/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

An internal NSA memo in February 2025 warned staff of a “Signal Vulnerability”; Signal says it was a phishing warning and “had nothing to do with” its core tech

Good morning.  The latest Nielsen numbers are out … HuffPost : Trump's CIA Director Blames Biden Team For Allowing Communications On Signal App James Farrell / SiliconANGLE : NSA warned about vulnerabilities in Signal prior to White House group chat fiasco Andrew Solender / Axios : Scoop: House Dem drafts bill to criminalize classified Signal chats Nia-Malika Henderson / Bloomberg : The Signal Leak Is Too Big to Sweep Under the Rug Associated Press : Encrypted messaging apps promise privacy. Government transparency is often the price Travis Gettys / Raw Story : Pentagon email ordered staff not to use Signal week before bombshell war plans report Rich Miller / Capitol Fax.com : Question of the day  —  * Background...  Signal is an open-source, encrypted messaging service … Rolling Stone : ‘Is Waltz Jonah From Veep?’: Team Trump Fumes Over Its Most Idiotic Scandal Yet Julianne McShane / Mother Jones : All the Ways Trump Officials Are Downplaying the “War Plans” Group Chat Washington Post : Interviews with 24+ US government workers show many embraced Signal after Trump's return to office as a tactic to shield communications, impacting transparency Bluesky: Mike Masnick / @mmasnick : Yes, but that warning was only meant for the little people.  —  www.cbsnews.com/news/nsa-sig... Iain Thomson / @iainthomson : CBS getting hold of the memo was a scoop, but the headline is wrong.  —  There's no vulnerabilities in the app itself, according to the memo, but it turns out that if you allow your phone to be compromised then someone can read your @signal.org messages if you haven't set them to autodelete. @signal.org : The memo used the term ‘vulnerability’ in relation to Signal—but it had nothing to do with Signal's core tech.  It was warning against phishing scams targeting Signal users.  3/ @signal.org : Right now there are a lot of new eyes on Signal, and not all of them are familiar with secure messaging and its nuances.  Which means there's misinfo flying around that might drive people away from Signal and private communications.  1/ @signal.org : One piece of misinfo we need to address is the claim that there are ‘vulnerabilities’ in Signal.  This isn't accurate.  Reporting on a Pentagon advisory memo appears to be at the heart of the misunderstanding: npr.org/2025/03/25/n.... 2/ Evan Greer / @evangreer : Yep.  This headline making the rounds and confusing way too many people today.  Saying this is a “vulnerability in Signal” is like saying someone looking over your shoulder while you message is a “vulnerability in Signal” [embedded post] Gary Myerberg-Lauter / @garythecleaner : So both the NSA and the Pentagon put out directives to NOT use Signal yet the people who run these agencies persisted!?the incompetence is breathtaking! [embedded post] @jpe1974 : The NSA knew about vulnerabilities in Signal before a Houthi attack, but instead of alerting people, they just sat there like a cat watching a wine glass get nudged off the counter?  —  Our national security strategy is starting to feel less like “Mission: Impossible” and more like “Oops!  All Leaks!” Josh Marshall / @joshtpm : This is an interesting piece.  But while it notes the general issues it makes a big error placing government workers use of Signal and the people running the govt using Signal more or less on equal footing.  They're not.  Not at all. www.washingtonpost.com/technology/ 2... Kim Zetter / @kimzetter : This is incorrect.  “Signal...prevents anyone — including hackers, law enforcement or Signal itself — from accessing what is written or said in the app.”  Signal *only* protects texts in transit, not texts that are on the device.  If hacker or law enforcement gains access to device, they can read msgs. X: @emptywheel : Now Signal has to respond to the brand damage that @MikeWaltz47, @PeteHegseth, and @SteveWitkoff did by failing to keep THEIR OWN DEVICES safe, failing to keep their own networks secure. These men are a wrecking crew of incompetence. Laura Rozen / @lrozen : NPR: Trump says Mike Waltz will lead Signal chat probe, the same man who Atlantic editor Jeff Goldberg reported added him to the group. Jim LaPorta / @jimlaporta : Here's the first page of the OPSEC Special Bulletin obtained by @CBSNews [image] Jack Pitney / @jpitney : The NSA reports to the Director of National Intelligence, Tulsi Gabbard. She should have known about this warning, and immediately shut down the Signal chat. She needs to resign, period. https://x.com/... Jim LaPorta / @jimlaporta : #BREAKING @CBSNews obtained an internal NSA bulletin from Feb. 2025—a month before the Houthi chat—which warns NSA employees of using Signal, adding, that that the app should “NOT” be used for communicating CUI, unclassified, protected information. https://www.cbsnews.com/... @1goodtern : Well, that's embarrassing. https://www.cbsnews.com/... Stephen Groves / @stephengroves : Signal is often used by officials - and not just for discussing military plans. An @AP review in all 50 states found accounts on encrypted platforms registered to cellphone numbers for over 1,100 government workers and elected officials https://apnews.com/... @matthew_d_green : Signal was designed to be a consumer-grade messaging app. It's really, really good for that purpose. And obviously “excellent consumer grade” has a lot of intersection with military-grade cryptography just because that's how the world works. But it is being asked to do a lot! Forums: r/nottheonion : Days after the Signal leak, the Pentagon warned the app was the target of hackers r/Intelligence : Days after the Signal leak, the Pentagon warned the app was the target of hackers r/Military : Days after the Signal leak, the Pentagon warned the app was the target of hackers r/politics : NSA warned of vulnerabilities in Signal app a month before Houthi strike chat r/neoliberal : Ahead of the Signal leak, the Pentagon warned of the app's weaknesses

