The bigger story is the follow up that shows someone already hacked telemessage because the app seems to be vulnerable to several exploits (and transmits data in the clear apparently).
I can’t read that full article, but are you saying the chats go e2e encrypted into signal and then come out non e2e when transmitting to the archive? That seems like an unlikely design for even an amateur. Why wouldn’t you just add something like an archive bot that sits in signal chats and sees everything e2e?
It seems TM SGNL also works when you're messaging with somebody using the genuine Signal app. They aren't gonna make a group chat with your archive bot to message you, and they might not be pleased when you add them to such a group chat.
Maybe but if that’s their opinion, I don’t think they’d be pleased to know that you are archiving their chats in any case. I guess it would depend on who the user base is.
https://news.ycombinator.com/item?id=43896138