7 ms·
TeleMessage Explorer: a new open source research tool
See also: TeleMessage customers include DC Police, Andreessen Horowitz, JP Morgan, and hundreds more:
https://micahflee.com/telemessage-customers-include-dc-police-andreesen-horowitz-jp-morgan-and-hundreds-more/ https://micahflee.com/telemessage-customers-include-dc-polic...
- klooney 1y agoHeap dumps on the Internet. Java ecosystem has some criminal defaults.
- mdhb 1y agoIt’s truly wild that something like this exists. It really speaks to the unfathomable levels of incompetence that this is what the Trump administration was using to plan military operations over.
- owlninja 1y agoAnd we all drop our jaws, wonder what is happening, and then wake up to a slurry of new stories.
- stepupmakeup 1y ago[flagged]
- OneDeuxTriSeiGo 1y agoIt's a data leak that was posted publicly online. Yes DDoSSecrets restricts access to verified journalists and security researchers but if you don't fall under that criteria you can always just get it the old fashioned way by digging around for torrents of data leaks like everyone else has done since forever.
- ipsum2 1y agoIsn't DDoSSecrets the only one that has access to the hacked/downloaded dataset, so there wouldn't be other copies floating around unless someone else simultaneously downloaded the dataset at the same time? Someone can prove me wrong by dropping a magnet link. :)
- deleted 1y ago[deleted]
- tamirmag 1y agoDoes the importer validate heapdump JSON and flag malformed records before they reach PostgreSQL?
- throw10920 1y agoI'm hoping that this will be yet another shot in the war to convice corporations and government agencies that they need to have on-prem data hosting that isn't accessible to the company running the service. I don't think you can do full E2E between individual employees in a corporate setting, but at the very least if all of the organization's data is only accessible to the organization, that'll help with a lot of these third-party data beaches. (it won't help when the organization is beached, which unfortunately still seems to be the main way that user data gets leaked) Ultimately, though, until there starts to be federal law mandating chain of custody for user data and harsh penalties on it being leaked, I think that this will continue for a long time... Update: I should have read the article - did not realize TeleMessage was supposed to be E2E. I guess now the lesson is that you shouldn't be using normal devices for national security information (classified or not), and otherwise it's still not good to use a sketchy service that doesn't have Moxie-grade crypto implementations.
- AtlasBarfed 1y agoIf a company knows something about you, so does the government(s). This is exactly the state of affairs the government prefers. Privacy and consumer protection long died on the altar of turnkey totalitarian universal monitoring. By having corps do the creepiest data collection, whatever all political opposition to the complete surveillance state is bypassed
- reactordev 1y agoJust so long as every once in a while, they convince some junior senator to hold a hearing to throw some executive at them that will use it as a way of earning clout within the company and no one cares about the outcome. The junior senator will lament about their political opponents, the committee will pat itself on the back for doing their job, the corporate crony will report back to the board that they delivered the talking points, and it will go right back to business as usual.
- JumpCrisscross 1y ago> if a company knows something about you, so does the government(s) The constant litigation between the government and private companies over records requests should put this hypothesis to bed.
- ComputerGuru 1y agoI don’t understand the value proposition of TeleMessage. Uses Signal but defeats the point of using Signal. Why not use a proper centralized chat with actual retention and encryption?
- ocdtrekkie 1y agoConsidering they accidentally included a journalist, compatibility with the existing user network. If you need logged chat with normal Signal users, TeleMessage would probably be the way to do this.
- ls612 1y agoYou might be subject to compliance requirements for archival but also want to talk to other people who use signal.
- kevincox 1y agoFor example DC Police may have confidential informants who would be best to use Signal because that isn't unusual. But the people there are communicating need to retain the communication.
- whatshisface 1y agoSo basically, you tell at-risk people they're E2E, but keep a copy on whatever storage system you want to use and send another to your friends.
