back
1291 comments
I'm an external individual to the US, but I must admit that some of the sentiments being expressed here in this thread and elsewhere about the lack of accountability deeply concern me, it reminds me of many things I saw growing up and still see today in south asia.

Independent of anything else, I do see the overton window shifting in the US, the most subtle of which are norms and expectations around acts of corruption.

Every nation has it's minor acts of corruption, small favours between friends, which I've always thought of as being functionally impossible to remove as they also allow for a flexible environment which allows things to get done.

However the norms seem to be shifting more towards the idea that those in power can act as they will, and in fact the expected thing is they will act to enrich themselves. I hope this does not happen, because this is death to entrepreneurship, this is one of those things that will poison the economy, when people no longer trust that what they make can be theirs, that others can look on in envy at the work they have built on their blood and sweat and can take it as their due because they have power.

That will create a chilling effect for anyone who wishes to create and will make them wonder as myself and many others have considered, whether it's better to create their life's work elsewhere.

I sincerely hope this doesn't happen here, once this mindset becomes a norm, it's incredibly hard thing to stamp out.

It's so much worse than that already. If corruption was the only problem we face in the US then there might be some real hope to reverse course.
I'd recommend for Entrepreneurs, just like Scientists now do, to consider Europe as a safe-haven. In the EU the rule of law still matters.
The ends justify the means is now openly accepted, even celebrated.
Yes, unfortunately we’re already at that point. Republicans and their base close ranks so effectively that it’s essentially a safe haven for all sorts of corruption and serious crime. The voters won’t punish them at the ballot and they’ve essentially captured all sources of checks and balances.
I'm already feeling like entrepreneurship is out the window.

It's a combination of AI being owned from these mega corporations and corruption at the highest level that I'm losing sight of what is the purpose building my startup business in an authoritarian landscape.

Trump illegally promoting Elon's corporation with a yard sale, kissing his feet for donating millions to his campaign thanks to citizens united, allowing him to ransack the federal government as an unelected official, to making vandalism a domestic terrorist act for people fed up when him,and now putting Elon in charge of investigating Signalgate.

People need to stand up now before they cannot.

>when people no longer trust that what they make can be theirs, that others can look on in envy at the work they have built on their blood and sweat and can take it as their due because they have power.

We just need liberals to embrace the 2nd with as much fervor as the right.

I began my career in a classified environment working on government satellite programs.

In my first week on the job, I was told, explicitly, that if I shared Classified or Controlled Unclassified information over unapproved channels, I would be reprimanded—likely fired, or less likely, prosecuted.

It was also made clear that safeguarding the nation's secrets from the carelessness of others was my responsibility, too.

It is mind-boggling that 18 people were on this thread, and none of them ever suggested that this discussion would be better served in a SCIF. To say nothing of SecDef starting the thread on Signal in the first place.

How many other such threads are active at the highest levels of government right now?

Does Chinese intelligence know?

I'm not suggesting punishment, or even prosecution, for the people involved. But the idea that this breach can occur with no accountability, consequences, or operational changes is unacceptable.

Setting aside the obvious shock of the actual subject, I'm going to try the herculean task of bringing this back to being a HN-related topic...

My guess is that there is someone named Jeffrey Goldberg in the NatSec team (or high up, it seems like a common combination of first and last name at least), and likely that they meant to add him, rather than the EDITOR IN CHIEF of the Atlantic of all people. Could this be a UI/UX thing with Signal? (not differentiating between two Jeffrey Goldbergs on your contact list?).

If anything, I'm a bit surprised that Jeff Goldberg burned this source.

If anything, I'd suspect that he'd keep the channel open as long as he could.

Or, he's got other channels that work better.

All the same, I mean, wow. These guys are just morons here, there's really no other way around it. I'm trying to think of a charitable way to spin this and I've got nothing.

Like, very clearly, these people are going to get service-members killed due to their idiocy

Steve Witkoff was on the chat while he was in Russia.

There’s a vulnerability in Signal where you can set up linked devices that replicate your signal messages. You can do this by just scanning a QRcode. This is known to be used by Russian hackers.

