lemmy.14042003.xyz
  • Communities
  • Create Post
  • Create Community
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
jeffw@lemmy.world to Technology@lemmy.worldEnglish · 1 day ago

How the Signal Knockoff App TeleMessage Got Hacked in 20 Minutes

www.wired.com

external-link
message-square
34
fedilink
  • cross-posted to:
  • [email protected]
320
external-link

How the Signal Knockoff App TeleMessage Got Hacked in 20 Minutes

www.wired.com

jeffw@lemmy.world to Technology@lemmy.worldEnglish · 1 day ago
message-square
34
fedilink
  • cross-posted to:
  • [email protected]
The company behind the Signal clone used by at least one Trump administration official was breached earlier this month. The hacker says they got in thanks to a basic misconfiguration.
alert-triangle
You must log in or register to comment.
  • /home/pineapplelover@lemm.ee
    link
    fedilink
    English
    arrow-up
    3
    ·
    3 hours ago

    Not to mention TeleMessage violated the terms of the GPL. Signal is under gpl and I can’t find TeleMessage’s code anywhere.

    Edit: it appears it is online somewhere just not in a github repo or anything

    https://micahflee.com/heres-the-source-code-for-the-unofficial-signal-app-used-by-trump-officials/

  • floofloof@lemmy.ca
    link
    fedilink
    English
    arrow-up
    39
    ·
    edit-2
    18 hours ago

    They sound staggeringly incompetent. And anyone who bought their software without any investigation into its quality also sounds staggeringly incompetent. Apparently there’s a lot of it going around.

    • Lost_My_Mind@lemmy.world
      link
      fedilink
      English
      arrow-up
      11
      ·
      14 hours ago

      In the 1980s the trend of the day was patriotism.

      In the 1990s the trend of the day was being a rebel.

      In the 2000s, there started to become a divide on what the trend ofthe day was. You were either pro patriotism/pro war…or, you were anti war/pro protesting. At least in the USA.

      2010s the trend of the day was culture wars and division.

      2020s, the trend of the day seems to be batshit lunacy and mindnumbing stupidity.

      It’s 2025. We have 5 more years to go. And with trump having 4 more of those years, I expect no change there.

      God I hope the 2030s bring some kind of sanity, unity, and enlightenment.

      Or, barring that, I’d also settle for UFOs visiting earth and allowing humans to leave earth. I mean seriously. How bad could other planets be, right? I mean their species is clearly more advanced then ours. I figure humans had their shot. Now I’ll roll the dice and give these grey guys a shot, right? What could POSSIBLY go wrong?

      And hey, if they’re the anal probe kind of aliens, that’s just a bonus…uhhhh…I mean…what? No no, I didn’t say that. I’m just some random straight dude looking to leave this planet with some grey dudes I just met.

  • Botzo@lemmy.world
    link
    fedilink
    English
    arrow-up
    59
    arrow-down
    5
    ·
    1 day ago

    Here’s a link to the original article (from the same author) on the platform you should actually subscribe to.

    https://www.404media.co/the-signal-clone-the-trump-admin-uses-was-hacked/

    • dantheclamman@lemmy.world
      link
      fedilink
      English
      arrow-up
      3
      ·
      7 hours ago

      404 has a partnership with Wired. They are both great publications; I subscribe to both. So reading this work on Wired supports 404

      https://www.404media.co/404-media-is-partnering-with-wired/

    • fmstrat@lemmy.nowsci.com
      link
      fedilink
      English
      arrow-up
      5
      ·
      11 hours ago

      Big 404 fan, but “original” is misleading. “First article on this topic” is more accurate. OPs link is arguably more interesting.

      • Botzo@lemmy.world
        link
        fedilink
        English
        arrow-up
        1
        ·
        3 hours ago

        You might enjoy the full blog post from the author:

        https://micahflee.com/despite-misleading-marketing-israeli-company-telemessage-used-by-trump-officials-can-access-plaintext-chat-logs/

    • treadful@lemmy.zip
      link
      fedilink
      English
      arrow-up
      39
      ·
      1 day ago

      The Wired article is not based on the 404 article. This one goes into detail about the mechanics of the hack.