- ls612 1y agoE2EE’s biggest use case is preventing the government from reading your messages. If you are messaging the government (or are in the government) then this isn’t relevant.
- mingus88 1y agoThis has always been possible with screenshots. SGNL is just an enterprise solution. At the end of they day you need to trust who you are talking to and never over share.
- klooney 1y agohttps://shewantstheisrd.myshopify.com/products/clean-on-opsec-pre-order https://shewantstheisrd.myshopify.com/products/clean-on-opse... I found the sticker
- 9dev 1y agoThat one is pure gold.
- FilosofumRex 1y ago[flagged]
- snarf21 1y agoObviously, it isn't about that. Our government just doesn't want anyone but them spying on its citizens.
- ujkhsjkdhf234 1y agoIt isn't even about that. Tiktok is taking market share from FAANGs. Zuckerberg has spent a pretty penny on this Tiktok disinformation campaign and if you look at the members of Congress behind the ban Tiktok bill, most of them purchased huge amounts of Meta stock before introducing it to Congress. It's corruption all the way down.
- mschuster91 1y ago> Zuckerberg has spent a pretty penny on this Tiktok disinformation campaign There's more than enough reports from outside the US that credibly allege TikTok is a critical factor in the radicalization and recruitment of the far-right and militant Islamism [1][2][3]. Conspiracies about Zuckerberg wanting to dunk on a competitor aside (that may or may not be real, and I'm heavily inclined to believe they are true), the threat from TikTok is real, this application needs to be exterminated at all cost before China completely tears apart our society. [1] https://www.bpb.de/lernen/digitale-bildung/werkstatt/560523/tiktok-als-antisemitischer-radikalisierungstunnel/ https://www.bpb.de/lernen/digitale-bildung/werkstatt/560523/... [2] https://www.zdf.de/nachrichten/politik/deutschland/radikalisierung-tiktok-lka-social-media-100.html https://www.zdf.de/nachrichten/politik/deutschland/radikalis... [3] https://www.tagesschau.de/inland/regional/hessen/hr-wandern-wiesen-wehrmacht-so-koedern-rechtsextreme-jugendliche-auf-tiktok-und-telegram-100.html https://www.tagesschau.de/inland/regional/hessen/hr-wandern-...
- verdverm 1y agoBoth assertions can be true at the same time
- specproc 1y agoWhat seemed to be interesting from the email addresses disclosed is that there are a hell of a lot of people engaged in finance, investment or trading of one sort or another. There are a few there with enough emails for it to be relatively widespread within the institution: Scotiabank, JPMorgan, KKR and Jeffries stand out -- Scotiabank has hundreds of emails, I imagine they're having a bad week. Also a lot of energy stuff, Aramco, Total.
- jxjnskkzxxhx 1y agoDo you understand how emails come into this? I thought signal used only phone numbers...
