If anybody is interested where WordPress comes into this:
TeleMessage also provides tools to hack WP sites.
The article delves into telemessage’s public API.
Scary shit.
So… this means the “disappearing messages”, are the correct way of doing this, right?
- Encrypted message is sent
- A copy of the message reaches several devices
- TeleMessage makes an archival copy for record keeping
- Message “disappears” (is deleted) from all devices
There can be issues raised about Signal itself, the ownership and operation of TeleMessage, or how the archival process works… but otherwise, it looks like a correct workflow.
TeleMessage makes an archival copy for record keeping
To where? Israeli servers?
From the article:
For US government use, these kind of services would most likely be run to a separate server to run in a government-certified facility, ideally one certified with Federal Risk and Authorization Management Program (FedRAMP) or similar
[…]
FedRAMP servers do not necessarily have to be in the United States
…so, maybe? 🤷