What are the chances the Russians duped Witkoff into scanning a QR code while he was in Moscow?

This hypocrisy reminds me of one of my former lead developers. He required everyone on the team to go through multi-person code reviews and pass an extensive CI suite before merging changes into our mainline.

But him? Half that time he'd approve his own changes without review, the other half he would force-push and bypass the CI system entirely.

He knew the system well and seemed to do enough local testing to avoid major breakage but still. Why have a bunch of rules and policies that you do not follow yourself?

In my opinion there are at least two ways to interpret this:

a) It's an unintentional opsec failure. Perhaps there was an address book collision with another intended user. Perhaps it was fat-fingered. This seems likely.

b) It was an intentional leak. Perhaps overtly, perhaps covertly, by one or more of the channel members for unknown purposes. This seems less likely as there are better ways to leak with less blowback risk.

Regarding using Signal in the first place. Yes, this seems like bad opsec, but it's possible that the current admin working groups don't trust the official secure channels and assume they are compromised and they are being spied upon by their own or foreign agencies. That seems very likely, given the circumstances. In which case, it is still a possible opsec failure, but perhaps a less bad risk than trusting operational security to known adverse agencies. This is the more interesting case, imho, since the assumption on here is largely that these types of coordination should be happening on official government channels. But "government" is not necessarily a unified collective working towards the same goals. If you have a strong suspicion that agents within your own team are acting against your goals, then of course, you have to consider communicating on alternative channels. Whether that's to evade legal restrictions or transparency, like with the Clinton email servers, or to evade sabotage, I'm not judging the ethics, just considering the necessity of truly secure communication.

Is that trust in Signal justified? It suggests members at the highest security clearances believe Signal is not compromised. Are they correct? In any case, clearly there are more ways to fail opsec than backdoors.

Reminds me of https://en.wikipedia.org/wiki/German_Taurus_leak

„Among the topics the officials discussed in their conversation, conducted using standard commercial Cisco Webex video conferencing software, were the presence of UK and US military personnel in Ukraine and the potential use of Taurus missiles to blow up the Crimean Bridge.“

The behavior will continue until an effective negative stimulus is introduced.
Here's how Eisenhower dealt with a similar leak.[1]

General Henry Miller made public comments about the secret date of the Allied invasion of Normandy in May 1944. He was a personal friend of Eisenhower. Eisenhower demoted him and sent him back to the US in disgrace. He wasn't court-martialed.

[1] https://youtu.be/fD0IlFPTopA?t=269

Without commenting on the (important) political or reputational considerations here, I want to talk a bit about the operational risk presented by this practice. There is a somewhat sizable "So what? Signal is e2e encrypted. Nothing bad happened and you're all overreacting." narrative floating around. (not so much in this thread, but in the general discourse)

If this operation was planned in Signal, then so were countless others (and presumably so would countless others be in the future).

If not for this journalist, this would likely have continued indefinitely. We have high confidence that at least some of the officials were doing this on their personal phones. (Gabbard refused to deny this in the congressional hearing -- it does not stand to reason that she'd do that unless she was, in fact using her personal phone).

At some point in the administration, it's likely that at least one of their personal phones will be compromised (Pegasus, etc). E2E encryption isn't much use if the phone itself is compromised. This is why we have SCIFs.

There was no operational fallout of this particular screwup, but if this practice were to continue, it's likely certain that an adversary would, at some point, compromise these communications. Not through being accidentally invited to the chat rooms, but through compromise of the participants' hardware. An APT could have advance notice of all manner of confidential and natsec-critical plans.

In all likelihood this would lead to failed operations and casualties. The criticism/pushback on this is absolutely justified.

How is trump staff using signal for classified military actions different from Clinton use of private email account ?

Back then he said she should be put in jail but now he is downplaying it. How can Americans take this guy seriously is beyond my mind.

In 2023, Hegseth had his own critique of the Biden administration handling classified documents “flippantly”, remarking on Fox News that “If at the very top there’s no accountability”, then we have “two tiers of justice”.

https://x.com/MattGertz/status/1904228588414464167

https://www.theguardian.com/us-news/2025/mar/24/journalist-t...

