16 ms·
Mike Waltz Accidentally Reveals App Govt Uses to Archive Signal Messages
- lurkersince2013 1y agohttps://archive.ph/oXYXe https://archive.ph/oXYXe
- _heimdall 1y agoIt seems reasonable enough that the government may have built a forked version of signal with message archiving that meets documentation requirements. If its an app they wanted kept under wraps, it will make the while Hegseth situation seem a lot more benign. I use Molly Messenger on a secondary phone that doesn't have a SIM, its a fork of Signal with a few differences related to encryption at rest. It still works with normal signal users just fine, on the other end you can't tell I have a different client. If the government has a similarly forked version you could likely still accidentally invite the wrong user in from their normal Signal app and they wouldn't know you're on a forked version with government archiving features.
- FreakyT 1y agoMolly is great; I use it for the same purpose. I find the Signal devs' attitude so frustrating; they deliberately disable the ability to use Signal in secondary device mode for phone-sized-devices, because they know the Correct Way To Use Signal™ is to only use it on one phone-sized-device.
- firesteelrain 1y ago6 days ago there was the Hegseth article regarding this being hotly debated in here and it’s a great example of not having all the facts before jumping to conclusions. Part of the debate was regarding archiving of messages which now apparently there is a way to archive Signal messages automatically. Huh who would have figured
- ceejayoz 1y agoGreat motivated thinking, but wrong. It would appear they're using this app now, post-incident, because they got in trouble. (And having messages with Vance, Gabbard, etc. be visible to the press pool camera is... not a great look for the guy who accidentally added a reporter.) https://www.nytimes.com/2025/04/15/us/politics/cia-director-leaked-chat.html https://www.nytimes.com/2025/04/15/us/politics/cia-director-... > All of the messages from a leaked group chat have been deleted from the phone of John Ratcliffe, the C.I.A. director, the agency said in a court filing.
- chrisco255 1y agoThose are just accusations from a 3rd party agency. They have no way of knowing if Ratcliffe archived the messages before deleting. Signal has been approved since the Biden admin. It was most likely already distributed with the Telemessage feature.
- UnreachableCode 1y ago> Signal has been approved since the Biden admin. It was most likely already distributed with the Telemessage feature. How do you know this? Also I would not consider this a “feature”. We should assume they’re different apps, insofar as Telemessage can add whatever they please to the source
- firesteelrain 1y ago"One of the things I was briefed on very early … was by the CIA records management folks about the use of Signal as a permissible work use," Ratcliffe said during a March 25 Senate Intelligence Committee hearing (see 45:05). "It is. That is a practice that preceded the current administration to the Biden administration." https://www.c-span.org/program/senate-committee/dni-director-gabbard-fbi-director-patel-and-other-national-security-officials-testfy-on-global-threats/657476 https://www.c-span.org/program/senate-committee/dni-director...
- sumeno 1y agoIt was not built by the government and it's not some secret software, it's off the shelf software by an Israeli company.
- _heimdall 1y agoI didn't catch this in the article here. Is that well known elsewhere?
- sumeno 1y ago> But the message is slightly different: it asks Waltz to verify his “TM SGNL PIN.” This is not the message that is displayed on an official version of Signal. > Instead TM SGNL appears to refer to a piece of software from a company called TeleMessage which makes clones of popular messaging apps but adds an archiving capability to each of them. https://en.wikipedia.org/wiki/TeleMessage https://en.wikipedia.org/wiki/TeleMessage
- UnreachableCode 1y agoAcquired by a US company, Smarsh, according to other comments
- poink 1y agoIt's not only reasonable the US government should be archiving communications between officials, it should be compulsory. We've already had problems with this re: agents of government agencies like CBP and big bankers using E2EE messaging apps to skirt regulatory requirements. That said, whether this makes the situation better or worse depends on who can actually see these archives. "Smarsh" is a US-based company, but they acquired TeleMessage, which was (is?) based in Israel.
- dmix 1y agoSome of the top US government IT contractors are British, Canadian, and Italian owned companies. Running servers in the US for a government contract isn’t a big deal at a technical level.
