Live data from Hacker News

Twilio incident: What Signal users need to know

support.signal.org

11–20 of 512 posts

Re: Twilio incident: What Signal users need to know

#11
post #7

Maybe this will make Signal re-think their hard requirement of a phone number to register for Signal. ...eh, who am I kidding?

which is a curious thing to me as the phone number i created a Signal account with is no longer my phone number. what happens if the person currently assigned that number tries to join Signal and what happens to me if they do?

They'll create a new key and your contacts will be notified that your key has changed.

Re: Twilio incident: What Signal users need to know

#12

Maybe this will make Signal re-think their hard requirement of a phone number to register for Signal. ...eh, who am I kidding?

How do you deal with spam without requiring a phone number to register?

Threema seems to manage just well. I guess payment is the natural limiter for spam there.

Re: Twilio incident: What Signal users need to know

#14

Maybe this will make Signal re-think their hard requirement of a phone number to register for Signal. ...eh, who am I kidding?

How do you deal with spam without requiring a phone number to register?

Who is dealing with the spam SMS messages I get all year round? Phone numbers do not stop spam, they are used to distribute it. I know I received no spam when I had Google Talk... It is a solvable problem that I guess benefits nobody in power to solve.

Re: Twilio incident: What Signal users need to know

#15

Maybe this will make Signal re-think their hard requirement of a phone number to register for Signal. ...eh, who am I kidding?

How do you deal with spam without requiring a phone number to register?

Signal doesn't ask for phone numbers simply to combat spam; the phone number isn't an elaborate captcha. Rather, as this article repeatedly points out, Signal doesn't keep your contact lists and other data available to its servers. It uses phone numbers because phones already have contact lists, stored clientside, keyed by those numbers.

To replace the numbers with usernames, Signal users would have to either give up contact lists altogether (at which point nobody would use the service), or allow Signal to keep a serverside database of contacts ready at all times for users who log in. This is what other messaging services do, and the result is that the servers have a plaintext log of who talks to who on their service, which is the most valuable information a secure messaging service can make available to a state-level adversary.

Re: Twilio incident: What Signal users need to know

#16

Earlier quoted context omitted.

How do you deal with spam without requiring a phone number to register?

One option could be to not be able to send unsolicited messages in the first place. Make it required for everyone to "accept interaction" before messages can actually be sent between two parties. Add in rate limiting so you can only have N open "invitations" and spamming should be very limited.

> Add in rate limiting so you can only have N open "invitations" and spamming should be very limited.

That also sounds like a good way to limit adoption as well, at least for anyone with more the N contacts, particularly >= 2N as that means likely a minimum waiting period before you can transfer over "more" contacts since some people will never accept/reject the invite because they don't use the app much.

If it were me and I had to wait on others to accept or reject my invite before I can continue transferring contacts, I'm gonna move on.

Re: Twilio incident: What Signal users need to know

#17

Maybe this will make Signal re-think their hard requirement of a phone number to register for Signal. ...eh, who am I kidding?

I've been complaining about the glaring privacy/integrity problem in their SMS-based account verification scheme for years. I don't think any snafu can make them reconsider. It would forfeit the valuable social network mapping they've already poured millions of dollars into through sending verification SMSes.

Re: Twilio incident: What Signal users need to know

#18
post #4

>Among the 1,900 phone numbers, the attacker explicitly searched for three numbers, and we’ve received a report from one of those three users that their account was re-registered. I wonder if this was a curious attacker trying to see what they could do with their access, or a targeted attack.

[deleted]

Re: Twilio incident: What Signal users need to know

#19
post #2

"...Twilio, the company that provides Signal with phone number verification services..." Perhaps this is why Twilio (and Twilio-issued) VoIP numbers work so well for Signal when I don't want to use the number issued by my cellular carrier? Kinda hard to SIM-swap me if you don't know my real phone number.

Do they offer numbers you can use that way or do you just use their APIs with a minimal app?
Post reply on HN