7 ms·
As some details: TeleMessage is/was an Israeli company [1], but was acquired last year by Smarsh [2], itself a subsidiary of K1 Investment Management, both US
by cge 1y ago
As some details:
TeleMessage is/was an Israeli company [1], but was acquired last year by Smarsh [2], itself a subsidiary of K1 Investment Management, both US companies. It me whether the company moved. While not necessarily related at all, their terms of service also seem to explain specific arrangements for messaging in China that appear to involve disclosures to the Chinese government.
It's unclear to me how the app works. It appears to be advertised as a fork of the Signal client which uploads all content to a remote server, thus, of course, breaking the E2E encryption, unless the archive is considered an end and the connection to it is secure. It also appears to be advertised as being the same interface as Signal.
However, both the iOS and Android Signal clients are AGPLv3. I can't find any indication that the TeleMessage clients are anything other than proprietary. So are they going the route of giving the software and source only to paying customers under AGPLv3 (with those customers then free to distribute it)? Did they completely reimplement the client? Or are they an illegal proprietary fork?
The first option seems unlikely, and the latter two seem rather ominous for the security of the app.
[1]: https://en.wikipedia.org/wiki/TeleMessage https://en.wikipedia.org/wiki/TeleMessage
[2]: https://en.wikipedia.org/wiki/Smarsh https://en.wikipedia.org/wiki/Smarsh
- tptacek 1y agoSmarsh is apparently a big deal in the compliance space. They're not randos. That doesn't take away the hilarity of using a Signal clone that defeats the whole purpose of Signal, though.
- defen 1y agoAdditional hilarity provided by their name being one letter different from the latinisation of a Soviet spy agency / Bond supervillain organization.
- schoen 1y agoIt looks like it was originally meant as a reference to the username of the founder (Stephen Marsh).
- wisemang 1y agoLousy smarsh weather
- diamondage 1y agoSeems like an odd choice of name from an apparently low attack surface, cybersecurity aware company...
- obitsten 1y ago[dead]
- fluidcruft 1y agoJust wondering... if you work for a company and your employer provides you with modified GPL software, it's not considered distributed to you in ways that GPL would apply (so you are not free to further distribute it). At least that's how GPLv2 used to be explained as as business friendly--"private" modifications remain private and employees are not considered exterbal distribution. I'm not familiar with AGPL though.
- giancarlostoro 1y agoAGPL is essentially GPL but over the network, if you can reach the service (be it website, or any other protocol) you should be able to receive a copy of the source code. TruthSocial was based on AGPL'd code, they had to comply.
- sterlind 1y agoif your company itself modified the GPL software, you can't demand the modified source code from your boss. if your company purchased modified GPL software from a third party vendor, your company's legal department could force the vendor to cough up the source code.
- wmf 1y agoThe realpolitik here is that you can get fired if you leak the code, legal or not.
- giancarlostoro 1y ago> Or are they an illegal proprietary fork? As long as their clients can redistribute it, its not illegal, especially if their clients have 0 interest in leaking the source code, the real trick is, has anyone who is NOT using that client hit any of the AGPL relay servers? For context, I worked for an employer that sold a custom software solution, which used GPL'd software, client was in the military space, so I guess DOD, anyway, for over a decade nobody asked for any of the code, till some years back. I am guessing they just wanted to have it evaluated, but it was a workhorse of many many things, good luck trying to fork it, LOTS of moving pieces involved. Nothing illegal unless someone who touches a TM SGNL server (somehow) requests the source and they reject you from having it.
- cge 1y agoYes, that's what I meant by the possibility of them only offering source under AGPL to paying customers. Oddly enough, I'm familiar with that in the completely different context of davisr's reMarkable Connection Utility, and the model can work reasonably. But from their website, which has terms of service for each app, it really seems that they are presenting them as standard proprietary closed-source offerings.
- cwillu 1y ago> breaking the E2E encryption E2E doesn't mean what I think you think it means; specifically, it has nothing to do with what the intended recipient (or their software) does with the message.
- cge 1y agoThat very much depends on who is running the archive system, and how it is implemented. But more generally, your point is why I mentioned "unless the archive is considered an end and the connection to it is secure."
- IgorPartola 1y agoThe point of E2E is only to make sure that Alice is talking to Bob and nobody else can pretend to be either of them or eavesdrop. There is no reason whatsoever to include where else the message may be sent, encrypted or not. Consider E2E protected email service. You send me the final designs over this encrypted channel. Then I put the designs onto a USB drive and give them to my printer to print. Then I hang them as billboards all over town. This is a valid use case for E2E. Yet the contents of the message ends up visible from the freeway. You are confusing Snapchat mechanics for encryption.
- cwillu 1y agoPrecisely. The security of a message endpoint ends at the point that the opposite party's leverage runs out. If I care more about my snapchat account than I do about saving your disappearing message minus your ability to leverage snapchat into banning my account or apply outside social pressure, then your disappearing message may actually disappear. As the stakes go up, so does the leverage required for “endpoint security” to be a meaningful security boundary.
- UnreachableCode 1y agoIs there a term for any application which offers full control of your messages then, ie, I send you messages on Signal, but I can make them self destruct and you cannot screenshot them? (Pretty sure Signal allows this?). Nothing stopping a user from taking photos of the screen using another device, of course. Or running their own fork of Signal (which, when run from the open source for Android at least, runs on production).
- Hobadee 1y ago> unless the archive is considered an end and the connection to it is secure LMAO NO! I have quite a few clients using Telemeasage, and most of them use Global Relay on the backend. It's a little terrifying actually, as Global Relay just ingests everything via SMTP. I haven't checked if they have DNSSEC or MTA-STS set up, but with how Global Relay operates I would be surprised if they did. I suspect a well-placed proxy or DNS poisoning could siphon off a good chunk of sensitive emails being sent to Global Relay.