Live data from Hacker News

Twilio incident: What Signal users need to know

support.signal.org

121–130 of 512 posts

Re: Twilio incident: What Signal users need to know

#121
post #26

Earlier quoted context omitted.

I've been complaining about the glaring privacy/integrity problem in their SMS-based account verification scheme for years. I don't think any snafu can make them reconsider. It would forfeit the valuable social network mapping they've already poured millions of dollars into through sending verification SMSes.

It's not so much "valuable social network mapping" as it is "the only social network available to Signal", by design. Without phone numbers, they can't use clientside contact lists (they can build their own, of course, but if it's strictly clientside it won't sync, and so it won't work for most of their users). The alternative design, which HN would wildly prefer, admits to usernames or email address accounts, but re…

That doesn't follow. A client side contact list does not need to consist of phone numbers.

Apart from using the device contact list (which contains email addresses as well as phone numbers) the client can also keep a private contact list.

Re: Twilio incident: What Signal users need to know

#122

Maybe this will make Signal re-think their hard requirement of a phone number to register for Signal. ...eh, who am I kidding?

I think they are. I just also think the problem is a lot harder than people give it credit for. If they just go with a standard username (as in some form of a database lookup) then I'll be upset. But I'll be upset because this effectively doesn't solve any issue, and introduces others that have big privacy impacts and requires Signal to be a trusted source (which is antithetical to Signal's proposed mission). I do wi…

Here's an idea that's been floated many times in the past: Add e-mail as an alternative alongside phone numbers. Support in contacts in both Android and iOS. The only real difference these days is that one requires government ID (by law in an increasing number of countries) and one does not.

I fail to see any fundamental difficulty here.

Re: Twilio incident: What Signal users need to know

#123

Earlier quoted context omitted.

I will admit that this requirement always confused me. What is there to benefit from by requiring it?

I believe they have covered this question many times before, but I don’t see an answer on signal’s website. From memory, it had to do with not wanting to own the user’s contact list. Using a phone number allowed them to rely on a contact list on the users phone, which is not tied to the signal account. There was more nuance than that though.

Why not just store a contact list of usernames on the phone though?

Re: Twilio incident: What Signal users need to know

#124

Earlier quoted context omitted.

I will admit that this requirement always confused me. What is there to benefit from by requiring it?

Without it, you wouldn’t be able to see which of your contacts are on signal. And then nobody would use Signal. It’s very unfashionable today, but they decided to not let perfect be the enemy of good.

While that is nice, I see no reason to require that. Some people just don't care about that feature.

Re: Twilio incident: What Signal users need to know

#125

Earlier quoted context omitted.

It may very well be the case for the smartphone-flipping demographic that prefer WhatsApp and TikTok, but I think it's a misunderstanding/misrepresentation of the crowd that go for e.g. Signal and Telegram.

The majority of my signal contacts aren't particularly tech-literate. The crowd that go for signal and the crowd that go for telegram are different crowds, in a large part because signal designed itself to be accessible to nonexperts.

So they are tech-literate enough to use a smartphone, and apps for it, and they are tech-literate enough to type in their Signal password reminder in a hidden text field (and probably also passwords on dozens of web pages because password/keychain apps are "hard") but typing in e.g. an anonymized "user token" to add a buddy would be too "tech" for them? I refuse to believe a word of what you're saying.

Re: Twilio incident: What Signal users need to know

#126
post #26

Earlier quoted context omitted.

I've been complaining about the glaring privacy/integrity problem in their SMS-based account verification scheme for years. I don't think any snafu can make them reconsider. It would forfeit the valuable social network mapping they've already poured millions of dollars into through sending verification SMSes.

It's not so much "valuable social network mapping" as it is "the only social network available to Signal", by design. Without phone numbers, they can't use clientside contact lists (they can build their own, of course, but if it's strictly clientside it won't sync, and so it won't work for most of their users). The alternative design, which HN would wildly prefer, admits to usernames or email address accounts, but re…

I feel we've had this conversation before. IIRC this is where we left off:

E-mail as a complement should work fine and supported in all contact lists. It wouldn't change a thing wrt what you're describing.

Re: Twilio incident: What Signal users need to know

#127

Earlier quoted context omitted.

I believe they have covered this question many times before, but I don’t see an answer on signal’s website. From memory, it had to do with not wanting to own the user’s contact list. Using a phone number allowed them to rely on a contact list on the users phone, which is not tied to the signal account. There was more nuance than that though.

Why not just store a contact list of usernames on the phone though?

What would this list contain? You don't have a signal username. If you did you'd have to claim it somehow (degenerates to email or phone verification). It's not that simple.

Using phone numbers allows signal to plug into the existing state of the world and leverage it to upgrade the security of messaging for everyone who uses it. The one compromise is that it treats phone number as a short identifier (importantly, not cryptographic, it uses real crypto for that).

If you don't use phone numbers, your product would look more like Keybase. You have to somehow facilitate key exchange between people in a way that's actually usable. Otherwise all your security benefits go out the window because nobody uses your product. Signal understands this nuance perfectly which is why they're a successful product.

Re: Twilio incident: What Signal users need to know

#129

Earlier quoted context omitted.

I believe they have covered this question many times before, but I don’t see an answer on signal’s website. From memory, it had to do with not wanting to own the user’s contact list. Using a phone number allowed them to rely on a contact list on the users phone, which is not tied to the signal account. There was more nuance than that though.

Why not just store a contact list of usernames on the phone though?

If I don't use Signal, then I'm not going to keep a list of my friends' Signal usernames on my phone.

If I subsequently sign-up for Signal, then I have no way to discover which of them use Signal - short of contacting them via some other method and asking for their Signal username, if any.

By making the Signal username the same as the user's phone number, I actually DO have a list of Signal 'usernames' on my phone already. As soon as I sign-up, I can send my list of friends' phone numbers to Signal and they can tell me which of those people have Signal accounts.

Re: Twilio incident: What Signal users need to know

#130
Hey look, the centralized nature of Signal has come back to bite it. Who could ever have predicted?

Edit to try and make this less snarky and more productive: In n number of threads regarding Matrix, and the Matrix vs Signal controversy[0][1], the point is that Signal took a single, simple approach and tried to proclaim it was necessary because it allows them to be agile and responsive and integrate new features or security standards and not be weighted down. However, they jumped in and married themselves to a centralized service to do that, and have just essentially ignored that the centralized service may have faults. Whereas Matrix, while slower to evolve, is setup to be far more resilient to a single point of failure.

[0] https://signal.org/blog/the-ecosystem-is-moving/

[1] https://matrix.org/blog/2020/01/02/on-privacy-versus-freedom

Post reply on HN