TE
테크에코
홈24시간 인기최신베스트질문쇼채용
GitHubTwitter
홈

테크에코

Next.js로 구축된 기술 뉴스 플랫폼으로 글로벌 기술 뉴스와 토론을 제공합니다.

GitHubTwitter

홈

홈최신베스트질문쇼채용

리소스

HackerNews API원본 HackerNewsNext.js

© 2025 테크에코. 모든 권리 보유.

TeleMessage Explorer: a new open source research tool

115 포인트작성자: micahflee4일 전
See also: TeleMessage customers include DC Police, Andreessen Horowitz, JP Morgan, and hundreds more: <a href="https:&#x2F;&#x2F;micahflee.com&#x2F;telemessage-customers-include-dc-police-andreesen-horowitz-jp-morgan-and-hundreds-more&#x2F;" rel="nofollow">https:&#x2F;&#x2F;micahflee.com&#x2F;telemessage-customers-include-dc-polic...</a>

10 comments

klooney4일 전
<a href="https:&#x2F;&#x2F;shewantstheisrd.myshopify.com&#x2F;products&#x2F;clean-on-opsec-pre-order" rel="nofollow">https:&#x2F;&#x2F;shewantstheisrd.myshopify.com&#x2F;products&#x2F;clean-on-opse...</a> I found the sticker
评论 #44101397 未加载
lzy4일 전
The TeleMessage dataset is massive and messy, and this tool lowers the barrier for journalists and researchers to extract meaningful insights. It’s also a reminder that “secure” enterprise tools often aren’t—especially when they’re built to satisfy compliance checkboxes rather than actual security principles. The fact that TM Signal was used by senior officials makes the plaintext logging and key exposure even more alarming. Kudos to Micah for not just reporting the breach but also enabling others to dig deeper.
specproc4일 전
What seemed to be interesting from the email addresses disclosed is that there are a hell of a lot of people engaged in finance, investment or trading of one sort or another.<p>There are a few there with enough emails for it to be relatively widespread within the institution: Scotiabank, JPMorgan, KKR and Jeffries stand out -- Scotiabank has hundreds of emails, I imagine they&#x27;re having a bad week. Also a lot of energy stuff, Aramco, Total.
评论 #44119756 未加载
评论 #44101129 未加载
ComputerGuru4일 전
I don’t understand the value proposition of TeleMessage. Uses Signal but defeats the point of using Signal. Why not use a proper centralized chat with actual retention and encryption?
评论 #44100608 未加载
评论 #44100561 未加载
评论 #44100518 未加载
评论 #44100592 未加载
评论 #44102308 未加载
评论 #44103696 未加载
评论 #44100499 未加载
评论 #44103621 未加载
throw109204일 전
I&#x27;m hoping that this will be yet another shot in the war to convice corporations and government agencies that they need to have on-prem data hosting that isn&#x27;t accessible to the company running the service. I don&#x27;t think you can do full E2E between individual employees in a corporate setting, but at the very least if all of the organization&#x27;s data is <i>only</i> accessible to the organization, that&#x27;ll help with a lot of these third-party data beaches.<p>(it won&#x27;t help when the organization is beached, which unfortunately still seems to be the main way that user data gets leaked)<p>Ultimately, though, until there starts to be federal law mandating chain of custody for user data and harsh penalties on it being leaked, I think that this will continue for a long time...<p>Update: I should have read the article - did not realize TeleMessage was <i>supposed</i> to be E2E. I guess now the lesson is that you shouldn&#x27;t be using normal devices for national security information (classified or not), and otherwise it&#x27;s still not good to use a sketchy service that doesn&#x27;t have Moxie-grade crypto implementations.
评论 #44100341 未加载
cypherpunks014일 전
Signal is licensed under GNU AGPLv3 - think there will be any action against the company for license violations? I suppose it&#x27;s the least of their liabilities, but just wondering.
评论 #44102908 未加载
tamirmag4일 전
Does the importer validate heapdump JSON and flag malformed records before they reach PostgreSQL?
klooney4일 전
Heap dumps on the Internet. Java ecosystem has some criminal defaults.
mdhb4일 전