    • OsrsNeedsF2P@lemmy.ml
      link
      fedilink
      English
      arrow-up
      16
      ·
      1 day ago

      Non-paywall: https://archive.is/qwonI

  • NotSteve_@lemmy.ca
    link
    fedilink
    English
    arrow-up
    5
    ·
    20 hours ago

    https://archive.is/5WcRT

  • tfm@europe.pub
    link
    fedilink
    English
    arrow-up
    16
    arrow-down
    1
    ·
    1 day ago

    Good that the most powerful people in the world use it then

  • Ulrich@feddit.org
    link
    fedilink
    English
    arrow-up
    8
    arrow-down
    71
    ·
    1 day ago

    works in almost exactly the same way as Signal, except that it also archives copies of all the messages passing through it, shattering all of its security guarantees.

    Pretty sure Signal does that as well, which is not a security issue.

    • disguy_ovahea@lemmy.world
      link
      fedilink
      English
      arrow-up
      42
      ·
      1 day ago

      Signal uses end-to-end encryption (E2EE). The only copies of messages are on the sender’s and recipient’s devices.

      https://support.signal.org/hc/en-us/articles/360007320391-Is-it-private-Can-I-trust-it#%3A~%3Atext=Signal+conversations+are+always+end%2C%2C+every+call%2C+every+time.

      • Ulrich@feddit.org
        link
        fedilink
        English
        arrow-up
        7
        arrow-down
        63
        ·
        1 day ago

        Copies of messages are also known as archives.

        • tehsYs@discuss.tchncs.de
          link
          fedilink
          English
          arrow-up
          45
          arrow-down
          3
          ·
          1 day ago

          Signal does not archive messages on server side

          • Ulrich@feddit.org
            link
            fedilink
            English
            arrow-up
            7
            arrow-down
            56
            ·
            edit-2
            1 day ago

            They weren’t talking about the server:

            This app…works in almost exactly the same way as Signal, except that it also archives copies of all the messages passing through it, shattering all of its security guarantees.

            • ShittyBeatlesFCPres@lemmy.world
              link
              fedilink
              English
              arrow-up
              45
              ·
              1 day ago

              Later in the article, it talks specifically about the server-side archives being stored in plain text. That’s why the hacker was able to access messages. This isn’t about the local copies on phones.

              • Ulrich@feddit.org
                link
                fedilink
                English
                arrow-up
                2
                arrow-down
                57
                ·
                1 day ago

                Yeah I didn’t read past the misinformation

                • AbidanYre@lemmy.world
                  link
                  fedilink
                  English
                  arrow-up
                  35
                  ·
                  edit-2
                  22 hours ago

                  Kinda seems like you’re the misinformation.

                • doodledup@lemmy.world
                  link
                  fedilink
                  English
                  arrow-up
                  17
                  arrow-down
                  1
                  ·
                  22 hours ago

                  Maybe you should start reading up on stuff you don’t know about before adding nonsense to internet threads.

            • OmegaSunkey@ani.social
              link
              fedilink
              English
              arrow-up
              5
              arrow-down
              1
              ·
              1 day ago

              It’s why Molly has local database encryption.

              • 0xD@infosec.pub
                link
                fedilink
                English
                arrow-up
                1
                arrow-down
                1
                ·
                1 day ago

                That doesn’t really do anything. Attackers need local access to the device to get the database itself. Chances are, they’ll get the key right with it.

                • HappyTimeHarry@lemm.ee
                  link
                  fedilink
                  English
                  arrow-up
                  4
                  ·
                  1 day ago

                  Molly encrypts it using a passphrase instead of a locally stored key for exactly that reason.

            • disguy_ovahea@lemmy.world
              link
              fedilink
              English
              arrow-up
              3
              ·
              1 day ago

              The only backup option I see for Signal is through Android, but it’s optional. There is no backup support for iOS or desktop.

              https://support.signal.org/hc/en-us/articles/360007059752-Backup-and-Restore-Messages

Technology@lemmy.world

technology@lemmy.world

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: [email protected]

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


  • @[email protected]
  • @[email protected]
  • @[email protected]
  • @[email protected]
Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 2.25K users / day
  • 9.63K users / week
  • 17K users / month
  • 28.7K users / 6 months
  • 1 local subscriber
  • 70.1K subscribers
  • 2.57K Posts
  • 57K Comments
  • Modlog
  • mods:
  • L3s@lemmy.world
  • enu@lemmy.world
  • Technopagan@lemmy.world
  • L4sBot@lemmy.world
  • L3s@hackingne.ws
  • L4s@hackingne.ws
  • BE: 0.19.9
  • Modlog
  • Instances
  • Docs
  • Code
  • join-lemmy.org