Live data from Hacker News

Twilio incident: What Signal users need to know

support.signal.org

161–170 of 512 posts

Re: Twilio incident: What Signal users need to know

#161
post #154

Yes, Signal’s phone number requirement is bad. But, given that, the fact that they don’t store any messages on their side and everything is client side is still a huge benefit over a lot of other apps and still a huge step forward for privacy! Criticism is definitely important but I just wanted to put that out there that all things considered, Signal is still very much a good thing.

I refuse to use or recommend Signal due to blatantly bad design choices that put people that need privacy most at risk like security researchers, journalists, abortion seekers, or dissidents. If you learn a contact phone number then you can buy their location history. Requiring phone numbers and requiring you share them with everyone you contact is brain dead. This alone is bad enough to abandon Signal but then consi…

> abortion seekers

Uhhh, not sure what koolaid you've swallowed, but including them in that list is almost laughable.

Re: Twilio incident: What Signal users need to know

#163
post #153

Earlier quoted context omitted.

> it had to do with not wanting to own the user’s contact list. Using a phone number allowed them to rely on a contact list on the users phone, which is not tied to the signal account. That doesn't make any sense. Signal did the total opposite. It started keeping sensitive user data in the cloud including your name, your photo, your phone number, and a list of your contacts. It stores that data on their servers perma…

I don't think this is true, do you have a source? They store registered users phone numbers and allow discovery by making a request with a hashed version of the phone numbers on your contact list. They add an extra layer to allow attestation of the software doing this using Intel's secure enclave. They give many examples of responding to warrants with only whether the number has been registered and the timestamp of r…

Your 2017 blog post is outdated.

See:

https://community.signalusers.org/t/can-signal-please-update...

and

https://community.signalusers.org/t/dont-want-pin-dont-want-...

See here for a discussion on how Intel's 'secure' enclave won't save you: https://community.signalusers.org/t/proper-secure-value-secu...

Re: Twilio incident: What Signal users need to know

#164
post #4

>Among the 1,900 phone numbers, the attacker explicitly searched for three numbers, and we’ve received a report from one of those three users that their account was re-registered. I wonder if this was a curious attacker trying to see what they could do with their access, or a targeted attack.

The page is also quite vague about how the attacker got these 1900 phone numbers. It seems to imply that they were just the ones around when the attacker got access. But it doesn’t actually state that clearly. Were they 1900 random numbers or were they chosen somehow? The latter is of course far worse.

They also apparently have logs of the attacker searching out three specific accounts within these 1900. That seems odd. What’s the chance that, out of all signal accounts, the three they are curious about just happen to be among the 1900 they got access to? (Perhaps signal/trillio don’t have logs from failed searches? That would be pretty poor logging though)

Re: Twilio incident: What Signal users need to know

#165
post #159

Earlier quoted context omitted.

I think the problem is that it's a requirement, not a feature you can choose to use. I'd be more inclined to use Signal if I choose to use only a user/pass. Just need a block function.

How would other people contact you?

With your username?

Re: Twilio incident: What Signal users need to know

#166
post #154

Earlier quoted context omitted.

I refuse to use or recommend Signal due to blatantly bad design choices that put people that need privacy most at risk like security researchers, journalists, abortion seekers, or dissidents. If you learn a contact phone number then you can buy their location history. Requiring phone numbers and requiring you share them with everyone you contact is brain dead. This alone is bad enough to abandon Signal but then consi…

> abortion seekers Uhhh, not sure what koolaid you've swallowed, but including them in that list is almost laughable.

I wonder how the people putting "abortion seekers" on such lists would feel if I included "self-defense rights advocates" for people 3d printing guns or smuggling them in from abroad on similar lists.

Re: Twilio incident: What Signal users need to know

#168
post #138

Earlier quoted context omitted.

What is this future UX you're imagining? How does the future solve the contacts book/short identifiers problem?

I'm not saying its an amazing experience or solves the problem systematically. Again, some people simply don't need these features. You can literally just take part of the public key and that's it. That is totally fine for some use-cases.

Then use urbit. It already exists.

Re: Twilio incident: What Signal users need to know

#169
post #160

This is a weird thread. There's a product that does secure messaging with usernames and only requires user/pass. It's called Keybase. If this is the product you want, then go use it. I don't understand why everyone wants Signal to be something it's not. I quite like Signal as they are and this "incident" demonstrates exactly what happens if a carrier gets compromised: nothing. Nothing happens. Signal decides not to t…

I love Keybase, but I would never recommend it today.

Zoom acqui-hired the team in 2020: https://blog.zoom.us/zoom-acquires-keybase-and-announces-goa...

Re: Twilio incident: What Signal users need to know

#170

Earlier quoted context omitted.

I will admit that this requirement always confused me. What is there to benefit from by requiring it?

It means that Signal doesn't need you to create or upload a list of your contacts; it uses the existing contact list from your phone. This also lets you use Signal to replace the default text messaging app on Android, automatically upgrading conversations to be encrypted when possible. This in turn means that just using Signal to communicate with someone becomes a normal, everyday activity, and less of a sign of susp…

On an iPhone, what does 'sharing your contact list' imply ?

Does the app get just name and phone numbers or all the meta data like address and personal notes that I put into my contacts ? I haven't been able to figure this out - does anyone know what Apple's policy is on this ?

Post reply on HN