Despite their misleading marketing, TeleMessage, the company that makes a modified version of Signal used by senior Trump officials, can access plaintext chat logs from its customers.

In this post I give a high level overview of how the TeleMessage fake Signal app, called TM SGNL, works and why it’s so insecure. Then I give a thorough analysis of the source code for TM SGNL’s Android app, and what led me to conclude that TeleMessage can access plaintext chat logs. Finally, I back up my analysis with as-of-yet unpublished details about the hack of TeleMessage.

  • giacomo@lemm.ee
    link
    fedilink
    English
    arrow-up
    6
    ·
    1 month ago

    who thought that wouldn’t be happening? they signed up for it knowing this.