CBS News James Laporta

Context & Ripple Effects

The reported warning lands amid a policy contradiction: officials had recently urged Americans toward encrypted messaging during the Salt Typhoon intrusions, while government users were also relying on Signal in sensitive operational settings. The key distinction is whether the risk lies in the app’s encryption or in users and endpoints.

Subsequent coverage reinforces that distinction: a breach of the Signal-like TeleMessage service was tied to a basic configuration failure, while the government’s Signal scrutiny followed a leaked official group chat. That makes the NSA memo consequential less as a verdict on Signal’s protocol than as evidence of the operational risks surrounding encrypted messaging.

First-order effects

  • NSA and Pentagon personnel face clearer pressure to avoid Signal for controlled or protected unclassified material, even if the underlying warning concerns phishing rather than a cryptographic flaw.
  • Signal must publicly separate compromise of an account or device from compromise of its core technology, as official use of the app becomes a matter of congressional and security scrutiny.

Second-order effects

  • Agency security teams may tighten device, phishing, and approved-channel controls rather than treat end-to-end encryption alone as sufficient protection; the earlier recommendation of encrypted apps during Salt Typhoon makes that policy balance especially visible.
  • Alternative government messaging products face higher scrutiny of their operational security: the later TeleMessage message theft illustrates how a weak implementation or deployment can negate the privacy promise of a messaging service.

Third-order effects

  • The episode points toward a more formal separation between consumer-grade encrypted communications and government-approved handling of sensitive information, based on endpoint management and records requirements as much as encryption.
  • If political scrutiny produces legislation or agency-wide restrictions, encrypted messaging vendors may increasingly be judged on identity controls, device security, and compliance workflows—not solely on the strength of their protocols.

The trend: Encrypted messaging is becoming an institutional security and governance issue in which phishing resilience, device control, and auditability matter alongside encryption.

