Live data from Hacker News

Twilio incident: What Signal users need to know

support.signal.org

151–160 of 512 posts

Re: Twilio incident: What Signal users need to know

#151
post #143

Earlier quoted context omitted.

> I do wish Signal would be more transparent though. You mean like updating their privacy policy to explain that they are keeping sensitive user data in the cloud? They refuse. There are people in this very discussion who are (or were at least) unaware that Signal is collecting and permanently storing user data on their servers. Signal's communication on what they're collecting and how has been a total joke. I cannot…

Please stop spreading objectively inaccurate FUD in the thread.

What part of what I said was inaccurate?

Re: Twilio incident: What Signal users need to know

#152

Earlier quoted context omitted.

I believe they have covered this question many times before, but I don’t see an answer on signal’s website. From memory, it had to do with not wanting to own the user’s contact list. Using a phone number allowed them to rely on a contact list on the users phone, which is not tied to the signal account. There was more nuance than that though.

> it had to do with not wanting to own the user’s contact list. Using a phone number allowed them to rely on a contact list on the users phone, which is not tied to the signal account. That doesn't make any sense. Signal did the total opposite. It started keeping sensitive user data in the cloud including your name, your photo, your phone number, and a list of your contacts. It stores that data on their servers perma…

The list of your contacts bit is patently false, they've discussed in detail about how they securely organize contact lists: https://signal.org/blog/contact-discovery/

Signal has always kept your name/pic/etc on their servers I believe, because otherwise you turn signal into a P2P application, which it is not. It's a fully encrypted application that stores minimal information. It is NOT P2P.

For example, your messages are stored on their servers until they're delivered.

Re: Twilio incident: What Signal users need to know

#153

Earlier quoted context omitted.

I believe they have covered this question many times before, but I don’t see an answer on signal’s website. From memory, it had to do with not wanting to own the user’s contact list. Using a phone number allowed them to rely on a contact list on the users phone, which is not tied to the signal account. There was more nuance than that though.

> it had to do with not wanting to own the user’s contact list. Using a phone number allowed them to rely on a contact list on the users phone, which is not tied to the signal account. That doesn't make any sense. Signal did the total opposite. It started keeping sensitive user data in the cloud including your name, your photo, your phone number, and a list of your contacts. It stores that data on their servers perma…

I don't think this is true, do you have a source?

They store registered users phone numbers and allow discovery by making a request with a hashed version of the phone numbers on your contact list. They add an extra layer to allow attestation of the software doing this using Intel's secure enclave. They give many examples of responding to warrants with only whether the number has been registered and the timestamp of registration, which they explain is the only information they hold.

Private Contact Discovery: https://signal.org/blog/private-contact-discovery/

Re: Twilio incident: What Signal users need to know

#154

Yes, Signal’s phone number requirement is bad. But, given that, the fact that they don’t store any messages on their side and everything is client side is still a huge benefit over a lot of other apps and still a huge step forward for privacy! Criticism is definitely important but I just wanted to put that out there that all things considered, Signal is still very much a good thing.

I refuse to use or recommend Signal due to blatantly bad design choices that put people that need privacy most at risk like security researchers, journalists, abortion seekers, or dissidents.

If you learn a contact phone number then you can buy their location history. Requiring phone numbers and requiring you share them with everyone you contact is brain dead.

This alone is bad enough to abandon Signal but then consider they have centralized control of client binaries, and metadata protection anchored on centralized SGX they can trivially access. This negligent design makes them vulnerable to coercion or even court orders if any judge realizes they actually -can- decrypt messages and dump metadata.

Matrix supports Signal crypto but in a federated network with no PII requirements like Signal. Also no lock-in or central control of apps.

Re: Twilio incident: What Signal users need to know

#155

Earlier quoted context omitted.

