9 ms·
White House communications director previously revealed (after “Signalgate”) that Signal was an approved and whitelisted app for gov’t officials to have on work
by ComputerGuru 1y ago
White House communications director previously revealed (after “Signalgate”) that Signal was an approved and whitelisted app for gov’t officials to have on work phones and even discuss top-secret matters on. But I haven’t heard that TeleMessage was approved (and I’d have serious questions if it were given the foreign intelligence factor). Anyone know if there is a clear answer to whether it’s been approved?
- ceejayoz 1y agoThe White House communications director lies continually, so the value of that statement is nil.
- dashundchen 1y ago[flagged]
- ceejayoz 1y agoShe’s the deputy. Steven Cheung is the director. Both people issue Baghdad Bob style statements.
- deleted 1y ago[deleted]
- donnachangstein 1y agoThe correct answer is no one outside US Government IT knows for sure what is or isn't approved per their own rules. Every article (and comments therein) are just speculation and people trying to confirm their own biases, desperately looking for something to blame someone for, to produce more rage-bait and thus feed more ad clicks. Every single article is written with the presumption that there are no actual IT people in the White House, that someone wheeled in a Starlink dish on a dessert cart in the yard which is somehow running the entire government. It's silly and ridiculous.
- ceejayoz 1y ago> It's silly and ridiculous. As is putting someone with a brain parasite and anti-vax beliefs as the head of HHS, but here we are. “Silly and ridiculous” does not mean “implausible” with this administration. It’s the standard.
- gopher_space 1y ago[flagged]
- mmooss 1y agoPalantir has a lot of IT employees, as does Oracle and Musk's companies, which actively support Trump.
- runlevel1 1y agoAre you trying to prove their point?
- gavin-1 1y agoWhat does conservative brain drain mean?
- michaelt 1y agoA few decades ago, the Republican party had one foot in the anti-intellectual camp, but only one. They were the party of young-earth creationists, religious pro-lifers, climate-deniers and gun-lovers - but also of educated fiscally conservative folks. The party would welcome economics professors and leaders of medium-sized businesses, promising no radical changes, no big increases in spending or regulation, and a generally pro-market/pro-business stance. The genius of Trump was in realising the educated fiscally conservative folk were driving 95% of the republican policy agenda but only delivering 10% of the votes. The average Republican voter loves the idea of disbanding the IRS and replacing all taxes with tariffs on imports. Sure, you lose the educated 10% who think that policy is economic suicide - but you can more than make up for it with increased turn-out from the other 90% who are really fired up by the prospect of eliminating all taxes. And it works - jumping into the anti-intellectual camp with both feet has delivered the house, the senate, the presidency (electoral college and popular vote), and the supreme court. The conservative movement has a brain-drain because they've realised they don't want the votes of smart, educated people.
- ipv6ipv4 1y agoIt was incontrovertibly approved as it is only installable via MDM. A likely explanation is that the communications director (or the people informing her) wouldn’t know to distinguish between Signal the app, and a Signal compatible app that is nearly indistinguishable from Signal. A lot like Kleenex is a common term for tissue paper regardless of brand. When the leak was first revealed, there was loud speculation about the legality of government chat messages being set to auto-delete. This additional revelation, about the use of TeleMessage, shows that someone with a security background has actually thought about these things. It makes perfect security sense to archive messages somewhere secure, off phone, for record keeping compliance while ensuring that relatively vulnerable phones don’t retain messages for very long. It’s also an easy explanation for why such an app was created in the first place. There is an obvious market for it.
- ceejayoz 1y ago> This additional revelation, about the use of TeleMessage, shows that someone with a security background has actually thought about these things. We only have evidence they used TeleMessage after the scandal. When the same guy let the press take a photo of his messages with Vance, Rubio, Gabbard and others.
- ryanwatkins 1y ago> It was incontrovertibly approved as it is only installable via MDM. Only if this his standard govt issued phone. It's also been shown they are also using their own personal phones. The could easily be using unapproved phones some random DOGE'er bought gave them with an MDM setup, without any real oversight.
- be_erik 1y agoThis is currently my bet. This looks like something I would set up— state actors are not in my threat list. But, I’m usually being paid to protect the employer not the employee.
- namdnay 1y agoThe device would have to be jailbroken right? These apps are (obviously) not in the App Store, I mean one of them is a cracked WhatsApp ...
