Live data from Hacker News

Twilio incident: What Signal users need to know

support.signal.org

171–180 of 512 posts

Re: Twilio incident: What Signal users need to know

#171

Yes, Signal’s phone number requirement is bad. But, given that, the fact that they don’t store any messages on their side and everything is client side is still a huge benefit over a lot of other apps and still a huge step forward for privacy! Criticism is definitely important but I just wanted to put that out there that all things considered, Signal is still very much a good thing.

> don’t store any messages on their side

Google Play services are still required for the official builds because of the (unverifiable to be really) encrypted backups.

> everything is client-side

Signal's FOSS fork developers would disagree. They got outright legal problems after they wanted to implement an open source alternative. Most APIs in regards to contact management are server-side. There's Molly as a younger fork but I'm waiting for Signal to write them also a cease and desist letter.

Honestly this is why I think that Signal should be treated the same like WhatsApp. Supposedly end to end encrypted, but only until you suddenly have the FBI with printed out chats in front of your door.

As long as Signal uses proprietary services and contains proprietary blobs in their (default aka Play store-provided) app we have to treat it as an unsecure messaging system.

Especially given the RCEs that it had in the past, where it was as simple as injecting an HTML with a script tag to install malware on your system.

Re: Twilio incident: What Signal users need to know

#172
post #154

Yes, Signal’s phone number requirement is bad. But, given that, the fact that they don’t store any messages on their side and everything is client side is still a huge benefit over a lot of other apps and still a huge step forward for privacy! Criticism is definitely important but I just wanted to put that out there that all things considered, Signal is still very much a good thing.

I refuse to use or recommend Signal due to blatantly bad design choices that put people that need privacy most at risk like security researchers, journalists, abortion seekers, or dissidents. If you learn a contact phone number then you can buy their location history. Requiring phone numbers and requiring you share them with everyone you contact is brain dead. This alone is bad enough to abandon Signal but then consi…

I agree that Signal does have several questionable design decisions, but that's not one of them. You can get a sim, register with it, and take it back out. There, no location. Or even better, you can simply get a voip number.

Bottom-line, despite Signal's issues it is still the #1 IM app that I recommend to "normal people" seeking to have private conversations. No, it's not perfect, yes, it's a massive improvement over facebook/instagram/whatsapp/telegram/etc.

Re: Twilio incident: What Signal users need to know

#173
post #160

This is a weird thread. There's a product that does secure messaging with usernames and only requires user/pass. It's called Keybase. If this is the product you want, then go use it. I don't understand why everyone wants Signal to be something it's not. I quite like Signal as they are and this "incident" demonstrates exactly what happens if a carrier gets compromised: nothing. Nothing happens. Signal decides not to t…

where does Telegram fit in your opinion?

genuine question from someone oblivious to messaging advances in the last decade.

Re: Twilio incident: What Signal users need to know

#174
post #160

This is a weird thread. There's a product that does secure messaging with usernames and only requires user/pass. It's called Keybase. If this is the product you want, then go use it. I don't understand why everyone wants Signal to be something it's not. I quite like Signal as they are and this "incident" demonstrates exactly what happens if a carrier gets compromised: nothing. Nothing happens. Signal decides not to t…

Isn't Keybase semi-abandoned? There hasn't been a blog post since 2020 when they were acquired by Zoom.

Re: Twilio incident: What Signal users need to know

#175

If they (Signal) care about privacy, they need to drop the need for phone numbers to use their service, there are many ways of dealing with spam (rate limiting, captchas, ...), a true private/secure messenger app should not require any user identifiable info. And the argument of "Signal was the first e2ee messenger app to go mainstream, so they can keep ignoring user's privacy, .... yada yada..." is naive at best; th…

I second recommending Briar as a messenger. Codebase is well maintained. Specifications and documents are audited, as well as the official clients.

Re: Twilio incident: What Signal users need to know

#176
post #154

Earlier quoted context omitted.

