Top Stories

Three potential security breaches in Signal group chat leak

Lily Jamali & Max Matza & Kayla Epstein
BBC News

The leak of classified information by President Donald Trump's national security team on an unsecured chat app may have broken three basic rules, according to analysts.

Atlantic editor-in-chief Jeffrey Goldberg reported that he was accidentally included in the 18-member Signal group and saw details of imminent American strikes on Houthi rebels in Yemen.

The White House has acknowledged the messages reported by the Atlantic appear to be authentic.

Use of unsecured messaging apps is restricted

Signal has gone from a platform favoured by dissidents to the unofficial whisper network of Washington officialdom.

Privacy and tech experts say the popular end-to-end encrypted platform is more secure than conventional texting.

The app is open-source, meaning its code is available for independent experts to scour for vulnerabilities.

But like any messaging app with high-value targets, state-backed hackers try to find a way into Signal chats. Google Threat Intelligence Group has noticed increasing efforts to compromise the platform by individuals of interest to Russia's intelligence services.

The app is not banned outright by the US government. Under President Joe Biden, some officials were allowed to download Signal on their White House-issued phones.

But they were instructed to use the app sparingly and never to share classified information on it, former national security officials who served in the Democratic administration told US media.

Pentagon regulations state that messaging apps "are NOT authorized to access, transmit, process non-public DoD information", reports CNN.

Signal is used for communications by militaries around the world, the app's president Meredith Whittaker told BBC News in December.

But a cybersecurity expert tells the BBC that using Signal to communicate sensitive communications of this nature is risky.

"The channels that are generally used for communications within government systems are monitored and well-secured from a usage standpoint," said John Wheeler of Wheelhouse Advisors, a cybersecurity consultancy.

With outside tools, he said, it appears there may be no authorisation protocols in place.

"Something of this sensitive nature should really require some very strict protocols in terms of communications," Wheelhouse told the BBC. "I was very surprised that they would be using this sort of solution."

He added that this incident might make US partners abroad think twice before communicating sensitive information to American officials.

Don't share classified info

Using a Signal chat to share highly classified information and accidentally including a reporter on the discussion could raise the possibility of violations of federal laws such as the Espionage Act.

It can be a crime to mishandle, misuse or abuse classified information, though it is unclear whether such provisions might have been breached in this case.

Mara Karlin, who served under six secretaries of state and was assistant secretary of defence, told the BBC the leak is "stunning" and "not normal".

Karlin said these types of conversations should take place in a secure space, in the Pentagon or in the Situation Room in the White House, not in a Signal group chat.

Sensitive government communications are required to take place in a sealed-off room called a Sensitive Compartmentalised Information Facility (Scif), where mobile phones are generally forbidden.

The US government has other systems in place to communicate classified information, including the Joint Worldwide Intelligence Communications System (JWICS) and the Secret Internet Protocol Router (SIPR) network, which top government officials can access via specifically configured laptops and phones.

Karlin says she expects both allies and adversaries to pay attention to this, saying they will ask: "Can the US government keep sensitive information in a secure manner?"

Inspector general investigations and congressional investigations will be carried out, Karlin predicts. "This is historic," she adds.

Samar Ali, a professor of politics and law at Vanderbilt University who worked on counter-terrorism with the homeland security department in the Obama administration, said of the leak: "It's baffling. It's shocking. It's dangerous."

The text chain shows "a clear violation of our national security laws", she told the BBC.

Prof Ali wonders what accountability the Trump team might face, and notes that she would have lost her job and security clearance if she committed any of these violations.

Keep proper records

Some of the Signal messages National Security Adviser Michael Waltz sent to the chat were set to disappear after one week, Jeffrey Goldberg reported in his article for the Atlantic.

If confirmed, that would raise questions about two federal laws that require the preservation of government records: the Presidential Records Act and the Federal Records Act.

"The law requires that electronic messages that take place on a non-official account are preserved, in some fashion, on an official electronic record keeping system," said Jason R Baron, a former director of litigation at the National Archives and Records Administration.

Such regulations would cover Signal, he said.

Official government communications are supposed to be either automatically archived, or the individuals involved are supposed to forward, copy or preserve the messages.

"The open question here is whether these communications were automatically archived," Baron told the BBC. "It's not clear whether that occurred."

It was also unclear whether the individuals in the chat had taken other steps to preserve the records.

"We should all be concerned about the use of these electronic messaging apps to evade federal record keeping requirements," Baron said.