- deleted 1y ago[deleted]
- UnreachableCode 1y ago> If the government has a similarly forked version you could likely still accidentally invite the wrong user in from their normal Signal app and they wouldn't know you're on a forked version with government archiving features. Is there no way Signal can prevent this in the official app?
- mmastrac 1y ago> TM SGNL appears to refer to a piece of software from a company called TeleMessage which makes clones of popular messaging apps but adds an archiving capability to each of them
- denkmoon 1y agoCrikey that's terrifying. Not even a US company either.
- jmathai 1y agoFTA, fwiw: "404 Media found numerous U.S. government contracts that mention TeleMessage specifically. One for around $90,000 from December 2024 says “Telemessage (a Smarsh Co.) Licenses for Text Message Archiving, & WhatsApp and Signal Licenses.”"
- Titan2189 1y agoTeleMessage is an Israeli software company based in Petah Tikva, Israel. Founded in 1999 by Guy Levit and Gil Shapira, it provides secure enterprise messaging, mobile communications archiving and high-volume text messaging services. https://en.wikipedia.org/wiki/TeleMessage https://en.wikipedia.org/wiki/TeleMessage
- bb88 1y agoEven though Israel is our "Ally" -- we really shouldn't trust a foreign company with our sensitive messaging. If you're in the government, you should treat Hegseth and anyone who uses Signal and TMSIGNL as compromised.
- decimalenough 1y agoIt's not like Israel would ever spy on the US right? https://en.wikipedia.org/wiki/Jonathan_Pollard https://en.wikipedia.org/wiki/Jonathan_Pollard
- 1y ago
- deleted 1y ago[deleted]
- janalsncm 1y agoIt’s possible Mike Waltz didn’t think the archiving capability was reliable enough, so he added a journalist to the group chat.
- pokstad 1y agoThat’s like in the old days when you needed to get married and grabbed a random nearby person to be the witness.
- onionisafruit 1y agoI doubt that’s happened more than twice in the history of marriage
- mattl 1y agoIt's happened more than once to me!
- incanus77 1y agoMy parents got married in 1975 in this way.
- joecool1029 1y agoI was the random person asked once before, didn't work though as my state requires a 72hour wait from filling out marriage application before you can be legally married. (Couple was eloping from another state and wanted to get married same day, were told it would have to be a different state)
- esafak 1y agoWhat is the point of using Signal if you are going to let a (foreign) company intercept your communications? I guess they wanted the UX of a commercial product instead of whatever clunky app that's approved for government. Does anyone know what the alternative was?
- sorcerer-mar 1y agoIt makes a lot more sense if you don't assume from the start these people have one iota of intellectual horsepower. Signal is approved for government uses, just not non-public DOD information. They're supposed to use Signal for something like "hey, get to a SCIF so we can discuss details," then they discuss the details in a secure environment.
- ezst 1y ago> Signal is approved for government use [Ref. needed]
- sorcerer-mar 1y agoApproved for government use: https://www.cisa.gov/sites/default/files/2024-12/guidance-mobile-communications-best-practices.pdf https://www.cisa.gov/sites/default/files/2024-12/guidance-mo... Not approved for non-public DOD information: https://dodcio.defense.gov/Portals/0/Documents/Library/Memo-UseOfUnclassMobileApps.pdf https://dodcio.defense.gov/Portals/0/Documents/Library/Memo-...
- Den_VR 1y agoGuidance from CISA (an agency within the Department of Homeland Security) does not translate to an Approval for DOD. The DOD memo does not supersede other DOD instructions referenced by the memo requiring RMF and NIAP things.
- sorcerer-mar 1y agoWe're saying the same thing, It's "use Signal for everything you'd use Whatsapp or SMS for, and use the standard secure channels for anything you'd typically need a secure channel for."
