Live data from Hacker News

Twilio incident: What Signal users need to know

support.signal.org

181–190 of 512 posts

Re: Twilio incident: What Signal users need to know

#181
post #154

Earlier quoted context omitted.

I refuse to use or recommend Signal due to blatantly bad design choices that put people that need privacy most at risk like security researchers, journalists, abortion seekers, or dissidents. If you learn a contact phone number then you can buy their location history. Requiring phone numbers and requiring you share them with everyone you contact is brain dead. This alone is bad enough to abandon Signal but then consi…

I agree that Signal does have several questionable design decisions, but that's not one of them. You can get a sim, register with it, and take it back out. There, no location. Or even better, you can simply get a voip number. Bottom-line, despite Signal's issues it is still the #1 IM app that I recommend to "normal people" seeking to have private conversations. No, it's not perfect, yes, it's a massive improvement ov…

> still the #1 IM app that I recommend to "normal people"

What app do you recommend to HN types? (I'm getting ready to switch messaging platforms. All my friends use iMessage and I'm so tired of typing on my phone at them. They can be lured over to something else with the promise of encryption.)

Re: Twilio incident: What Signal users need to know

#182
post #154

Earlier quoted context omitted.

I refuse to use or recommend Signal due to blatantly bad design choices that put people that need privacy most at risk like security researchers, journalists, abortion seekers, or dissidents. If you learn a contact phone number then you can buy their location history. Requiring phone numbers and requiring you share them with everyone you contact is brain dead. This alone is bad enough to abandon Signal but then consi…

> abortion seekers Uhhh, not sure what koolaid you've swallowed, but including them in that list is almost laughable.

Why is it laughable? https://www.npr.org/2022/08/12/1117092169/nebraska-cops-used...

Re: Twilio incident: What Signal users need to know

#183

Earlier quoted context omitted.

> abortion seekers Uhhh, not sure what koolaid you've swallowed, but including them in that list is almost laughable.

I wonder how the people putting "abortion seekers" on such lists would feel if I included "self-defense rights advocates" for people 3d printing guns or smuggling them in from abroad on similar lists.

I would have no problem seeing that included on such lists either. I have friends who hunt and I myself enjoy shooting on a range once in a while. I also know single parents that live alone in sketchy areas that are well trained and level headed enough to trust with firearms for home self defense.

There are almost always reasonable uses of many services and tools we tend to have knee-jerk-ban reactions to as a society.

Re: Twilio incident: What Signal users need to know

#184

Earlier quoted context omitted.

I believe they have covered this question many times before, but I don’t see an answer on signal’s website. From memory, it had to do with not wanting to own the user’s contact list. Using a phone number allowed them to rely on a contact list on the users phone, which is not tied to the signal account. There was more nuance than that though.

> it had to do with not wanting to own the user’s contact list. Using a phone number allowed them to rely on a contact list on the users phone, which is not tied to the signal account. That doesn't make any sense. Signal did the total opposite. It started keeping sensitive user data in the cloud including your name, your photo, your phone number, and a list of your contacts. It stores that data on their servers perma…

>That doesn't make any sense. Signal did the total opposite. It started keeping sensitive user data in the cloud including your name, your photo, your phone number, and a list of your contacts. It stores that data on their servers permanently.

This is the first I've heard of that. And if it's true, it's a big problem.

Is there any documentation of this behavior that you can direct me to?

Re: Twilio incident: What Signal users need to know

#185
post #154

Earlier quoted context omitted.

I refuse to use or recommend Signal due to blatantly bad design choices that put people that need privacy most at risk like security researchers, journalists, abortion seekers, or dissidents. If you learn a contact phone number then you can buy their location history. Requiring phone numbers and requiring you share them with everyone you contact is brain dead. This alone is bad enough to abandon Signal but then consi…

I agree that Signal does have several questionable design decisions, but that's not one of them. You can get a sim, register with it, and take it back out. There, no location. Or even better, you can simply get a voip number. Bottom-line, despite Signal's issues it is still the #1 IM app that I recommend to "normal people" seeking to have private conversations. No, it's not perfect, yes, it's a massive improvement ov…

You need a government issued ID to get mobile service many places. You can’t just get a SIM in the same way you get a burner email address.

Re: Twilio incident: What Signal users need to know

#186

The attack Twilio suffered is almost identical to the recent attack against Cloudflare: https://blog.cloudflare.com/2022-07-sms-phishing-attacks/ (even down the wording of the text messages, which are nearly identical). Cloudflare’s use of security keys prevented the attackers getting access to any accounts in that case. These attacks are sophisticated and are capable of bypassing TOTP or mobile-app-based MFA. If thi…

to be clear they are not able to "bypass" TOTP or mobile-app-based MFA in the way security folks think of that term. They were able to bypass humans[1], which are often the weakest link in security related matters.