It’s truly wild that something like this exists. It really speaks to the unfathomable levels of incompetence that this is what the Trump administration was using to plan military operations over.
评论 #44099156 未加载
heywoods4일 전
From the other article which shared the email domains found in the heap. Sorry in advance for the poor formatting.<p>---<p>Source: `<a href="https:&#x2F;&#x2F;micahflee.com&#x2F;telemessage-customers-include-dc-police-andreesen-horowitz-jp-morgan-and-hundreds-more&#x2F;" rel="nofollow">https:&#x2F;&#x2F;micahflee.com&#x2F;telemessage-customers-include-dc-polic...</a>`<p>### I. Industry Breakdown<p>*Financial Services (Dominant):* This is by far the most represented sector. It encompasses a wide array of sub-sectors:<p>* *Investment Banking &amp; Brokerage:* A large number of domains belong to global and regional investment banks, interdealer brokers, and brokerage firms. * Examples: `jefferies.com`, `morganstanley.com`, `cantor.com`, `tpicap.com`, `bgcg.com`, `rjobrien.com`, `clarksons.com` (shipping finance&#x2F;brokerage)<p>* *Asset &amp; Investment Management:* Numerous firms managing diverse asset classes for institutional and private clients are present. * Examples: `kkr.com`, `aresmgmt.com`, `pimco.com`, `nuveen.com`, `franklintempleton.com`, `apg-am.com`<p>* *Banking (Commercial &amp; Private):* Major multinational and regional banks are included, covering commercial, private, and retail banking. * Examples: `jpmorgan.com`, `bbva.com`, `cibc.com`, `scotiabank.com` (and its numerous regional variations), `bradescobank.com`, `safra.com`, `standardbank.co.za`, `dbank.co.il`<p>* *Wealth Management:* Firms specializing in wealth advisory for high-net-worth individuals are visible. * Examples: `gentrustwm.com`, `boltonglobal.com`, `rohrpwm.com`<p>* *Cryptocurrency &amp; Digital Assets:* A significant and growing sub-sector, with exchanges, trading firms, and investment managers focusing on digital assets. * Examples: `coinbase.com`, `galaxydigital.io`, `b2c2.com`, `hiddenroad.com`, `aminagroup.com` (formerly SEBA), `panteracapital.com`<p>* *Fintech &amp; Financial Technology:* Companies providing technology solutions for the financial industry, including trading platforms and compliance tools. * Examples: `smarsh.com`, `telemessage.com`, `interactivebrokers.com`<p>* *Venture Capital &amp; Private Equity:* A strong showing of firms investing across various stages and sectors, from early-stage tech to large buyouts. * Examples: `a16z.com`, `sequoiacap.com` (implied), `vistaequitypartners.com`, `lcatterton.com`, `ardian.com`, `tigerglobal.com`, `tcv.com`, `bitkraft.vc`, `blockchaincapital.com`<p>*Energy &amp; Commodities:* This sector is well-represented by:<p>* *Trading Houses:* Global and regional commodity traders dealing in oil, gas, metals, and agricultural products. * Examples: `vitol.com`, `gunvorgroup.com`, `eni.com` (also integrated), `amerexenergy.com`, `amius.com`, `pvm.co.uk`<p>* *Energy Companies (Integrated &amp; Exploration&#x2F;Production):* Major oil and gas companies and related services. * Examples: `totalenergies.com`, `petrobras.com`, `marathonpetroleum.com`, `p66.com`, `aramcotrading.us`<p>*Government &amp; Public Sector:* Primarily U.S. government entities, including:<p>* *Federal Agencies:* * Examples: `cbp.dhs.gov` (Customs and Border Protection), `usss.dhs.gov` (Secret Service), `dfc.gov` (Development Finance Corporation), `who.eop.gov` (White House Office)<p>* *Local Government:* * Example: `dc.gov` (District of Columbia Government)<p>*Technology (Non-Fintech Focus):* While many tech firms are Fintech-related, some general software and IT service providers are present. * Examples: `nice.com`, `nebari.com`, `vlmsofts.com`<p>*Consulting:* A smaller representation, often specialized. * Example: `soteriasolutions.us` (safety&#x2F;threat management)<p>*Real Estate:* Investment and advisory firms in the real estate sector. * Examples: `eastdilsecured.com`, `digitalbridge.com` (digital infrastructure)<p>*Shipping &amp; Logistics:* Companies involved in shipping brokerage and services. * Examples: `clarksons.com`, `mcquilling-energy.com`, `freightinvestor.com`<p>### II. Geographical Breakdown (Based on domain extensions and company descriptions)<p>* *United States (Dominant):* A very large portion of the entities are U.S.