Live data from Hacker News

Twilio incident: What Signal users need to know

support.signal.org

131–140 of 512 posts

Re: Twilio incident: What Signal users need to know

#131

This incident points to something much more severe. What role was this employee(s) whose credentials were compromised? How did these credentials allow even an employee to get plain text auth codes being sent out to end users? Such a permission should be extremely limited in who it is granted to.

I suspect many Twilio support reps need access to outgoing SMS, because manually looking over those will be an important component of handling a "someone is using your service for spamming" complaint.

Re: Twilio incident: What Signal users need to know

#132

Earlier quoted context omitted.

I will admit that this requirement always confused me. What is there to benefit from by requiring it?

I believe they have covered this question many times before, but I don’t see an answer on signal’s website. From memory, it had to do with not wanting to own the user’s contact list. Using a phone number allowed them to rely on a contact list on the users phone, which is not tied to the signal account. There was more nuance than that though.

> it had to do with not wanting to own the user’s contact list. Using a phone number allowed them to rely on a contact list on the users phone, which is not tied to the signal account.

That doesn't make any sense. Signal did the total opposite. It started keeping sensitive user data in the cloud including your name, your photo, your phone number, and a list of your contacts. It stores that data on their servers permanently.

Re: Twilio incident: What Signal users need to know

#133
I was always opposed to this STUPID requirement that you NEED to tie Signal to your phone number. I never used it and AFAIK even for the Desktop client you need to have a phone number. Wire and other messengers that use the same or similar protocols do not have this issue.

I am not the only one hating this, from the very start this was a huge critique on Signal by many people, but they never changed. I did not even know they used a 3rd party service to "verify" phone numbers. This is a HUGE issue. People who truly want to stay PRIVATE, politically hunted people who are in life and death situations should never ever use Signal.

Re: Twilio incident: What Signal users need to know

#135

The attack Twilio suffered is almost identical to the recent attack against Cloudflare: https://blog.cloudflare.com/2022-07-sms-phishing-attacks/ (even down the wording of the text messages, which are nearly identical). Cloudflare’s use of security keys prevented the attackers getting access to any accounts in that case. These attacks are sophisticated and are capable of bypassing TOTP or mobile-app-based MFA. If thi…

The way that Cloudflare attack was working out sounds similar in nature to the way MailChimp was attacked a few months ago:

https://www.bleepingcomputer.com/news/security/hackers-breac...

Re: Twilio incident: What Signal users need to know

#137

Maybe this will make Signal re-think their hard requirement of a phone number to register for Signal. ...eh, who am I kidding?

I think they are. I just also think the problem is a lot harder than people give it credit for. If they just go with a standard username (as in some form of a database lookup) then I'll be upset. But I'll be upset because this effectively doesn't solve any issue, and introduces others that have big privacy impacts and requires Signal to be a trusted source (which is antithetical to Signal's proposed mission). I do wi…

> I do wish Signal would be more transparent though.

You mean like updating their privacy policy to explain that they are keeping sensitive user data in the cloud? They refuse. There are people in this very discussion who are (or were at least) unaware that Signal is collecting and permanently storing user data on their servers. Signal's communication on what they're collecting and how has been a total joke. I cannot consider them trustworthy and at this point I suspect that refusing to update their privacy policy is a giant dead canary intended to warn users away from their product.

Re: Twilio incident: What Signal users need to know

#138

Earlier quoted context omitted.

Without it, you wouldn’t be able to see which of your contacts are on signal. And then nobody would use Signal. It’s very unfashionable today, but they decided to not let perfect be the enemy of good.

While that is nice, I see no reason to require that. Some people just don't care about that feature.

What is this future UX you're imagining? How does the future solve the contacts book/short identifiers problem?

Re: Twilio incident: What Signal users need to know

#139

Earlier quoted context omitted.

The majority of my signal contacts aren't particularly tech-literate. The crowd that go for signal and the crowd that go for telegram are different crowds, in a large part because signal designed itself to be accessible to nonexperts.

So they are tech-literate enough to use a smartphone, and apps for it, and they are tech-literate enough to type in their Signal password reminder in a hidden text field (and probably also passwords on dozens of web pages because password/keychain apps are "hard") but typing in e.g. an anonymized "user token" to add a buddy would be too "tech" for them? I refuse to believe a word of what you're saying.

> anonymized "user token" to add a buddy would be too "tech" for them? I refuse to believe a word of what you're saying.

How do you transmit said anonymous user token securely? Using the secure messaging app you're already using? Meeting up in real life? Posting it on keybase? Each of these has downsides that are all solved by a phone number.

Re: Twilio incident: What Signal users need to know

#140
post #53

Earlier quoted context omitted.

It was because of over-represented complaints about phone number requirements that Signal implemented the mistake that is SGX and server-side contact lists. Now the social graph of millions of Signal users is instead centrally protected by Intel's attestation obfuscation and a weak 4-digit PIN. All to eventually support usernames, which normies won't use.

Why are server-side contact lists needed to support identities not linked to phone numbers?

Because right now, Signal can use your contact list on the device to get your signal contacts. If you replace a phone number with a username, there will be no way to match signal's user to your contact without:

- Having a server to hold your contacts

- Or having signal app to maintain contact list and sync it across devices

Post reply on HN