DEF CON On Saturday at DEF CON, security boffin Micah Lee explained just how he published data from TeleMessage, the supposedly secure messaging app used by White House officials, which in turn led to a massive database dump of their communications. As possibly the most secure end-to-end encrypted messaging app, Signal is used by everyone from security-conscious journalists to the former White House national security adviser Mike Waltz – although as we saw in the Signalgate saga no security systems can save one from stupidity like mistakenly adding a journalist to your chat. Shortly after the Signalgate fiasco, a canny photographer spotted Waltz was using a Signal clone, TeleMessage, which backed up messages to a server, reportedly intended to comply with the US Federal Records Act. Lee decided to investigate and explained to The Register how he managed to put a 410GB database of messages online. "I analyzed the Android source code, which TeleMessage published on their website, although it was kind of hard to find," he said. "I spent a while trying to download a copy of the app, because I knew that if I had a copy, I could request the source code or they would be violating the Signal license. But they published the Android source code." After "three minutes" of examination, Lee spotted that the app had hardcoded credentials stored for a WordPress API, he said. Every message sent using the app was backed up to a SQLite database via HTTPS, and a hacker also working on the TeleM...
The inside story of the Telemessage saga
The Register
·Iain Thomson
·Published Aug 10, 2025
·Updated
Affected Software
2 affected components
TeleMessage TeleMessage
AdaptiveMobile Signal