-based or have significant U.S. operations. This is evident from the high number of `.com` domains associated with American companies and the presence of `.gov` domains. * Major financial centers like New York and tech hubs in California are implicitly represented (e.g., `aresmgmt.com`, `kkr.com`, `a16z.com`, `morganstanley.com`).<p>* *Canada:* A strong presence, particularly Scotiabank and its various divisions, along with other financial and tech firms. * Examples: `scotiabank.com`, `scotiabank.ca` (implied), `cibc.com`, `bitbuy.ca`, `wonder.fi`<p>* *United Kingdom:* Well-represented in finance (banking, brokerage, asset management) and commodities. London&#x27;s role as a global financial hub is evident. * Examples: `cantor.co.uk`, `pvm.co.uk`, `ubauk.com`, `hbluk.com`, `rmb.co.uk`, `amcgroup.com`<p>* *Latin America:* Several domains indicate operations or focus in this region, with Scotiabank having a particularly strong showing. * *Mexico:* `scotiabank.com.mx`, `scotiacb.com.mx`, `scotiawealth.com.mx` * *Chile:* `scotiabank.cl`, `larrainvial.com` * *Peru:* `scotiabank.com.pe` * *Colombia:* `scotiabankcolpatria.com` * *Brazil:* `br.scotiabank.com`, `petrobras.com.br`, `bradescobank.com`, `itaubba.eu` (European arm of Brazilian bank) * *Panama:* `pa.scotiabank.com`<p>* *Europe (excluding UK):* * *France:* `totalenergies.com`, `ardian.com`, `mbcfrance.com` * *Switzerland:* `seba.swiss` &#x2F; `aminagroup.com`, `hnwag.com`, `itau.ch` * *Monaco:* `tyruscap.mc` * *Netherlands:* `apg-am.com` * Other European presences through global firms (e.g., `itaubba.eu`).<p>* *Asia:* Highlighting its role as a financial hub. * *Hong Kong:* `apg-am.hk` * *Singapore:* `apg-am.sg`, `gfigroup.com.sg`, `icap.com.sg`, `sg.pimco.com`, `traditionasia.com` * *Japan:* `mitsui.com`, `tullettprebon.co.jp`, `smbcgroup.com` * *Israel:* `dbank.co.il`, `fibi.co.il`, `opco.co.il`, `nice.com` * *Indonesia:* `miraeasset.co.id`<p>* *Middle East:* * *UAE:* `freightinvestor.ae`, `aramcotrading.us` (US trading arm of Saudi Aramco) * General presence of firms like Alpha Wave Global with strong ties to the region.<p>* *Africa:* * *South Africa:* `standardbank.co.za`<p>* *Global:* Many firms operate globally, even if headquartered in a specific country (e.g., `a16z.com`, `kkr.com`, `morganstanley.com`).<p>### III. Notable Trends &amp; Observations<p>* *Dominance of Financial Services:* The sheer volume of financial sector domains underscores its significant role in this context. * *Globalization of Finance:* Many financial institutions have multiple country-specific domains (e.g., Scotiabank, PIMCO, ICAP&#x2F;TP ICAP), reflecting international operations. * *Rise of Digital Assets:* Numerous cryptocurrency exchanges, traders, and VCs focused on Web3 indicate the growing institutionalization of this asset class. * *Concentration of Energy Trading:* A significant number of specialized energy and commodity trading firms are present. * *Venture Capital Focus on Technology:* Many VC firms listed are known for investments in technology and, increasingly, blockchain&#x2F;crypto. * *Government Presence:* Inclusion of U.S. federal and local government domains suggests interactions with these regulatory or administrative bodies. * *Prevalence of `.com`:* Despite geographical diversity, `.com` remains the most common top-level domain. * *Personal Email Addresses (`gmail.com`):* The presence of a few Gmail addresses (6 emails) is minor but indicates not all communications are necessarily from official corporate domains.<p>---