Everyone crying about the opsec failure and not that these people were cheering murdering women and children in one of the world's poorest country.
I guess Signal is pretty safe, but the phone you are using it on is far from safe. Then there is the issue of being able to accidently add unvetted people to the chat. Is that pretty much the size of the technological issue here?
And these guys have been in power for only a few months, they're still finding out about their new tools. What will happen in the next 4 years? will they even leave power peacefully?
What are the odds that Goldberg was included in the Signal chat intentionally by a whistleblower? I.e., someone who had reservations about what was about to take place (either the bombing action itself, or the intentional avoidance of government recordkeeping) and so included him as a witness?
The reason?

I would put my chips on (an attempt at) avoiding the duty to keep records.

Great take from Timothy Snyder, including…

“Signal is attractive not because it is secure with respect to foreign adversaries, which it is not, but because it is secure with respect to American citizens and American judges.”

https://open.substack.com/pub/snyder/p/signalgate-violating-...

(…maybe his article should be a top level HN post)

The whole thread is WILD, and the fact that it was verified is crazy. But the actual text of the thread is horrifying:

On one hand, they say they complain about "bailing out Europe". But on the other hand, they explicitly moved up the timeline so they could move before other actors and take credit.

> "If the US successfully restores freedom of navigation at great cost there needs to be some further economic gain extracted in return."

So to be clear, when presented with the option to wait a month, they instead explicitly choose to act decisively for political reasons. And then they want to turn around and extort European allies over it.

Well, this is distressing.

Question: how many people here who are concerned about this behavior have actually contacted their senators or representatives to voice an opinion on this?

I wonder whether the phones and software used were certified for discussing such sensitive issues and if there are risks of leaking the data because of this.
304 votes, 75 comments 3 hours after posting and this is already being thrown all the way back to 134 rank on the front page with some 2-3 day old posts. This is very clearly hacker news: a case of opsec slipup in easily the worst fashion coming straight from the SecDef (or one representing the SecDef). A shame it is probably getting flamed and downvoted over partisan reasons, although I know there are many conservatives here who probably don't enjoy these constant leopards eating face moments they've unleashed and am not surprised they'd be acting out and flagging embarrassing posts.
If anything, this is a hell of a "social proof" for Signal :)
easier to read as rendered here https://mimoo.github.io/houthi_signal/
It just came out one of the chat members was in Russia at the time.
I mean im not shocked by neither the fact this happend nor the content. it portraits the staff exactly as i would imagine them.

Tho i still find it kinda amusing that this is the finally proofs that the average security invested joe has a better opsec than the highest ranking us gov officials.

How exactly do you accidentally add a reporter to a signal group chat ...? That's a pretty bizarre sequence of events if it's actually what happened isn't it?
>"The Houthi-run Yemeni health ministry reported that at least 53 people were killed in the strikes, a number that has not been independently verified."

weird chat, surprised Waltz was active in planning strikes. 18 confidantes - closer knit cabinet from internal coms. was under the impression that signal log was leaked to emulate Spinoza's excommunication decree.

Relatively minor side point, but still: for people who chastise "European freeloading", it's interesting to note that none of Signal group's members' usernames have the badge Signal gives users who pay for the service. Users like me, from Europe. Sure, they might all be paying but have opted out, but let's be honest that's unlikely.
Jeffrey Goldberg mentioned in an interview with MSNBC his Signal Alias was "JG." I wonder if JD Vance goes by JD?
> Waltz set some of the messages in the Signal group to disappear after one week, and some after four. That raises questions about whether the officials may have violated federal records law: Text messages about official acts are considered records that should be preserved.

I suspect that this was the point of their using Signal, to avoid preservation of records.

The funny thing is I heard the head of the CIA testify today and say they use Signal because it is E2E encrypted. Are they that confident that no other country like China can crack those? I sure hope our intelligence officers are using better systems than effing Signal
but her emails
The level of incompetence and lack of accountability is mind-boggling.