- cge 1y agoAs some details: TeleMessage is/was an Israeli company [1], but was acquired last year by Smarsh [2], itself a subsidiary of K1 Investment Management, both US companies. It me whether the company moved. While not necessarily related at all, their terms of service also seem to explain specific arrangements for messaging in China that appear to involve disclosures to the Chinese government. It's unclear to me how the app works. It appears to be advertised as a fork of the Signal client which uploads all content to a remote server, thus, of course, breaking the E2E encryption, unless the archive is considered an end and the connection to it is secure. It also appears to be advertised as being the same interface as Signal. However, both the iOS and Android Signal clients are AGPLv3. I can't find any indication that the TeleMessage clients are anything other than proprietary. So are they going the route of giving the software and source only to paying customers under AGPLv3 (with those customers then free to distribute it)? Did they completely reimplement the client? Or are they an illegal proprietary fork? The first option seems unlikely, and the latter two seem rather ominous for the security of the app. [1]: https://en.wikipedia.org/wiki/TeleMessage https://en.wikipedia.org/wiki/TeleMessage [2]: https://en.wikipedia.org/wiki/Smarsh https://en.wikipedia.org/wiki/Smarsh
- tptacek 1y agoSmarsh is apparently a big deal in the compliance space. They're not randos. That doesn't take away the hilarity of using a Signal clone that defeats the whole purpose of Signal, though.
- joejoo 1y ago[flagged]
- JumpCrisscross 1y ago“On Thursday Reuters published a photograph of Waltz checking his mobile phone during a cabinet meeting held by Donald Trump. The screen appears to show messages from various top level government officials, including JD Vance, Tulsi Gabbard, and Marco Rubio.” Head of NatSec, ladies and gentlemen. Once the domain of Kissinger, Brzezinski, Powell and Rice. Now with the opsec of a brain-damaged cocaine dealer.
- grg0 1y agoPin is 1234.
- stateofinquiry 1y ago"That's amazing! I've got the same combination on my luggage!"
- cantrecallmypwd 1y agoLooks at each other disapprovingly. (It was 1-2-3-4-5.)
- KerrAvon 1y agoKissinger and Rice are war criminals who should have gone to jail for the rest of their respective lives. Trump’s guy can’t even manage that level of evil.
- wiseowise 1y agoWar criminals or not, you can’t deny they were smart. Unlike current administration.
- cantrecallmypwd 1y agoIntelligence isn't a respectable quality in the face of illegal (allegedly), unethical, and/or immoral behavior. Kissinger shared culpability for what happened in Cambodia, Laos, and Vietnam. Rice shares culpability for what happened in Afghanistan and Iraq. Hegseth may still participate in war crimes regardless of being a dim bulb. One can only hope his disability makes him less effective in causing harm deliberately, but he still may cause great harm inadvertently as well. America needs to acknowledge that it has a multitiered system of selective criminal prosecution where some people get away with crimes because of who they are.
- giancarlostoro 1y agoLooks like the app is this one? https://www.telemessage.com/how-to-install-and-register-signal-archiver-from-the-ios-app-center/ https://www.telemessage.com/how-to-install-and-register-sign...
- deleted 1y ago[deleted]
- UnreachableCode 1y agoChrist. Install it using an App Centre distribution
- arghandugh 1y ago[flagged]
- JumpCrisscross 1y agoWaltz was chosen for loyalty. He simply isn’t very smart. There is no grand plan behind getting your screen photographed while chatting with the VP, DNI and SecState.
- UnreachableCode 1y agoShouldn’t any government issued smartphone have privacy screen protectors at the very least?
- OhioMan2943 1y agoI don't get it. Why risk secuity vulnerabilities to archive when you can just ask israel and pegasus for the archives anyway.
- OhioMan2943 1y agoWait this is israeli. Lol.
- deleted 1y ago[deleted]
- IG_Semmelweiss 1y ago>>> overnment agencies have paid for versions of encrypted messaging apps that also have archive abilities before. In 2021, Customs and Border Protection (CBP) paid encrypted app company Wickr $700,000. This seems like a perfect use case to support Signal. Have large, corporate or govt entities, pay for a custom fork of the app, built by the app developers themselves. Why is telemessage getting the money ? Does the Signal Foundation not make it easy to do paid fork implementations ?