After countless discussions of Signal on HN, I have yet to see an explanation for why Signal can use phone numbers from a client-side contact list, but not email addresses from a client-side contact list. Surely, in either case the identifier can be treated as an opaque string, right? Or in other words: suppose the definition of "phone number" was expanded to include alphanumeric characters and @. What aspect of Sign…

> Or in other words: suppose the definition of "phone number" was expanded to include alphanumeric characters and @. What aspect of Signal's current design would break? I feel like you're mis-analyzing a social problem or some other design goal as a low-level technical problem. I don't know their real reason, but I can say that my email contact list is waaay messier and less curated than my phone contact list. It wou…

Noone wants those messages

Re: Twilio incident: What Signal users need to know

#156

Earlier quoted context omitted.

I think they are. I just also think the problem is a lot harder than people give it credit for. If they just go with a standard username (as in some form of a database lookup) then I'll be upset. But I'll be upset because this effectively doesn't solve any issue, and introduces others that have big privacy impacts and requires Signal to be a trusted source (which is antithetical to Signal's proposed mission). I do wi…

Signal is a trusted source already – you trust them telling you which number is which user.

Signal does not tell me which number is which user. I know which number is who myself. The most Signal does is presumably warn me when the key associated with the number changed (eg. new phone).

And that's where I have to trust Signal, but as a protocol not a "trusted source" of information.

Re: Twilio incident: What Signal users need to know

#157
post #138

Earlier quoted context omitted.

While that is nice, I see no reason to require that. Some people just don't care about that feature.

What is this future UX you're imagining? How does the future solve the contacts book/short identifiers problem?

I'm not saying its an amazing experience or solves the problem systematically. Again, some people simply don't need these features. You can literally just take part of the public key and that's it. That is totally fine for some use-cases.

Re: Twilio incident: What Signal users need to know

#158

Earlier quoted context omitted.

> it had to do with not wanting to own the user’s contact list. Using a phone number allowed them to rely on a contact list on the users phone, which is not tied to the signal account. That doesn't make any sense. Signal did the total opposite. It started keeping sensitive user data in the cloud including your name, your photo, your phone number, and a list of your contacts. It stores that data on their servers perma…

The list of your contacts bit is patently false, they've discussed in detail about how they securely organize contact lists: https://signal.org/blog/contact-discovery/ Signal has always kept your name/pic/etc on their servers I believe, because otherwise you turn signal into a P2P application, which it is not. It's a fully encrypted application that stores minimal information. It is NOT P2P. For example, your message…

> The list of your contacts bit is patently false,

You are wrong and your blog post from 2014 doesn't take into account their new data collection practices. See: https://community.signalusers.org/t/proper-secure-value-secu...

If this is the first time you're hearing about the data collection, that should tell you everything you need to know about how trustworthy Signal is.

> Signal has always kept your name/pic/etc on their servers I believe

Wrong again I'm afraid. There really was a time when Signal didn't collect and store any user data on their servers. They've repeatedly bragged about times when governments have come around asking them for data and they were able to turn the feds away because that data was never collected in the first place. That changed with the update which added pins. Today, Signal now collects that very same data.

Re: Twilio incident: What Signal users need to know

#159

Earlier quoted context omitted.

It means that Signal doesn't need you to create or upload a list of your contacts; it uses the existing contact list from your phone. This also lets you use Signal to replace the default text messaging app on Android, automatically upgrading conversations to be encrypted when possible. This in turn means that just using Signal to communicate with someone becomes a normal, everyday activity, and less of a sign of susp…

I think the problem is that it's a requirement, not a feature you can choose to use. I'd be more inclined to use Signal if I choose to use only a user/pass. Just need a block function.

How would other people contact you?

Re: Twilio incident: What Signal users need to know

#160
This is a weird thread. There's a product that does secure messaging with usernames and only requires user/pass. It's called Keybase. If this is the product you want, then go use it. I don't understand why everyone wants Signal to be something it's not. I quite like Signal as they are and this "incident" demonstrates exactly what happens if a carrier gets compromised: nothing. Nothing happens. Signal decides not to trust any phone verifications from the period of compromise and requires affected numbers to reregister. All the important crypto has nothing to do with phone numbers in Signal's domain. And this is exactly why I use Signal. It lets me send secure messages to people using a tried and true UX: text messaging, but with its own secure application layer. It's really difficult to build a useable security product, and Signal has done it successfully.
Post reply on HN