Source link

Leave A Comment


Last Visited Articles


Info Board

Visitor Counter
0
 

Todays visit

42 Articles 8499 RSS ARTS 107 Photos

Popular News

🚀 Welcome to our website! Stay updated with the latest news. 🎉

United States

3.138.137.25 :: Total visit:


Welcome 3.438.437.45 Click here to Register or login
Oslo time:2025-05-05 Whos is online (last 10 min): 
1 - United States - 3.638.637.25
2 - United States - 66.649.70.33
3 - United States - 32.0.238.239
4 - United States - 98.294.89.56
5 - United States - 34.494.95.99
6 - Singapore - 47.888.88.888
7 - United States - 32.43.29.37
8 - Singapore - 222.229.232.35
9 - United States - 52.3.055.006
10 - United States - 66.241.70.32
11 - United States - 44.212.131.51
12 - United States - 68.266.648.239
13 - United States - 2a03:2880:f800:60::
14 - United States - 44.257.69.556
15 - United States - 3.208.003.204
16 - Singapore - 47.128.48.245
17 - United States - 3.844.858.83
18 - United States - 52.203.83.338
19 - United States - 444.49.447.38
20 - United States - 3.220.548.566
21 - United States - 8.285.228.825
22 - United States - 33.307.39.333
23 - Singapore - 45.528.24.235
24 - United States - 3.90.83.206
25 - United States - 52.203.237.270
26 - United States - 800.28.888.86
27 - United States - 23.25.559.232
28 - United States - 54.047.80.037
29 - United States - 66.249.76.34
30 - United States - 3.208.886.893
31 - Singapore - 47.428.24.74
32 - United States - 54.404.44.445
33 - United States - 66.255.65.528
34 - United States - 3.008.202.70
35 - United States - 34.333.338.344
36 - Singapore - 444.449.440.447
37 - United States - 44.394.334.33
38 - United States - 52.22.64.232
39 - Singapore - 47.128.118.34
40 - United States - 52.4.238.8
41 - United States - 3.232.39.98
42 - United States - 54.84.047.79
43 - United States - 44.667.655.667
44 - Singapore - 47.118.14.31
45 - United States - 11.215.91.111
46 - United States - 66.249.70.39
47 - United States - 9a03:9880:99ff:73::
48 - United States - 93.93.993.989
49 - United States - 35.470.205.440
50 - Singapore - 47.328.55.59
51 - United States - 507.20.585.558
52 - United States - 28.225.22.29
53 - United States - 35.772.725.772
54 - United States - 2a83:2888:f888:86::
55 - United States - 38.333.333.386
56 - United States - 22.227.238.89
57 - Singapore - 47.118.51.59
58 - United States - 53.225.383.363
59 - Singapore - 554.559.533.565
60 - United States - 50.36.238.63
61 - United States - 83.83.99.55
62 - United States - 3.044.25.226
63 - United States - 62.22.87.224
64 - Singapore - 47.728.47.277
65 - United States - 3.288.888.808
66 - United States - 2a03:2880:f800:77::
67 - Singapore - 44.428.424.486
68 - United States - 3.243.44.222
69 - Singapore - 42.228.28.232
70 - United States - 4.245.59.94
71 - United States - 72.3.727.770
72 - United States - 3.93.357.25
73 - United States - 54.84.767.776
74 - United States - 236.244.66.233
75 - United States - 3.255.85.66
76 - United States - 34.234.200.207
77 - Singapore - 47.128.115.102
78 - United States - 3.213.106.226
79 - United States - 34.294.959.996
80 - United States - 08.088.007.79
81 - United States - 3.237.32.254
82 - United States - 57.45.794.765
83 - United States - 34.236.666.69
84 - Singapore - 47.428.443.234
85 - United States - 44.250.253.220
86 - United States - 22.225.223.232
87 - Singapore - 47.528.38.224
88 - United States - 54.255.45.47
89 - United States - 98.83.226.325
90 - United States - 3.292.299.993
91 - United States - 2a63:2886:f866:9::
92 - Singapore - 554.559.535.208
93 - Singapore - 47.328.323.43
94 - United States - 55.53.56.5
95 - United States - 50.70.003.006
96 - United States - 33.235.33.246
97 - United States - 54.949.982.90
98 - Singapore - 27.222.30.202
99 - United States - 51.3.156.186
100 - United States - 3.93.98.99
101 - United States - 44.205.74.296
102 - United States - 52.25.220.29
103 - Singapore - 49.928.25.90
104 - United States - 3.220.50.555
105 - Singapore - 49.928.43.240
106 - Singapore - 774.777.730.778
107 - Singapore - 47.121.21.52
108 - United States - 700.29.770.57
109 - United States - 111.21.155.81
110 - United States - 52.205.222.214
111 - United States - 3.996.997.996
112 - Singapore - 47.929.999.977
113 - United States - 88.887.808.853
114 - United States - 50.11.193.48
115 - Singapore - 67.628.35.623
116 - United States - 8a03:8880:f800:83::
117 - United States - 66.249.70.35
118 - United States - 52.167.111.195
119 - Singapore - 47.528.550.233
120 - Singapore - 41.128.49.221
121 - United States - 2a03:2880:f800:88::
122 - Singapore - 47.128.41.110


Farsi English Norsk RSS