Live data from Hacker News

Twilio incident: What Signal users need to know

support.signal.org

61–70 of 512 posts

Re: Twilio incident: What Signal users need to know

#61
If they (Signal) care about privacy, they need to drop the need for phone numbers to use their service, there are many ways of dealing with spam (rate limiting, captchas, ...), a true private/secure messenger app should not require any user identifiable info. And the argument of "Signal was the first e2ee messenger app to go mainstream, so they can keep ignoring user's privacy, .... yada yada..." is naive at best; they should lead by example, right now there are many solutions way more private (Briar, SimpleX, Session, Wickr, ....). I user Signal, and I like it, is just a shame they soft-refuse("We are working on it...") to remove phone numbers from the equation.

Re: Twilio incident: What Signal users need to know

#63
post #34

Earlier quoted context omitted.

That's a good way to build a secure messaging app nobody ever uses.

It may very well be the case for the smartphone-flipping demographic that prefer WhatsApp and TikTok, but I think it's a misunderstanding/misrepresentation of the crowd that go for e.g. Signal and Telegram.

Large swaths of my non-tech social group are on Signal because it offers a large amount of practical security and privacy without the kinds of sacrifices people seem to assume signal users want to take. Signal has successfully and dramatically increased the number of people enjoying privacy in their communications by not making that assumption.

Re: Twilio incident: What Signal users need to know

#64
The attack Twilio suffered is almost identical to the recent attack against Cloudflare: https://blog.cloudflare.com/2022-07-sms-phishing-attacks/ (even down the wording of the text messages, which are nearly identical). Cloudflare’s use of security keys prevented the attackers getting access to any accounts in that case.

These attacks are sophisticated and are capable of bypassing TOTP or mobile-app-based MFA. If this is widespread, I’d be surprised if we didn’t see a massive influx of breaches soon. The vast majority of companies are not well defended against this.

Re: Twilio incident: What Signal users need to know

#65
post #15

Earlier quoted context omitted.

Signal doesn't ask for phone numbers simply to combat spam; the phone number isn't an elaborate captcha. Rather, as this article repeatedly points out, Signal doesn't keep your contact lists and other data available to its servers. It uses phone numbers because phones already have contact lists, stored clientside, keyed by those numbers. To replace the numbers with usernames, Signal users would have to either give up…

Users having to add their contacts each time they set Signal up on a new phone, should the app keep its own client-side contact book, doesn't sound like hassle. Could you please explain how Signal does not have a social network map, when 1) user accounts are equal to mobile phone numbers, and 2) Signal servers route messages between user accounts.

The Signal protocol has had "sealed sender" since 2018 - Signal server does not know who sent a message, because the sender's identity is E2E encrypted along with the message.

Even if Signal's server saves a message (they claim not to, once downloaded), Signal's server by design has no way of knowing who sent the message.

Re: Twilio incident: What Signal users need to know

#66
post #31

Earlier quoted context omitted.

You forgot the part where joining signal "conveniently" discloses that to everyone - with no way to opt out(!). Also, everyone not sharing their contacts with the signal app already have that UX. Minus the privacy benefits of course.

Signal has always prioritized message security and integrity over anonymity. If you want anonymity, Signal is not, has not, and probably never will be the tool for you.

Huge difference between having a low profile and actively advertising out new registrations. Does not sit well with any conceivable notion of privacy. Which supposedly is one of their strongpoints.

Re: Twilio incident: What Signal users need to know

#67
post #35
post #8

Earlier quoted context omitted.

Give people the option to pay. I would gladly pay $100 one time fee if it meant I could avoid having a phone number associated. https://jmp.chat is a great work around but I would rather just have an email address or ideally nothing but a receipt directly associated with my signal account.

Isn't email even worse for security?

Depends, if you're able to poison the DNS of the mailprovider / hack the recipient mailserver or do a phising attack.

I just want to be able to communicate without sharing my phone number (since my phone number is bound to Swedish "Swish") meaning someone can get my ID from my phone number here.

This is why drug dealers use Wickr, Threema and others, because they don't expose identity, not because they're "safer".

I have a contact on Threema who I've met many times, but I have no idea how to contact him outside of Threema, because I don't know his identity and we'd both like to keep it that way.

Re: Twilio incident: What Signal users need to know

#68
post #21

Please, stop using phone numbers. There is no reliable way to hold a phone number. The messaging protocols are insecure. If your service uses phone numbers or SMS, that means it's not secure or reliable.

Not only that, I don't want any service that I use tied to a phone number. Partially for the reasons you listed, but also because there are better alternatives; email, authenticator apps, physical keys, cards, etc. I hate looking at my phone. I hate using my phone. I don't want to have even more reasons to keep my phone charged and in my hand. Phones suck.

The Signal desktop app doesn't require your phone to be turned on (once it's been "paired") by the way, as opposed to for example Whatsapp.

Re: Twilio incident: What Signal users need to know

#69
post #26

Earlier quoted context omitted.

I've been complaining about the glaring privacy/integrity problem in their SMS-based account verification scheme for years. I don't think any snafu can make them reconsider. It would forfeit the valuable social network mapping they've already poured millions of dollars into through sending verification SMSes.

It's not so much "valuable social network mapping" as it is "the only social network available to Signal", by design. Without phone numbers, they can't use clientside contact lists (they can build their own, of course, but if it's strictly clientside it won't sync, and so it won't work for most of their users). The alternative design, which HN would wildly prefer, admits to usernames or email address accounts, but re…

[deleted]

Re: Twilio incident: What Signal users need to know

#70

Yes, Signal’s phone number requirement is bad. But, given that, the fact that they don’t store any messages on their side and everything is client side is still a huge benefit over a lot of other apps and still a huge step forward for privacy! Criticism is definitely important but I just wanted to put that out there that all things considered, Signal is still very much a good thing.

I will admit that this requirement always confused me. What is there to benefit from by requiring it?
Post reply on HN