GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Conversation

Notices

  1. Embed this notice
    VessOnSecurity (bontchev@infosec.exchange)'s status on Monday, 05-May-2025 02:48:03 JST VessOnSecurity VessOnSecurity

    OK, here is some additional info about the Telemessage thing found by somebody on BlueSky:

    - The hard-coded credentials are used to encrypt the collected logs.

    - They seem to be "encrypted" in a passworded archive (ZIP?). Not sure; I'm not familiar with Kotlin.

    - They are uploaded to a PostgreSQL database on a server in Israel.

    - The database is accessed by subscriber e-mail and PIN.

    - The site has been purged, which probably means that at least until the app is updated, the US government communications via Signal are no longer logged, as required by law.

    I still wouldn't call this a "backdoor" but definitely poor security practices:

    - Hard-coded credentials, duh.

    - ZIP legacy encryption is vulnerable to known-plaintext attacks.

    - Storing sensitive info on a server in a foreign country is bad - not because you can't trust the company but because you have no control of its security. What if an employee runs an info stealer and the admin password to the database gets leaked? The US government has a secure cloud, why not use that?

    Link to my conversation with the person who found this:

    https://bsky.app/profile/vure.bsky.social/post/3loe5irieck22

    In conversation about 2 months ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/450/651/537/795/788/original/5885e1880d23c91e.jpg

    Feeds

    • Activity Streams
    • RSS 2.0
    • Atom
    • Help
    • About
    • FAQ
    • TOS
    • Privacy
    • Source
    • Version
    • Contact

    GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

    Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.