- tough 1y agoSince TeleMessage is not really signal but just a front the israelis want your email to signup (its mostly an enterprise service, so you either pay and they know who you are already) etc this is like slack for signal
- a_dabbler 1y agoI don't think a banks email being there indicates they use the service, more likely a customer of theirs uses TeleMessage and as a result the comms between that bank customer and the bank are in the breach
- heywoods 1y agoFrom the other article which shared the email domains found in the heap. Sorry in advance for the poor formatting. --- Source: `https://micahflee.com/telemessage-customers-include-dc-police-andreesen-horowitz-jp-morgan-and-hundreds-more/ https://micahflee.com/telemessage-customers-include-dc-polic...` ### I. Industry Breakdown *Financial Services (Dominant):* This is by far the most represented sector. It encompasses a wide array of sub-sectors: * *Investment Banking & Brokerage:* A large number of domains belong to global and regional investment banks, interdealer brokers, and brokerage firms. * Examples: `jefferies.com`, `morganstanley.com`, `cantor.com`, `tpicap.com`, `bgcg.com`, `rjobrien.com`, `clarksons.com` (shipping finance/brokerage) * *Asset & Investment Management:* Numerous firms managing diverse asset classes for institutional and private clients are present. * Examples: `kkr.com`, `aresmgmt.com`, `pimco.com`, `nuveen.com`, `franklintempleton.com`, `apg-am.com` * *Banking (Commercial & Private):* Major multinational and regional banks are included, covering commercial, private, and retail banking. * Examples: `jpmorgan.com`, `bbva.com`, `cibc.com`, `scotiabank.com` (and its numerous regional variations), `bradescobank.com`, `safra.com`, `standardbank.co.za`, `dbank.co.il` * *Wealth Management:* Firms specializing in wealth advisory for high-net-worth individuals are visible. * Examples: `gentrustwm.com`, `boltonglobal.com`, `rohrpwm.com` * *Cryptocurrency & Digital Assets:* A significant and growing sub-sector, with exchanges, trading firms, and investment managers focusing on digital assets. * Examples: `coinbase.com`, `galaxydigital.io`, `b2c2.com`, `hiddenroad.com`, `aminagroup.com` (formerly SEBA), `panteracapital.com` * *Fintech & Financial Technology:* Companies providing technology solutions for the financial industry, including trading platforms and compliance tools. * Examples: `smarsh.com`, `telemessage.com`, `interactivebrokers.com` * *Venture Capital & Private Equity:* A strong showing of firms investing across various stages and sectors, from early-stage tech to large buyouts. * Examples: `a16z.com`, `sequoiacap.com` (implied), `vistaequitypartners.com`, `lcatterton.com`, `ardian.com`, `tigerglobal.com`, `tcv.com`, `bitkraft.vc`, `blockchaincapital.com` *Energy & Commodities:* This sector is well-represented by: * *Trading Houses:* Global and regional commodity traders dealing in oil, gas, metals, and agricultural products. * Examples: `vitol.com`, `gunvorgroup.com`, `eni.com` (also integrated), `amerexenergy.com`, `amius.com`, `pvm.co.uk` * *Energy Companies (Integrated & Exploration/Production):* Major oil and gas companies and related services. * Examples: `totalenergies.com`, `petrobras.com`, `marathonpetroleum.com`, `p66.com`, `aramcotrading.us` *Government & Public Sector:* Primarily U.S. government entities, including: * *Federal Agencies:* * Examples: `cbp.dhs.gov` (Customs and Border Protection), `usss.dhs.gov` (Secret Service), `dfc.gov` (Development Finance Corporation), `who.eop.gov` (White House Office) * *Local Government:* * Example: `dc.gov` (District of Columbia Government) *Technology (Non-Fintech Focus):* While many tech firms are Fintech-related, some general software and IT service providers are present. * Examples: `nice.com`, `nebari.com`, `vlmsofts.com` *Consulting:* A smaller representation, often specialized. * Example: `soteriasolutions.us` (safety/threat management) *Real Estate:* Investment and advisory firms in the real estate sector. * Examples: `eastdilsecured.com`, `digitalbridge.com` (digital infrastructure) *Shipping & Logistics:* Companies involved in shipping brokerage and services. * Examples: `clarksons.com`, `mcquilling-energy.com`, `freightinvestor.com` ### II. Geographical Breakdown (Based on domain extensions and company descriptions) * *United States (Dominant):* A very large portion of the entities are U.S.