Discussion

  • Capitol Fax.com Rich Miller on x
    Question of the day  —  * Background...  Signal is an open-source, encrypted messaging service …
  • @mmasnick Mike Masnick on bluesky
    Yes, but that warning was only meant for the little people.  —  www.cbsnews.com/news/nsa-sig...
  • @iainthomson Iain Thomson on bluesky
    CBS getting hold of the memo was a scoop, but the headline is wrong.  —  There's no vulnerabilities in the app itself, according to the memo, but it turns out that if you allow your phone to be compromised then someone can read your @signal.org messages if you haven't set them to…
  • @signal.org @signal.org on bluesky
    The memo used the term ‘vulnerability’ in relation to Signal—but it had nothing to do with Signal's core tech.  It was warning against phishing scams targeting Signal users.  3/
  • @signal.org @signal.org on bluesky
    Right now there are a lot of new eyes on Signal, and not all of them are familiar with secure messaging and its nuances.  Which means there's misinfo flying around that might drive people away from Signal and private communications.  1/
  • @signal.org @signal.org on bluesky
    One piece of misinfo we need to address is the claim that there are ‘vulnerabilities’ in Signal.  This isn't accurate.  Reporting on a Pentagon advisory memo appears to be at the heart of the misunderstanding: npr.org/2025/03/25/n.... 2/
  • @evangreer Evan Greer on bluesky
    Yep.  This headline making the rounds and confusing way too many people today.  Saying this is a “vulnerability in Signal” is like saying someone looking over your shoulder while you message is a “vulnerability in Signal” [embedded post]
  • @garythecleaner Gary Myerberg-Lauter on bluesky
    So both the NSA and the Pentagon put out directives to NOT use Signal yet the people who run these agencies persisted!?the incompetence is breathtaking! [embedded post]
  • @jpe1974 @jpe1974 on bluesky
    The NSA knew about vulnerabilities in Signal before a Houthi attack, but instead of alerting people, they just sat there like a cat watching a wine glass get nudged off the counter?  —  Our national security strategy is starting to feel less like “Mission: Impossible” and more li…
  • @joshtpm Josh Marshall on bluesky
    This is an interesting piece.  But while it notes the general issues it makes a big error placing government workers use of Signal and the people running the govt using Signal more or less on equal footing.  They're not.  Not at all. www.washingtonpost.com/technology/ 2...
  • @kimzetter Kim Zetter on bluesky
    This is incorrect.  “Signal...prevents anyone — including hackers, law enforcement or Signal itself — from accessing what is written or said in the app.”  Signal *only* protects texts in transit, not texts that are on the device.  If hacker or law enforcement gains access to devi…
  • @emptywheel @emptywheel on x
    Now Signal has to respond to the brand damage that @MikeWaltz47, @PeteHegseth, and @SteveWitkoff did by failing to keep THEIR OWN DEVICES safe, failing to keep their own networks secure. These men are a wrecking crew of incompetence.
  • @lrozen Laura Rozen on x
    NPR: Trump says Mike Waltz will lead Signal chat probe, the same man who Atlantic editor Jeff Goldberg reported added him to the group.
  • @jimlaporta Jim LaPorta on x
    Here's the first page of the OPSEC Special Bulletin obtained by @CBSNews [image]
  • @jpitney Jack Pitney on x
    The NSA reports to the Director of National Intelligence, Tulsi Gabbard. She should have known about this warning, and immediately shut down the Signal chat. She needs to resign, period. https://x.com/...
  • @jimlaporta Jim LaPorta on x
    #BREAKING @CBSNews obtained an internal NSA bulletin from Feb. 2025—a month before the Houthi chat—which warns NSA employees of using Signal, adding, that that the app should “NOT” be used for communicating CUI, unclassified, protected information. https://www.cbsnews.com/...
  • @1goodtern @1goodtern on x
    Well, that's embarrassing. https://www.cbsnews.com/...
  • @stephengroves Stephen Groves on x
    Signal is often used by officials - and not just for discussing military plans. An @AP review in all 50 states found accounts on encrypted platforms registered to cellphone numbers for over 1,100 government workers and elected officials https://apnews.com/...
  • @matthew_d_green @matthew_d_green on x
    Signal was designed to be a consumer-grade messaging app. It's really, really good for that purpose. And obviously “excellent consumer grade” has a lot of intersection with military-grade cryptography just because that's how the world works. But it is being asked to do a lot!
  • r/nottheonion r on reddit
    Days after the Signal leak, the Pentagon warned the app was the target of hackers
  • r/Intelligence r on reddit
    Days after the Signal leak, the Pentagon warned the app was the target of hackers
  • r/Military r on reddit
    Days after the Signal leak, the Pentagon warned the app was the target of hackers
  • r/politics r on reddit
    NSA warned of vulnerabilities in Signal app a month before Houthi strike chat
  • r/neoliberal r on reddit
    Ahead of the Signal leak, the Pentagon warned of the app's weaknesses