- mmooss 1y agoMaybe Signal needs to devote all their resources to develping the main app, which is their mission - secure communications for the general public.
- bigfatkitten 1y agoThey have ‘interesting’ priorities. MobileCoin is prioritised ahead of allowing an iPad-like secondary device experience on Android tablets, for example.
- mmooss 1y agoWhat makes you say that? I would guess they would do both if it was worthwhile. Android tablets and iPads have different capabilities under the hood - maybe the requirements aren't possible on Android tablets? In any case, saying their priorities are misaligned because they don't scratch your particular itch is making a mountain of a molehill.
- bigfatkitten 1y agoIt has nothing to do with device capabilities or technical effort, and there are client forks which support it. Signal have simply made a conscious choice to disallow it. https://community.signalusers.org/t/android-tablet-support/5590/262 https://community.signalusers.org/t/android-tablet-support/5...
- bamboozled 1y ago"He's just joking"
- whimsicalism 1y ago> 404 Media found numerous U.S. government contracts that mention TeleMessage specifically. One for around $90,000 from December 2024 says “Telemessage (a Smarsh Co.) Licenses for Text Message Archiving, & WhatsApp and Signal Licenses.” A blatant AGPL violation, no? Were they using Signal in the Biden admin or do these contracts get setup in prep for the new team?
- qingcharles 1y agoWould love to know what the message from JD means: "I have confirmation from my counterpart it's turned off."
- brewdad 1y agoOMG. He turned off the Pope!
- cryptonector 1y agoAt least this takes care of the open records issues, no?
- MaxPock 1y agoWouldn’t it be more effective for the government to develop a highly secure communication app, known only to individuals in top-level positions? This app would be discreetly installed upon appointment to a senior government role and automatically removed upon departure from office.
- kristjansson 1y agoThat's ... that's the communication network they're avoiding? Because the problem is not _which_ app, it's that it's _an_ app, on standard hardware, on the public internet?
- UnreachableCode 1y agoOnly, made by an Israeli company that presumably doesn’t make their version of Signal open source
- aorloff 1y agoA lot more legal too.
- cantrecallmypwd 1y agoYes and no. No, not for classified comms. They already have secure comms and SCIFs but they're not using them. This is what they should be using. And they should be following sterile opsec so they don't carry tracking and listening devices into classified meetings or strategy discussions with decision makers. They do need better opsec for unclassified and personal comms. It would be nice™ for them to have a Signal-like app controlled by the NSA because depending on Signal or WhatsApp is vulnerable to a malicious insider. Few Meta employees have security clearances, while I don't know about Signal.
- sagarpatil 1y agoSo is signal safe or not?
- brewdad 1y agoThere's nothing to suggest Signal is compromised. Once you are passing your Signal data through a third party...who knows?
- EasyMark 1y agoSignal is fine, what's not fine is using it for top secret messages on your average everyday phone which is apt to get hacked by state actors and their mercenaries if you're important enough to be on their radar.
- mmooss 1y agoAlso it's not secure to share info in Signal chats with people who lack clearance.
- SurfShoulders 1y ago[dead]
- michaelteter 1y agoClown car.
- deleted 1y ago[deleted]
- mdhb 1y agoSo wait… They are using a Signal clone that is run by a group of Israeli intelligence officers?? I don’t think that part of the story has broken yet properly. When you go to google maps for the address listed for that company you actually get a company called “Cyberint” which seems extremely not good. https://maps.app.goo.gl/L7vVHw5x4VdgS8859?g_st=com.google.maps.preview.copy https://maps.app.goo.gl/L7vVHw5x4VdgS8859?g_st=com.google.ma... Worse.. when you take a look at the bios for the company on their website I see that it’s filled with supposedly “ex” Israeli intelligence officers including the CEO among others. https://www.telemessage.com/team/ https://www.telemessage.com/team/ That seems like a MUCH MUCH bigger deal than they currently known story. Like several orders of magnitude bigger than the original signalgate story. The implication here is that a bunch of Israeli intelligence officers have maybe the best access of anyone in the world right now in that they have a real time feed of every conversation that the US national security advisor is a part of.