-based or have significant U.S. operations. This is evident from the high number of `.com` domains associated with American companies and the presence of `.gov` domains. * Major financial centers like New York and tech hubs in California are implicitly represented (e.g., `aresmgmt.com`, `kkr.com`, `a16z.com`, `morganstanley.com`). * *Canada:* A strong presence, particularly Scotiabank and its various divisions, along with other financial and tech firms. * Examples: `scotiabank.com`, `scotiabank.ca` (implied), `cibc.com`, `bitbuy.ca`, `wonder.fi` * *United Kingdom:* Well-represented in finance (banking, brokerage, asset management) and commodities. London's role as a global financial hub is evident. * Examples: `cantor.co.uk`, `pvm.co.uk`, `ubauk.com`, `hbluk.com`, `rmb.co.uk`, `amcgroup.com` * *Latin America:* Several domains indicate operations or focus in this region, with Scotiabank having a particularly strong showing. * *Mexico:* `scotiabank.com.mx`, `scotiacb.com.mx`, `scotiawealth.com.mx` * *Chile:* `scotiabank.cl`, `larrainvial.com` * *Peru:* `scotiabank.com.pe` * *Colombia:* `scotiabankcolpatria.com` * *Brazil:* `br.scotiabank.com`, `petrobras.com.br`, `bradescobank.com`, `itaubba.eu` (European arm of Brazilian bank) * *Panama:* `pa.scotiabank.com` * *Europe (excluding UK):* * *France:* `totalenergies.com`, `ardian.com`, `mbcfrance.com` * *Switzerland:* `seba.swiss` / `aminagroup.com`, `hnwag.com`, `itau.ch` * *Monaco:* `tyruscap.mc` * *Netherlands:* `apg-am.com` * Other European presences through global firms (e.g., `itaubba.eu`). * *Asia:* Highlighting its role as a financial hub. * *Hong Kong:* `apg-am.hk` * *Singapore:* `apg-am.sg`, `gfigroup.com.sg`, `icap.com.sg`, `sg.pimco.com`, `traditionasia.com` * *Japan:* `mitsui.com`, `tullettprebon.co.jp`, `smbcgroup.com` * *Israel:* `dbank.co.il`, `fibi.co.il`, `opco.co.il`, `nice.com` * *Indonesia:* `miraeasset.co.id` * *Middle East:* * *UAE:* `freightinvestor.ae`, `aramcotrading.us` (US trading arm of Saudi Aramco) * General presence of firms like Alpha Wave Global with strong ties to the region. * *Africa:* * *South Africa:* `standardbank.co.za` * *Global:* Many firms operate globally, even if headquartered in a specific country (e.g., `a16z.com`, `kkr.com`, `morganstanley.com`). ### III. Notable Trends & Observations * *Dominance of Financial Services:* The sheer volume of financial sector domains underscores its significant role in this context. * *Globalization of Finance:* Many financial institutions have multiple country-specific domains (e.g., Scotiabank, PIMCO, ICAP/TP ICAP), reflecting international operations. * *Rise of Digital Assets:* Numerous cryptocurrency exchanges, traders, and VCs focused on Web3 indicate the growing institutionalization of this asset class. * *Concentration of Energy Trading:* A significant number of specialized energy and commodity trading firms are present. * *Venture Capital Focus on Technology:* Many VC firms listed are known for investments in technology and, increasingly, blockchain/crypto. * *Government Presence:* Inclusion of U.S. federal and local government domains suggests interactions with these regulatory or administrative bodies. * *Prevalence of `.com`:* Despite geographical diversity, `.com` remains the most common top-level domain. * *Personal Email Addresses (`gmail.com`):* The presence of a few Gmail addresses (6 emails) is minor but indicates not all communications are necessarily from official corporate domains. ---
- cypherpunks01 1y agoSignal is licensed under GNU AGPLv3 - think there will be any action against the company for license violations? I suppose it's the least of their liabilities, but just wondering.
- cavisne 1y agoThe signal protocol is public, using their servers is frowned upon but its not a source code license violation.
- lzy 1y agoThe TeleMessage dataset is massive and messy, and this tool lowers the barrier for journalists and researchers to extract meaningful insights. It’s also a reminder that “secure” enterprise tools often aren’t—especially when they’re built to satisfy compliance checkboxes rather than actual security principles. The fact that TM Signal was used by senior officials makes the plaintext logging and key exposure even more alarming. Kudos to Micah for not just reporting the breach but also enabling others to dig deeper.