Live data from Hacker News

Twilio incident: What Signal users need to know

support.signal.org

71–80 of 512 posts

Re: Twilio incident: What Signal users need to know

#71
This info gives us an interesting opportunity to estimate the rate at which Signal is adding new users. They've been very tight-lipped (understandably) about their usage stats but anecdotally they seem to be an increasingly common presence on my friends' phones, even the non-techies.

As far as I can tell, Signal uses Twilio only to send SMS for phone number verification. Verification happens when a user registers a new number or changes the number on their existing account.

The rate at which Signal is adding new users could be calculated by:

1900 * (proportion of new registrants among SMS recipients) / (length of Twilio incident)

You could probably make some common-sense assumptions about the first variable. But I can't find any publicly available info on when Twilio was first compromised. Their press release only mentions that they discovered the intrusion on August 4, which is presumably close to the end date of the incident. Does anyone know what the estimated start of the incident might be?

Re: Twilio incident: What Signal users need to know

#72
post #15

Earlier quoted context omitted.

How do you deal with spam without requiring a phone number to register?

Signal doesn't ask for phone numbers simply to combat spam; the phone number isn't an elaborate captcha. Rather, as this article repeatedly points out, Signal doesn't keep your contact lists and other data available to its servers. It uses phone numbers because phones already have contact lists, stored clientside, keyed by those numbers. To replace the numbers with usernames, Signal users would have to either give up…

Are you basing your argument on assumptions that:

  A) Most contacts have phone numbers
  B) Most contacts don't have email addresses?
I think you're assuming this (and as it happens, I agree, although the number of email-only contacts is still nonzero for a lot of people).

Are you also assuming that it just adds a lot of complexity to be willing to search by both phone numbers and emails?

That's the part of your argument I'm not grasping. Signal has to be willing to intersect known-account-identifiers with this-device's-local-contact-handles, what's the problem with preferring phone numbers but allowing emails?

Re: Twilio incident: What Signal users need to know

#73

Earlier quoted context omitted.

So if you have a phone number that someone else used to create an account, you can't use Signal?

Close, but not quite. You see, if the other person didn't use registration lock, now you've got access to complete strangers account. Problem solved!

Which is less scary than it sounds because a signal "account" is a phone number. Oh no your privacy!

If you view Signal as "a service that allows you to send E2E messages to phone numbers" then this is fine. Your friends will even get a message that says the chat has been rekeyed once the new person sets up Signal.

And if you're worried about government's compelling your cell carrier to turn over your phone number then rest assured that usernames wouldn't help you since they could just compel Signal to turn over your username. So much safer.

As long as the source of identity is something other than a private key that is owned and controlled by the user and devices must have their keys signed by that key to be considered valid it will be the same issue.

Re: Twilio incident: What Signal users need to know

#74
post #35
post #8

Earlier quoted context omitted.

Give people the option to pay. I would gladly pay $100 one time fee if it meant I could avoid having a phone number associated. https://jmp.chat is a great work around but I would rather just have an email address or ideally nothing but a receipt directly associated with my signal account.

Isn't email even worse for security?

You can trivially create as many emails as you want, anonymously and for free.

In many countries, registering phone numbers anonymously is illegal and/or impossible.

Re: Twilio incident: What Signal users need to know

#75
post #57

Earlier quoted context omitted.

After countless discussions of Signal on HN, I have yet to see an explanation for why Signal can use phone numbers from a client-side contact list, but not email addresses from a client-side contact list. Surely, in either case the identifier can be treated as an opaque string, right? Or in other words: suppose the definition of "phone number" was expanded to include alphanumeric characters and @. What aspect of Sign…

> I have yet to see an explanation for why Signal can use phone numbers from a client-side contact list, but not email addresses from a client-side contact list OS functionality? There no "Grant access to Gmail contacts" (= email addresses) on Android/iOS, so that client-side list would have to be manually maintained, while (practically) everyone already has a contact list containing phone numbers of their friends. T…

At least on Android, any application that I give permission to access my contact list can see email addresses for the client-side contacts that are synced with my Gmail account. Maybe iOS behaves differently?

Re: Twilio incident: What Signal users need to know

#76
post #55

Earlier quoted context omitted.

It may very well be the case for the smartphone-flipping demographic that prefer WhatsApp and TikTok, but I think it's a misunderstanding/misrepresentation of the crowd that go for e.g. Signal and Telegram.

Signals very explicit goal is making something that's usable for everybody. If they'd wanted to make a nerd-messenger they'd make a different product. (I still consider it a major downside that the phone number is the only lookup key)

Sounds pretty drastic to me to draw the line between "everybody" and "nerds" at the point of the contact book being available or not.

Re: Twilio incident: What Signal users need to know

#77

Earlier quoted context omitted.

After countless discussions of Signal on HN, I have yet to see an explanation for why Signal can use phone numbers from a client-side contact list, but not email addresses from a client-side contact list. Surely, in either case the identifier can be treated as an opaque string, right? Or in other words: suppose the definition of "phone number" was expanded to include alphanumeric characters and @. What aspect of Sign…

> Or in other words: suppose the definition of "phone number" was expanded to include alphanumeric characters and @. What aspect of Signal's current design would break? I feel like you're mis-analyzing a social problem or some other design goal as a low-level technical problem. I don't know their real reason, but I can say that my email contact list is waaay messier and less curated than my phone contact list. It wou…

That seems like a problem that could easily be solved by sending fewer notifications. Do I really need to know if somebody has joined Signal until I actually want to talk to them? Isn't it better to have a larger pool of people with whom I can communicate securely using Signal?

I'm mostly just confused because this is being presented as a technical limitation: using email addresses would supposedly "require Signal to keep a database of contacts serverside". I don't understand how or why that's true.

Re: Twilio incident: What Signal users need to know

#78
I absolutely do not understand why I have to link my very sensitive Signal account to a very insecure and hard to change ID: my phone number (which can be traced to my identity in too many ways).

Why Signal does not allow fully anonymous IDs (like Threema does) is a mystery to me.

Signal is fine for most users, but it is inherently _unsafe_ for high-value sensitive communications where participants can expect targeted phishing attacks.

Re: Twilio incident: What Signal users need to know

#79
post #15

Earlier quoted context omitted.

How do you deal with spam without requiring a phone number to register?

Signal doesn't ask for phone numbers simply to combat spam; the phone number isn't an elaborate captcha. Rather, as this article repeatedly points out, Signal doesn't keep your contact lists and other data available to its servers. It uses phone numbers because phones already have contact lists, stored clientside, keyed by those numbers. To replace the numbers with usernames, Signal users would have to either give up…

> ...and the result is that the servers have a plaintext log of who talks to who on their service

Is there a reason why a user's address book can't be encrypted as well?

Re: Twilio incident: What Signal users need to know

#80

>it was possible for them to attempt to register the phone numbers they accessed to another device using the SMS verification code That's a thing? If my number expires and gets reassigned to someone else, and they register for Signal, I'll get locked out of my account just like that? And they'll start getting all the messages that were addressed to me?

Your account is tied to your phone number so pretty sure that’s the case, yep!

That sounds horrible. Would I be SoL even if I had ticked "Registration Lock" prior to that?
Post reply on HN