National Security Adviser Mike Waltz had a rough Thursday. While he made it in that job longer than Mike Flynn, he’s out after just over 100 days. Unfortunately for him, Reuters press photographer Evelyn Hockstein caught him using a Signal-like interface to view chats on his phone under the Cabinet table at a public meeting. Much like the earlier SignalGate chats, key Trump officials like Vice President JD Vance and Tulsi Gabbard show up in the messages on that sole photo. Signal users regularly get messages reminding them to enter their PIN number, a kind of secondary lock on the account data. This phrase “TM SGNL” was oddly different than normal on Waltz’s phone, which quickly led people to a software vendor called TeleMessage that is based in Israel, first reported in detail by 404Media. TeleMessage is owned by Portland, Oregon-based Smarsh, which provides communication compliance, recordkeeping, legal, and other software according to its website. Smarsh started to acquire TeleMessage in 2022 to “deliver unmatched capability for mobile communications compliance for the hybrid workforce.” Official developer docs show that TeleMessage’s “tech stack” has included a user management function implemented on the server side to connect directly with a WordPress site, a few eagle-eyed people pointed out online. Additionally, Unicorn Riot found that at least one access pattern must have been implemented through the WordPress Gravity Forms plugin, which is a very unusual design choice for a set of company programs with such sensitive devices to track. (Details on that below.) (…) TeleMessage says it can “CAPTURE, ARCHIVE AND MONITOR MOBILE COMMUNICATION: SMS, MMS, Voice Calls, WhatsApp, WeChat, Telegram & Signal,” as well as network carrier capture, voice calls, and Signal capture: “Record and capture Signal calls, texts, multimedia and files on corporate-issued and employee BYOD [bring your own device] phones.” Tom Padgett from Smarsh told the Times that no information they collect would be sent in any fashion that “could potentially violate our data residency commitments to our customers,” adding, “We do not de-encrypt.” Interestingly, the service also has some other ways to capture data at the network carrier level as well. Its features would clone the Signal traffic and archive it:
via unicornriot: SignalGate Meets WordPress: Outgoing National Security Adviser’s Phone Dumps Messages via Israeli App