[1]: "Twilio became aware of unauthorized access to information related to a limited number of Twilio customer accounts through a sophisticated social engineering attack designed to steal employee credentials. This broad based attack against our employee base succeeded in fooling some employees into providing their credentials. The attackers then used the stolen credentials to gain access to some of our internal systems, where they were able to access certain customer data. " https://www.twilio.com/blog/august-2022-social-engineering-a...

Re: Twilio incident: What Signal users need to know

#187

Earlier quoted context omitted.

> it had to do with not wanting to own the user’s contact list. Using a phone number allowed them to rely on a contact list on the users phone, which is not tied to the signal account. That doesn't make any sense. Signal did the total opposite. It started keeping sensitive user data in the cloud including your name, your photo, your phone number, and a list of your contacts. It stores that data on their servers perma…

This is absolutely NOT true. (1) Signal doesn't store your contacts, and (2) Signal only stores a name and a profile photo if you want, and in a secure way https://signal.org/blog/signal-profiles-beta/

I'm sorry to be the one to tell you, but Signal 100% stores your contacts. They keep your name, your photo, your phone number, and a list of every person you've contacted using Signal. That data is permanently stored on their servers.

See: https://community.signalusers.org/t/can-signal-please-update...

> "This should be updated for the recent changes where contacts are uploaded to Signal’s servers and stored permanently along with Groups V2 and other data, protected by a 4-digit minimum PIN and Intel SGX – there have been concerns 5 raised 2 in these forums, particularly if one of your contacts chooses a brute-forceable PIN which in the context of an Intel SGX vulnerability 1 could leak a lot of contact data if hacked, even if you choose a strong password."

See the two links sited in that comment for more information on why it isn't actually stored in "secure" way.

Re: Twilio incident: What Signal users need to know

#189
post #154

Earlier quoted context omitted.

I refuse to use or recommend Signal due to blatantly bad design choices that put people that need privacy most at risk like security researchers, journalists, abortion seekers, or dissidents. If you learn a contact phone number then you can buy their location history. Requiring phone numbers and requiring you share them with everyone you contact is brain dead. This alone is bad enough to abandon Signal but then consi…

>I refuse to use or recommend Signal due to blatantly bad design choices that put people that need privacy most at risk like security researchers, journalists, abortion seekers, or dissidents. I understand your concerns, and if I was a security researcher, journalist, abortion seeker or dissident, I wouldn't use Signal either. But, like the vast majority of us, I am not any of those things. As such, for my (and most…

Those of us that do not need high privacy today might need it tomorrow, or maybe someone we frequently communicate with.

We also have a responsibility to favor tools and practices that make those that really need privacy not stand out.

Element or other Matrix clients are easy to use and lack the serious flaws I outlined for Signal.

Re: Twilio incident: What Signal users need to know

#190
post #153

Earlier quoted context omitted.

I don't think this is true, do you have a source? They store registered users phone numbers and allow discovery by making a request with a hashed version of the phone numbers on your contact list. They add an extra layer to allow attestation of the software doing this using Intel's secure enclave. They give many examples of responding to warrants with only whether the number has been registered and the timestamp of r…

Your 2017 blog post is outdated. See: https://community.signalusers.org/t/can-signal-please-update... and https://community.signalusers.org/t/dont-want-pin-dont-want-... See here for a discussion on how Intel's 'secure' enclave won't save you: https://community.signalusers.org/t/proper-secure-value-secu...

There's a horrible conflation of concepts here. A pretty big one.

When people talk about cloud services, they generally mean part of an application that runs on the cloud that participates as a trusted actor in the application's trust model.

What people in the linked thread are realizing is that "signal has a server" and they are confused because they thought signal didn't have a server, or something.

So, what's important about Signals servers is that, outside of initial key exchange which is verified by two parties out of band, they are not a trusted entity, ever. When you send a message it goes through signals servers. When you sync your profile picture with other devices, same thing. The data transits signals servers. This is made possible because of cryptography. By encrypting the data in a way that is indecipherable by 3rd parties (Signal's servers included) your data is isomorphic to random noise. So, the only thing Signal needs to do is route the random noise to the right place. If it doesn't do that, it's a denial of service and about the only attack you're vulnerable to if you use Signal. Otherwise, the receiver gets the exact random noise that you sent, but only they can make sense of it because of the miracle of cryptography.

If you're really doing to throw a fit because Signal syncs a profile picture between your devices using the same level of crypto as is used for messaging then you're honestly crazy.

No. Signal did not "not have a cloud" and now they "have a cloud". Not by any reasonable interpretation of the events.

Post reply on HN