- watusername 1y agoAccording to the new 404 Media article [0] about the app's archive server actually being hacked, TeleMessage does have contracts with several governmental agencies. Still not a direct answer to the question, I know, but it tilts the answer overwhelmingly towards "yes." [0]: https://www.404media.co/the-signal-clone-the-trump-admin-uses-was-hacked/ https://www.404media.co/the-signal-clone-the-trump-admin-use...
- be_erik 1y agoThis is so frightening. I worked in corporate security, and that was occasionally a leaking ship, but this wouldn’t even fly with our engineers even if we wanted their message history. This is negligence.
- namdnay 1y agoThe scariest part? They also sell to corporations... Read their install guide and weep at the idea of pushing cracked WhatsApp binaires through MDM https://smarsh.my.salesforce.com/sfc/p/#30000001FgxH/a/Pb000000r00H/0aFJJ3tCViox8quTxN05CvEu53Cz22.IvHqz4o4EoIc https://smarsh.my.salesforce.com/sfc/p/#30000001FgxH/a/Pb000...
- watusername 1y ago> cracked WhatsApp binaries On a more meta note, I wonder who even works at companies founded on ideas that are just... bad. On average, I expect good engineers to push back on such business requirements and also have better job mobility so they can leave and work elsewhere. The researcher found the vulnerabilities "in less than 30 minutes" so it seems there's some lack of competence here. Unfortunately, misguided business requirements like this won't simply disappear and I get that those can be niche offerings that attract juicy contracts.
- jjani 1y agoCasinos, scams (both of these Web3 as well as traditional), game hack developers, ransomware and database hackers. Adtech, which thousands of HNers work in (anyone at Google). Temu, Shein, gacha/lootbox games, dopamine drug dealers (Meta, Bytedance). NSO group, spyware. Policeware, Clearview, surveillance tech. You could name defense as well, but I find that more ambiguous. I wouldn't be surprised if it at least 25% of HN has worked for such companies for at least 2 years of their career.
- sandworm101 1y ago>> Signal was an approved and whitelisted app for ... discuss top-secret matters on. No. Just no. Anyone who has handled TS information would know how nutz that sounds. Irrespective of software, TS stuff is only ever displayed in special rooms with big doors and a man with a gun outside. The concept of having TS on an everyday-use cellphone is just maddening.
- timschmidt 1y ago[flagged]
- seanhunter 1y agoDo you have evidence that Obama discussed or viewed topsecret intel on that blackberry or are you just trying to muddy the waters with a false equivalence?
- timschmidt 1y agoYou think he used it only to discuss what flavor of ice cream was being served that day in the whitehouse dining hall? With only the senior staff? If so, I have a bridge for sale which may interest you. > false equivalence We're literally talking about people occupying the same positions. If anything, blackberry seems less secure. For instance, there's a global en/decryption key, and it's known: https://www.vice.com/en/article/exclusive-canada-police-obtained-blackberrys-global-decryption-key-how/ https://www.vice.com/en/article/exclusive-canada-police-obta...
- runlevel1 1y agoIt was only to be used for a limited subset of Secret or lower comms. It was hardened and didn't use RIM's servers.
- timschmidt 1y ago[flagged]
- mmooss 1y agoThe publicly known recommendations, from CISA for example, was to use Signal for non-classified information only.
- Hobadee 1y agoIt would have to be approved; there is no way for lay-users to install/configure TM-SGNL in their own; it needs to be deployed via MDM. Source: I'm the admin who installs TM-SGNL for many users.
- jetbalsa 1y agoWould be interesting to dump the app binaries so people can take a look at how its put together, I suspect its a minefield of sloppy injection functions into how signal works.
- XorNot 1y agoSignal is open source for the client, no one is doing work they don't have to cracking a binary you can just compile.
- philipwhiuk 1y ago> Source: I'm the admin who installs TM-SGNL for many users. So... is it properly open source?
- axus 1y agoI felt the writer implied open source code was a bad/insecure thing, since they downloaded a zip file from some WordPress upload folder. I'm guessing the code was being made available to companies that "legally" obtained TM-SGNL. His repo, not theirs: https://github.com/micahflee/TM-SGNL-Android/commits/master/ https://github.com/micahflee/TM-SGNL-Android/commits/master/ He points out that "You must license the entire work, as a whole, under this License to anyone who comes into possession of a copy."