Live data from Hacker News

Twilio incident: What Signal users need to know

support.signal.org

41–50 of 512 posts

Re: Twilio incident: What Signal users need to know

#41
post #26

Earlier quoted context omitted.

I've been complaining about the glaring privacy/integrity problem in their SMS-based account verification scheme for years. I don't think any snafu can make them reconsider. It would forfeit the valuable social network mapping they've already poured millions of dollars into through sending verification SMSes.

It's not so much "valuable social network mapping" as it is "the only social network available to Signal", by design. Without phone numbers, they can't use clientside contact lists (they can build their own, of course, but if it's strictly clientside it won't sync, and so it won't work for most of their users). The alternative design, which HN would wildly prefer, admits to usernames or email address accounts, but re…

> "It's not so much "valuable social network mapping" as it is "the only social network available to Signal", by design."

I don't understand why you state this, when you obvioulsy know that data is connectable and joinable across discrete sources. Being "the only social network available to service X" is the inherent case for every single online service on the entire planet when viewed as an isolated entity. But this isn't a case of anonymized UUIDs. It's a case of personal phone numbers.

Re: Twilio incident: What Signal users need to know

#42

Earlier quoted context omitted.

Who is dealing with the spam SMS messages I get all year round? Phone numbers do not stop spam, they are used to distribute it. I know I received no spam when I had Google Talk... It is a solvable problem that I guess benefits nobody in power to solve.

Spam is one of the major reasons people don’t use sms. “The product Were replacing sucks so our product can suck too”

I don't use SMS because I can't download an open source client to use on desktop, send pictures or other files, edit messages, encrypt conversations, share a live location, hold a poll, have group chats with some semblance of scale, it just doesn't work for more than receiving an occasional message as last resort.

Spam via sms doesn't seem to really exist here, maybe two per year now, up from zero until three years ago.

Re: Twilio incident: What Signal users need to know

#43
>it was possible for them to attempt to register the phone numbers they accessed to another device using the SMS verification code

That's a thing? If my number expires and gets reassigned to someone else, and they register for Signal, I'll get locked out of my account just like that? And they'll start getting all the messages that were addressed to me?

Re: Twilio incident: What Signal users need to know

#44
post #4

>Among the 1,900 phone numbers, the attacker explicitly searched for three numbers, and we’ve received a report from one of those three users that their account was re-registered. I wonder if this was a curious attacker trying to see what they could do with their access, or a targeted attack.

It sure feels like it was targeted. Is trying to re-register a Signal account the sort of thing an attacker is likely to do at random?

Re: Twilio incident: What Signal users need to know

#45

>it was possible for them to attempt to register the phone numbers they accessed to another device using the SMS verification code That's a thing? If my number expires and gets reassigned to someone else, and they register for Signal, I'll get locked out of my account just like that? And they'll start getting all the messages that were addressed to me?

Your account is tied to your phone number so pretty sure that’s the case, yep!

Re: Twilio incident: What Signal users need to know

#46
post #34

Earlier quoted context omitted.

The sane alternative is that it could keep a client-side contact book that users would be responsible for managing entirely on their own, including when setting the app up on a new phone. Addendum: also, there is nothing preventing this type of contact book data from being backed-up/synced to a new phone, like any other data and settings of any other app. iOS has this feature since like 7 years now. Android, too, I'm…

That's a good way to build a secure messaging app nobody ever uses.

It may very well be the case for the smartphone-flipping demographic that prefer WhatsApp and TikTok, but I think it's a misunderstanding/misrepresentation of the crowd that go for e.g. Signal and Telegram.

Re: Twilio incident: What Signal users need to know

#47
Yes, Signal’s phone number requirement is bad. But, given that, the fact that they don’t store any messages on their side and everything is client side is still a huge benefit over a lot of other apps and still a huge step forward for privacy! Criticism is definitely important but I just wanted to put that out there that all things considered, Signal is still very much a good thing.

Re: Twilio incident: What Signal users need to know

#48
post #44
post #4

>Among the 1,900 phone numbers, the attacker explicitly searched for three numbers, and we’ve received a report from one of those three users that their account was re-registered. I wonder if this was a curious attacker trying to see what they could do with their access, or a targeted attack.

It sure feels like it was targeted. Is trying to re-register a Signal account the sort of thing an attacker is likely to do at random?

> Is trying to re-register a Signal account the sort of thing an attacker is likely to do at random?

Yes. I mean why not, you've got the number(s).

Re: Twilio incident: What Signal users need to know

#49
post #7

Earlier quoted context omitted.

which is a curious thing to me as the phone number i created a Signal account with is no longer my phone number. what happens if the person currently assigned that number tries to join Signal and what happens to me if they do?

They mention it, use registration lock: https://support.signal.org/hc/en-us/articles/360007059792-Si... Basically if someone tries to register to Signal with your phone number they'll need to enter that PIN Signal consistently reminds you of.

So if you have a phone number that someone else used to create an account, you can't use Signal?

Re: Twilio incident: What Signal users need to know

#50
post #21

Please, stop using phone numbers. There is no reliable way to hold a phone number. The messaging protocols are insecure. If your service uses phone numbers or SMS, that means it's not secure or reliable.

Not only that, I don't want any service that I use tied to a phone number. Partially for the reasons you listed, but also because there are better alternatives; email, authenticator apps, physical keys, cards, etc.

I hate looking at my phone. I hate using my phone. I don't want to have even more reasons to keep my phone charged and in my hand. Phones suck.

Post reply on HN