Live data from Hacker News

Twilio incident: What Signal users need to know

support.signal.org

101–110 of 512 posts

Re: Twilio incident: What Signal users need to know

#101

Earlier quoted context omitted.

After countless discussions of Signal on HN, I have yet to see an explanation for why Signal can use phone numbers from a client-side contact list, but not email addresses from a client-side contact list. Surely, in either case the identifier can be treated as an opaque string, right? Or in other words: suppose the definition of "phone number" was expanded to include alphanumeric characters and @. What aspect of Sign…

> Or in other words: suppose the definition of "phone number" was expanded to include alphanumeric characters and @. What aspect of Signal's current design would break? I feel like you're mis-analyzing a social problem or some other design goal as a low-level technical problem. I don't know their real reason, but I can say that my email contact list is waaay messier and less curated than my phone contact list. It wou…

Of course there is no real reason Signal should be spamming anybody with these crap "notifications" in the first place. Who wants to wake up at 1 AM to know some dude they texted years ago is now on Signal?

Re: Twilio incident: What Signal users need to know

#102

Yes, Signal’s phone number requirement is bad. But, given that, the fact that they don’t store any messages on their side and everything is client side is still a huge benefit over a lot of other apps and still a huge step forward for privacy! Criticism is definitely important but I just wanted to put that out there that all things considered, Signal is still very much a good thing.

I will admit that this requirement always confused me. What is there to benefit from by requiring it?

Without it, you wouldn’t be able to see which of your contacts are on signal.

And then nobody would use Signal.

It’s very unfashionable today, but they decided to not let perfect be the enemy of good.

Re: Twilio incident: What Signal users need to know

#104
post #84

Earlier quoted context omitted.

Do "normies" care about high quality encryption? And did signal ever turn on username support?

I think developers have a moral responsibility to make their products as secure as possible, within reason and while still being usable. It doesn't matter if the users care about the benefits. To your second question: no, not yet.

I fully agree with you, and my first question was asked somewhat sarcastically. For the second, my implication is that developers also have a moral responsibility to make their products as private as possible, and SMS verification aint it.

Re: Twilio incident: What Signal users need to know

#105
post #4

>Among the 1,900 phone numbers, the attacker explicitly searched for three numbers, and we’ve received a report from one of those three users that their account was re-registered. I wonder if this was a curious attacker trying to see what they could do with their access, or a targeted attack.

I think someone might know that certain numbers belong to certain users and that they want to prove it. Happened a lot with Disqus accounts.

You can btw use the password reset function on many sites to correlate it with notifications. Easy at public events.

Re: Twilio incident: What Signal users need to know

#106

Yes, Signal’s phone number requirement is bad. But, given that, the fact that they don’t store any messages on their side and everything is client side is still a huge benefit over a lot of other apps and still a huge step forward for privacy! Criticism is definitely important but I just wanted to put that out there that all things considered, Signal is still very much a good thing.

I will admit that this requirement always confused me. What is there to benefit from by requiring it?

It means that Signal doesn't need you to create or upload a list of your contacts; it uses the existing contact list from your phone. This also lets you use Signal to replace the default text messaging app on Android, automatically upgrading conversations to be encrypted when possible. This in turn means that just using Signal to communicate with someone becomes a normal, everyday activity, and less of a sign of suspicious activity (from the point of view of law enforcement, etc.).

Re: Twilio incident: What Signal users need to know

#107
post #65

Earlier quoted context omitted.

The Signal protocol has had "sealed sender" since 2018 - Signal server does not know who sent a message, because the sender's identity is E2E encrypted along with the message. Even if Signal's server saves a message (they claim not to, once downloaded), Signal's server by design has no way of knowing who sent the message.

Every inbound message is authenticated, and credentials are stored somewhere . Correct me if I am wrong, but I'm betting that it's with the same credential/channel as for logging-in a user (aka "sender"). Also, wasn't "sealed sender" broken (again) earlier this year by a group of researchers?

No, sealed sender messages are not authenticated. The sender's client uploads two things: 1) an encrypted message (with sender id encrypted), and 2) a zero-knowledge proof that the sender's client knows the recipient's delivery token.

There is no authentication by the sender, and the sender does not upload any credentials.

Re: Twilio incident: What Signal users need to know

#108

Yes, Signal’s phone number requirement is bad. But, given that, the fact that they don’t store any messages on their side and everything is client side is still a huge benefit over a lot of other apps and still a huge step forward for privacy! Criticism is definitely important but I just wanted to put that out there that all things considered, Signal is still very much a good thing.

I will admit that this requirement always confused me. What is there to benefit from by requiring it?

Using the phone number as the identity. You need to verify ownership of the phone number to prove your identity. I guess they could use email as an alternative.

Re: Twilio incident: What Signal users need to know

#109
post #34

Earlier quoted context omitted.

That's a good way to build a secure messaging app nobody ever uses.

It may very well be the case for the smartphone-flipping demographic that prefer WhatsApp and TikTok, but I think it's a misunderstanding/misrepresentation of the crowd that go for e.g. Signal and Telegram.

The majority of my signal contacts aren't particularly tech-literate. The crowd that go for signal and the crowd that go for telegram are different crowds, in a large part because signal designed itself to be accessible to nonexperts.

Re: Twilio incident: What Signal users need to know

#110
post #53

Maybe this will make Signal re-think their hard requirement of a phone number to register for Signal. ...eh, who am I kidding?

It was because of over-represented complaints about phone number requirements that Signal implemented the mistake that is SGX and server-side contact lists. Now the social graph of millions of Signal users is instead centrally protected by Intel's attestation obfuscation and a weak 4-digit PIN. All to eventually support usernames, which normies won't use.

> All to eventually support usernames, which normies won't use.

But brogrammers will. /s

Post reply on HN