Hacker News new | past | comments | ask | show | jobs | submit login

And the lesson every us pol seems to have learned is "use signal, use protonmail."



They're using Signal to circumvent the Presidential Records act - the US government nowadays has ample ways to officially and quickly communicate with each other, while being in compliance with recordkeeping and national secrets requirements.


Use of Signal has been rife in Washington DC since COVID times.

During COVID they closed many of the secure facilities indefinitely. Building access was on a rotation, so many people couldn’t see or communicate with their counterparts for weeks or months unless their rotation intersected. The government had no plan for how to conduct classified business with their facilities closed for extended periods. It is in this milieu that Signal became established as an alternative way to communicate.

They required almost everyone to work at home without a plan for how that is supposed to work when most people don’t have a SCIF[0] in their house. As bad as it is that the US DoD converged on using Signal, there is an identical issue in many European countries with the pervasive use of WhatsApp for sensitive communication. It is a classic case of shadow IT taking over.

[0] https://en.wikipedia.org/wiki/Sensitive_compartmented_inform...


I hadn't heard that. Do you remember where that story is covered?


It is first-hand knowledge, I was doing quite a bit of government work in Washington DC during COVID. Everything ground to a halt because it was so difficult to connect with people. I use Signal today primarily because of working in Washington DC.


That is what I assumed as well. In both the current and previous admins.

But as more details come out about the current admins use of signal, this appears to not be the case.

They are using a shitty third party patched version of signal specifically designed to archive messages.

Leaving aside the security issues with the version they are using and the lack of public facing policy, the use of a Signal variant that archives chats is a reasonable compromise.

Instead of walling off users, creating a barrier to use and therefore extensive bypassing of the security standards, they have met users where they are and provided them with what the user cannot distinguish from official signal. This allows them to interface internally and externally through signal, preserving records and maintaining a much better level of security than the other options.

This represents a huge breach of trust between external parties and government signal users, but most of the government signal users are probably completely unaware that it's being logged.

My issue is not that they are using Signal. I think it's one of the better options. My issue is that they use a shitty version of it when there should be an in house maintained version for government use.


> They're using Signal to circumvent the Presidential Records act

FWIW, the national security advisor was/is using an unofficial Signal client that logs messages - insecurely, of course.


Well, they're not even using Signal, but a wrapper that's less secure.

https://micahflee.com/tm-sgnl-the-obscure-unofficial-signal-...




Consider applying for YC's Fall 2025 batch! Applications are open till Aug 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: