordpiglet 1y agoI doubt that’s the point either. The government should have cipher text they are able to decrypt in an approved archive location with rigorously managed key material and a careful cryptographically variable chain of custody from its inception. Plain text should never factor into this.
- matthewdgreen 1y agoThe US government does have storage facilities and secure messaging tools with escrow, all designed for exactly this use-case (secure messaging amongst DoD personnel.) But the whole point of Signal+TeleMessage was to route around that "clunky stuff" by outsourcing it to a vendor.
- fnordpiglet 1y ago
- fnordpiglet 1y agoThese are the guys trying to jail Krebs for being honest. They earned the “experts” they deserve.
- deleted 1y ago[deleted]
- actionfromafar 1y agoAnd still there is ample support for the administration, also here. I am curious how much of it is through cognitive dissonance and how much not thinking too hard about the stuff a particular supporter don't like, and how much of it is with eyes open, embracing the crazy and the incompetence for some "higher goal" whatever that may be. (It also probably is very different, all from "own the libs" through "escalate the second coming of Christ" or any combination thereof.)
- mtlynch 1y agoFor anyone else confused, "Krebs" in this context refers to Chris Krebs[0, 1], former Director of the US Cybersecurity and Infrastructure Security Agency. Chris Krebs is unrelated to Brian Krebs of Krebs on Security. [0] https://en.wikipedia.org/wiki/Chris_Krebs https://en.wikipedia.org/wiki/Chris_Krebs [1] https://www.whitehouse.gov/fact-sheets/2025/04/fact-sheet-president-donald-j-trump-addresses-risks-from-chris-krebs-and-government-censorship/ https://www.whitehouse.gov/fact-sheets/2025/04/fact-sheet-pr...
- khaki54 1y agoYou DO realize that TeleMessage was put in place and procured before Trump took office right?
- deleted 1y ago[deleted]
- yapyap 1y agogenius
- aeontech 1y agoWhy bother hacking your phone and installing a keylogger when we can convince your IT department to buy it and install it for your entire team. Have to say, this is pretty epic.
- deleted 1y ago[deleted]
- khaki54 1y agoThis may be a factual but not truthful article. This was initially framed to appear like the Trump Administration was doing something out of the ordinary by using Signal. There were also accusations that they were using Signal's disappearing message feature to conceal their activities from the authorities, and that they were breaking the Presidential Records Act, etc. Now it's revealed that they are using a version that actually archives all the messages to be compliant with the law and individual Agency policies. The new theory is that the Trump Administration is doing something especially nefarious by archiving the messages and/or they are doing it insecurely and they are controlled by Israel. First and foremost, the Signal infrastructure was setup in most cases by the previous administration! Even a cursory search of USA Spending reveals millions were spent on telemessage before Trump was elected. https://www.usaspending.gov/search?hash=d900bda0a5eccae47ba7655a5ac2830f https://www.usaspending.gov/search?hash=d900bda0a5eccae47ba7... I'm not a journalist, but look for yourself. As for accusations that what the Biden Administration procured and configured is insecure: it's not. TeleMessage has a configuration approved for CUI that integrates with GCC-high (IL4) and O365 DoD (IL5). Thus they are fine to collect and archive unclassified CUI, ITAR, NSS data, command and control/ISR, tactical data, etc. "TeleMessage can go a long way in enabling regulatory compliance by working with Microsoft to capture, archive, and maintain text messages, voice calls, and other files, leading to stress-free adherence to all the security controls required as per FedRAMP. Crucially, the mobile archiver supports Microsoft 365 Government Community Cloud, Government Community Cloud High, and Department of Defense solutions across all devices, carriers, and instant messengers. Federal agencies and contractors can issue their own phones to personnel or have their employees use their own BYOD devices because TeleMessage can still securely retain all the communication within its servers or have it forwarded to a data storage vendor of choice. There is also the option of cross-carrier and international mobile text and calls archiving." -- https://web.archive.org/web/20250502041804/https://www.telemessage.com/fedramp-environments-explained/ https://web.archive.org/web/20250502041804/https://www.telem... So far they're good in theory. They decrypted messages are transmitted in at least 1 encrypted wrapper (TLS) to mobile archiver, then ultimately landing in the DoD Azure cloud environment. The question is whether the whole chain after the phone is in the DoD environment, or if it routes through Telemessage's systems. If you look at the hack (https://archive.ph/yyyLg https://archive.ph/yyyLg), initially it leads you to believe that the message archiver doesn't live in the DoD environment and instead lives in AWS commercial or some lesser rated cloud. I think this is only true some of the time. Note in the hack, they only have messages from CPB. They don't appear to have any .mil, cia.gov, eop.gov, etc. CBP doesn't have access to the IL5 DoD Tenant in the first place and their archiver is likely hosted in AWS Commercial or AWS East/West (IL2). Frankly, I don't think that any of the higher sensitivity organizations will be routing through a TeleMessage controlled server, or any server lower than IL4. They host that piece on their own infrastructure.
- Zambyte 1y ago[flagged]
- mmooss 1y agoSo far, no especially substantive analysis in this HN thread. What can anyone say at this point? A large portion of HN's commenters wouldn't make this mistake in a quickly written offhand comment.
- deleted 1y ago[deleted]
- dogman144 1y agoIt’s probably against the rules to self-link old comments. And it’s hard to be remotely proud about having a good take on this news as it unfolded. However, when this first broke, select HN users were claiming this was OPSEC 4D chess and not deeply irresponsible cybersec practices. That was a terrible take then, and it’s a terrible take now. Clear as day when this started there was a nasty vendor supply chain risk lurking, and if it was 4D cybersec chess it was done by some absolute muppets. Bad setups get exploited in natsec. A bad setup exploited. Sounds like a brutal US natsec leak is brewing.
- whatshisface 1y agoBrewing? This is it. All of these messages have been leaking; that's what the article is about.
- dogman144 1y agoHave you found info on the chat texts? Referring to “a leak” as in these chats go public in some form vs into a RU SCIF somewhere, and that there’s some verification of what the clear text chats were/who’s in it. I am speculating it’ll be the latter scenario, with periodic strategic leaks.
- whatshisface 1y agoA leak to the press is one of the least damaging (relatively speaking) categories of leak, because intelligence officials quickly become aware. What's far more damaging is when secret communications are leaked to outside intelligence.
- dogman144 1y agoRight. What evidence is out there on the leak contents? All I have found is putting 2 and 2 together that this Signal variant has been used for months, the vendor was exploited and lost data, and vendor worked with clear texts logs. That leaves a lot of room for interpretation still. certain agencies on certain tenants, certain tenants were hacked but others, technical info like that.
- asadm 1y ago[flagged]
- deleted 1y ago[deleted]
- mersorion 1y agoStories like this are why we started the gospl.chat project I've been part of. Most so called “secure” systems sabotage themselves not by accident, but because of compromises. There's always an attempt to “secure the system” for the system which often results in architectures that fail the people they're supposed to protect. Industry headliners often focus on encryption protocols, but E2EE alone doesn’t guarantee safety. If a user or business finds themselves in a life-threatening situation most messaging platforms will do nothing to protect them and may even become part of the threat. We approached gospl.chat from the opposite direction - modeled real world threats and built a communication system that minimizes the risk of harm, even in worst-case scenarios. Security isn’t just about math. It’s about context. It’s about the environment where an app is used and how it behaves when things go wrong. Our goal isn’t to win a crypto audit. It’s to make sure no one loses their freedom, safety, or life because of a message.
- felishiagreen12 1y ago[flagged]