When Signal was designed, our threat model was protecting the communications of civil society, journalists, just regular citizens ...

The threat model of military operations & sharing your hate of Europeans was not what Signal was designed for. Ephemeral messages and cryptographic deniability are not fit for communications that require accountability.
But I appreciate their effort to make government more efficient by adding journalists to the chat instead of requiring to go through FOIA.

Trump said “Signal could be defective, we're going to have to find out”.
And now we hear that Elon and DOGE are getting involved.

I don't know how to say this respectfully, but the go-to Elon person in DOGE for Cybersecurity doesn't seem at all up to the task. It's the person who designed the flawed encrypted DMs on X, which very much are defective ...

https://thehill.com/homenews/administration/5215547-white-house-asks-musk-investigate-signal/

@fj I can't wait for Website Boy to conclude that Curve25519 is broken because Twitter chose P-256 instead, and no other basis for such an argument.
@soatok @fj it is not FIPS! Of course it's insecure. Only FIPS can ever be secure. Or so I was told. /s
@fj Tome for @signalapp to ensure they have a legal entity and servers outside of the US, so they can get the hell out of Dodge when this becomes necessary - that point in time can come sooner than you think.

@fj Blame the tools rather than the obvious operational fuck up: "‘Elon Musk has offered to put his technical experts on this to figure out how this number was inadvertently added to the chat, again to take responsibility and ensure this can never happen again’ she added."

It was added because they were inadvertent. Because they didn't follow procedure and rules.

And in a fascistic mindset, given all that matters is power and the power balance, this is just another way to test their power.

@fj The whole Trump admin is defective, not Signal.
@fj this worries me. I hope I won't have to quit Signal because of Elon's team
@Frederic Jacobs Let me venture a guess...

Signal is bad, and the Radical Woke Left is in cahoots with them to do damage to King Trump. Signal probably helped the Atlantic to get into the chat.

Subpoenas coming for @Meredith Whittaker and Jeffrey Goldberg in 3... 2... 1...

I hope @Signal is thinking about moving out of the jurisdiction of Agent Orange. Move to Europe, for example.

@hans
This is the unfortunate byproduct of centralization.

Not everything has to be federated, until the BDFL looses their citizenship.

BTW, Signal seems to be on the @guardianproject repo (available in @fdroidorg, but turned off by default).

@fj

@Dźwiedziu Yup, that's why I prefer Matrix over Signal. I use both, but I try to get as many people as possible to Matrix.

@fj
Sorry to barge in - but, it seems to me, this is yet another example of shifting the narrative.

What matters is that Signal was not approved for sensitive comms. (One would hope that approved apps are, to the extent possible, checked for defects). They were using it, contrary to THE LAW, both for convenience and quite likely to avoid official records of the communications. THAT’S the story.

@jan

@fj Trump lies so much that it's uncertain whether something is true or a lie. Moreover, I'm not sure if anyone in the government who isn't strictly military would have any chance of success in this matter (encrypt***). The doors of the Secretary of Defense are exclusive to military personnel.
@fj I'm not exactly sure, but there's a deep chasm completely separating the military personnel and the rest of the civil government of the United States. And eventually some politicians, and advisors and consultants, who are neither military nor civilian, trying to find out exactly what the US military wing is doing or wants to do. In the explicit case of attacks on pirates: the US military wing is independent.