I refuse to use or recommend Signal due to blatantly bad design choices that put people that need privacy most at risk like security researchers, journalists, abortion seekers, or dissidents. If you learn a contact phone number then you can buy their location history. Requiring phone numbers and requiring you share them with everyone you contact is brain dead. This alone is bad enough to abandon Signal but then consi…

I agree that Signal does have several questionable design decisions, but that's not one of them. You can get a sim, register with it, and take it back out. There, no location. Or even better, you can simply get a voip number. Bottom-line, despite Signal's issues it is still the #1 IM app that I recommend to "normal people" seeking to have private conversations. No, it's not perfect, yes, it's a massive improvement ov…

You can not buy a sim without KYC in almost all countries. Also most users will not realize these consequences and will just assume the defaults on Signal protect them with their every day phone number and SIM.

Also facebook/instagram/whatsapp/telegram/etc are not trying to advertise themselves for the high risk use cases Signal is actively promoted for. I obviously do not recommend anyone use those either, regardless.

Matrix is all I suggest for most people.

Re: Twilio incident: What Signal users need to know

#177

Earlier quoted context omitted.

I believe they have covered this question many times before, but I don’t see an answer on signal’s website. From memory, it had to do with not wanting to own the user’s contact list. Using a phone number allowed them to rely on a contact list on the users phone, which is not tied to the signal account. There was more nuance than that though.

> it had to do with not wanting to own the user’s contact list. Using a phone number allowed them to rely on a contact list on the users phone, which is not tied to the signal account. That doesn't make any sense. Signal did the total opposite. It started keeping sensitive user data in the cloud including your name, your photo, your phone number, and a list of your contacts. It stores that data on their servers perma…

This is absolutely NOT true. (1) Signal doesn't store your contacts, and (2) Signal only stores a name and a profile photo if you want, and in a secure way https://signal.org/blog/signal-profiles-beta/

Re: Twilio incident: What Signal users need to know

#178
post #173
post #160

This is a weird thread. There's a product that does secure messaging with usernames and only requires user/pass. It's called Keybase. If this is the product you want, then go use it. I don't understand why everyone wants Signal to be something it's not. I quite like Signal as they are and this "incident" demonstrates exactly what happens if a carrier gets compromised: nothing. Nothing happens. Signal decides not to t…

where does Telegram fit in your opinion? genuine question from someone oblivious to messaging advances in the last decade.

This article is worth a read on that front: https://www.wired.com/story/how-telegram-became-anti-faceboo...

Re: Twilio incident: What Signal users need to know

#179
post #154

Yes, Signal’s phone number requirement is bad. But, given that, the fact that they don’t store any messages on their side and everything is client side is still a huge benefit over a lot of other apps and still a huge step forward for privacy! Criticism is definitely important but I just wanted to put that out there that all things considered, Signal is still very much a good thing.

I refuse to use or recommend Signal due to blatantly bad design choices that put people that need privacy most at risk like security researchers, journalists, abortion seekers, or dissidents. If you learn a contact phone number then you can buy their location history. Requiring phone numbers and requiring you share them with everyone you contact is brain dead. This alone is bad enough to abandon Signal but then consi…

>I refuse to use or recommend Signal due to blatantly bad design choices that put people that need privacy most at risk like security researchers, journalists, abortion seekers, or dissidents.

I understand your concerns, and if I was a security researcher, journalist, abortion seeker or dissident, I wouldn't use Signal either.

But, like the vast majority of us, I am not any of those things. As such, for my (and most others) use case, Signal is great.

For those at risk from highly motivated and/or state-level actors, Signal isn't nearly enough. Nor, unless you build and run your own servers and clients (and never screw up your OpSec), is Matrix.

Signal isn't perfect. However, for most people, it's good enough.

Don't make perfect the enemy of the good. Because perfect doesn't exist.

Re: Twilio incident: What Signal users need to know

#180
post #154

Earlier quoted context omitted.

I refuse to use or recommend Signal due to blatantly bad design choices that put people that need privacy most at risk like security researchers, journalists, abortion seekers, or dissidents. If you learn a contact phone number then you can buy their location history. Requiring phone numbers and requiring you share them with everyone you contact is brain dead. This alone is bad enough to abandon Signal but then consi…

> abortion seekers Uhhh, not sure what koolaid you've swallowed, but including them in that list is almost laughable.

How do you figure? Several states had abortion laws that were never repealed and others have trigger laws on the books that have gone into effect or will shortly, so yes you can be prosecuted for abortion now. Hence the need for privacy.
Post reply on HN