Live data from Hacker News

Twilio incident: What Signal users need to know

support.signal.org

51–60 of 512 posts

Re: Twilio incident: What Signal users need to know

#51
post #44
post #4

>Among the 1,900 phone numbers, the attacker explicitly searched for three numbers, and we’ve received a report from one of those three users that their account was re-registered. I wonder if this was a curious attacker trying to see what they could do with their access, or a targeted attack.

It sure feels like it was targeted. Is trying to re-register a Signal account the sort of thing an attacker is likely to do at random?

Similar to the other reply, I imagine it would be along the lines of:

"Holy shit are those Signal 2FA codes? That's wild"

In my head, this is something a more teenager (e.g. Lapsus) might think?

Re: Twilio incident: What Signal users need to know

#53

Maybe this will make Signal re-think their hard requirement of a phone number to register for Signal. ...eh, who am I kidding?

It was because of over-represented complaints about phone number requirements that Signal implemented the mistake that is SGX and server-side contact lists. Now the social graph of millions of Signal users is instead centrally protected by Intel's attestation obfuscation and a weak 4-digit PIN. All to eventually support usernames, which normies won't use.

Re: Twilio incident: What Signal users need to know

#54
post #26

Earlier quoted context omitted.

It's not so much "valuable social network mapping" as it is "the only social network available to Signal", by design. Without phone numbers, they can't use clientside contact lists (they can build their own, of course, but if it's strictly clientside it won't sync, and so it won't work for most of their users). The alternative design, which HN would wildly prefer, admits to usernames or email address accounts, but re…

After countless discussions of Signal on HN, I have yet to see an explanation for why Signal can use phone numbers from a client-side contact list, but not email addresses from a client-side contact list. Surely, in either case the identifier can be treated as an opaque string, right? Or in other words: suppose the definition of "phone number" was expanded to include alphanumeric characters and @. What aspect of Sign…

People don't have email addresses in their contact lists because all their email contacts are stored on Google servers.

Re: Twilio incident: What Signal users need to know

#55
post #34

Earlier quoted context omitted.

That's a good way to build a secure messaging app nobody ever uses.

It may very well be the case for the smartphone-flipping demographic that prefer WhatsApp and TikTok, but I think it's a misunderstanding/misrepresentation of the crowd that go for e.g. Signal and Telegram.

Signals very explicit goal is making something that's usable for everybody. If they'd wanted to make a nerd-messenger they'd make a different product.

(I still consider it a major downside that the phone number is the only lookup key)

Re: Twilio incident: What Signal users need to know

#56
post #53

Maybe this will make Signal re-think their hard requirement of a phone number to register for Signal. ...eh, who am I kidding?

It was because of over-represented complaints about phone number requirements that Signal implemented the mistake that is SGX and server-side contact lists. Now the social graph of millions of Signal users is instead centrally protected by Intel's attestation obfuscation and a weak 4-digit PIN. All to eventually support usernames, which normies won't use.

Do "normies" care about high quality encryption? And did signal ever turn on username support?

Re: Twilio incident: What Signal users need to know

#57
post #26

Earlier quoted context omitted.

It's not so much "valuable social network mapping" as it is "the only social network available to Signal", by design. Without phone numbers, they can't use clientside contact lists (they can build their own, of course, but if it's strictly clientside it won't sync, and so it won't work for most of their users). The alternative design, which HN would wildly prefer, admits to usernames or email address accounts, but re…

After countless discussions of Signal on HN, I have yet to see an explanation for why Signal can use phone numbers from a client-side contact list, but not email addresses from a client-side contact list. Surely, in either case the identifier can be treated as an opaque string, right? Or in other words: suppose the definition of "phone number" was expanded to include alphanumeric characters and @. What aspect of Sign…

> I have yet to see an explanation for why Signal can use phone numbers from a client-side contact list, but not email addresses from a client-side contact list

OS functionality? There no "Grant access to Gmail contacts" (= email addresses) on Android/iOS, so that client-side list would have to be manually maintained, while (practically) everyone already has a contact list containing phone numbers of their friends.

That said I don't see why a user would have to have a stored social network at all, why can't it simply be opt-out?

Re: Twilio incident: What Signal users need to know

#58
post #31
post #15

Earlier quoted context omitted.

Signal doesn't ask for phone numbers simply to combat spam; the phone number isn't an elaborate captcha. Rather, as this article repeatedly points out, Signal doesn't keep your contact lists and other data available to its servers. It uses phone numbers because phones already have contact lists, stored clientside, keyed by those numbers. To replace the numbers with usernames, Signal users would have to either give up…

You forgot the part where joining signal "conveniently" discloses that to everyone - with no way to opt out(!). Also, everyone not sharing their contacts with the signal app already have that UX. Minus the privacy benefits of course.

Signal has always prioritized message security and integrity over anonymity. If you want anonymity, Signal is not, has not, and probably never will be the tool for you.

Re: Twilio incident: What Signal users need to know

#59

Earlier quoted context omitted.

They mention it, use registration lock: https://support.signal.org/hc/en-us/articles/360007059792-Si... Basically if someone tries to register to Signal with your phone number they'll need to enter that PIN Signal consistently reminds you of.

So if you have a phone number that someone else used to create an account, you can't use Signal?

Close, but not quite.

You see, if the other person didn't use registration lock, now you've got access to complete strangers account.

Problem solved!

Re: Twilio incident: What Signal users need to know

#60
post #26

Earlier quoted context omitted.

It's not so much "valuable social network mapping" as it is "the only social network available to Signal", by design. Without phone numbers, they can't use clientside contact lists (they can build their own, of course, but if it's strictly clientside it won't sync, and so it won't work for most of their users). The alternative design, which HN would wildly prefer, admits to usernames or email address accounts, but re…

After countless discussions of Signal on HN, I have yet to see an explanation for why Signal can use phone numbers from a client-side contact list, but not email addresses from a client-side contact list. Surely, in either case the identifier can be treated as an opaque string, right? Or in other words: suppose the definition of "phone number" was expanded to include alphanumeric characters and @. What aspect of Sign…

> Or in other words: suppose the definition of "phone number" was expanded to include alphanumeric characters and @. What aspect of Signal's current design would break?

I feel like you're mis-analyzing a social problem or some other design goal as a low-level technical problem.

I don't know their real reason, but I can say that my email contact list is waaay messier and less curated than my phone contact list. It would probably be annoying is I'd get a "So-and-so joined Signal!" notification for a bunch of randos I've emailed once and had their email auto-added to my address book.

Post reply on HN