Live data from Hacker News

Twilio incident: What Signal users need to know

support.signal.org

191–200 of 512 posts

Re: Twilio incident: What Signal users need to know

#191
post #173
post #160

This is a weird thread. There's a product that does secure messaging with usernames and only requires user/pass. It's called Keybase. If this is the product you want, then go use it. I don't understand why everyone wants Signal to be something it's not. I quite like Signal as they are and this "incident" demonstrates exactly what happens if a carrier gets compromised: nothing. Nothing happens. Signal decides not to t…

where does Telegram fit in your opinion? genuine question from someone oblivious to messaging advances in the last decade.

telegram "supports" e2e encryption, but it is frustrating to use and is not enabled by default

Re: Twilio incident: What Signal users need to know

#192
post #160

This is a weird thread. There's a product that does secure messaging with usernames and only requires user/pass. It's called Keybase. If this is the product you want, then go use it. I don't understand why everyone wants Signal to be something it's not. I quite like Signal as they are and this "incident" demonstrates exactly what happens if a carrier gets compromised: nothing. Nothing happens. Signal decides not to t…

It's interesting to me that you used Keybase as the example. My brain doing its guessing ahead thing assumed you were going to say Matrix. I've seen several popular instances of it, and run in to people actively using it at least monthly where I haven't seen anyone use Keybase in years (since the Zoom acquisition). Do you see a lot of people _actively_ using Keybase still?

Re: Twilio incident: What Signal users need to know

#193
post #173

Earlier quoted context omitted.

where does Telegram fit in your opinion? genuine question from someone oblivious to messaging advances in the last decade.

telegram "supports" e2e encryption, but it is frustrating to use and is not enabled by default

Last time I checked, it also doesn't work for group chats. Has that changed?

Re: Twilio incident: What Signal users need to know

#194
post #71

This info gives us an interesting opportunity to estimate the rate at which Signal is adding new users. They've been very tight-lipped (understandably) about their usage stats but anecdotally they seem to be an increasingly common presence on my friends' phones, even the non-techies. As far as I can tell, Signal uses Twilio only to send SMS for phone number verification. Verification happens when a user registers a n…

Signal's SMS registration codes expire after a few minutes, so you wouldn't even need to know the duration of the incident. Let's be conservative and say the codes expire after 5 minutes (it's probably shorter), then Signal is registering 380 devices a minute.

Re: Twilio incident: What Signal users need to know

#195

Yes, Signal’s phone number requirement is bad. But, given that, the fact that they don’t store any messages on their side and everything is client side is still a huge benefit over a lot of other apps and still a huge step forward for privacy! Criticism is definitely important but I just wanted to put that out there that all things considered, Signal is still very much a good thing.

> don’t store any messages on their side Google Play services are still required for the official builds because of the (unverifiable to be really) encrypted backups. > everything is client-side Signal's FOSS fork developers would disagree. They got outright legal problems after they wanted to implement an open source alternative. Most APIs in regards to contact management are server-side. There's Molly as a younger…

we still don't know of anyone with their messages printed out. Signal probably doesn't have all the contacts hoarded on their server, while WA certainly does. For me, there is a big difference in "might be buggy" vs "certainly is privacy hostile"

I still prefer Matrix, but Signal is clearly the next best thing for chats. And it also has quite a number of non-HN users :)

Re: Twilio incident: What Signal users need to know

#196

Yes, Signal’s phone number requirement is bad. But, given that, the fact that they don’t store any messages on their side and everything is client side is still a huge benefit over a lot of other apps and still a huge step forward for privacy! Criticism is definitely important but I just wanted to put that out there that all things considered, Signal is still very much a good thing.

[deleted]

Re: Twilio incident: What Signal users need to know

#197
post #176

Earlier quoted context omitted.

I agree that Signal does have several questionable design decisions, but that's not one of them. You can get a sim, register with it, and take it back out. There, no location. Or even better, you can simply get a voip number. Bottom-line, despite Signal's issues it is still the #1 IM app that I recommend to "normal people" seeking to have private conversations. No, it's not perfect, yes, it's a massive improvement ov…

You can not buy a sim without KYC in almost all countries. Also most users will not realize these consequences and will just assume the defaults on Signal protect them with their every day phone number and SIM. Also facebook/instagram/whatsapp/telegram/etc are not trying to advertise themselves for the high risk use cases Signal is actively promoted for. I obviously do not recommend anyone use those either, regardles…

> You can not buy a sim without KYC in almost all countries.

I'd be curious to see stats on this. At least in the US, it is very easy to buy a SIM and sign up for a pre-paid plan with zero KYC.

Re: Twilio incident: What Signal users need to know

#198

>it was possible for them to attempt to register the phone numbers they accessed to another device using the SMS verification code That's a thing? If my number expires and gets reassigned to someone else, and they register for Signal, I'll get locked out of my account just like that? And they'll start getting all the messages that were addressed to me?

It's not your account any more. The new owner gets "your" SMS and phone calls too. The identity is backed by the ownership of the number, not your person.

Importantly the safety number will change since it's a new device. If you care about stuff like this, verify the new device out of band and distrust any unexpected changes. Most people don't care and they still see a huge improvement over plain SMS.

Re: Twilio incident: What Signal users need to know

#199

Earlier quoted context omitted.

> abortion seekers Uhhh, not sure what koolaid you've swallowed, but including them in that list is almost laughable.

I wonder how the people putting "abortion seekers" on such lists would feel if I included "self-defense rights advocates" for people 3d printing guns or smuggling them in from abroad on similar lists.

I'd wonder if it's for self defense why you didn't buy your firearm legally, since, you know, it's legal to do so. I haven't done a deep dive, but as far as I can tell in most cases it's legal to 3d print too, though admittedly that's something that there are some semi-serious efforts to change.

In other words I'd suspect the classification of "self defense advocate" to be a self serving branding effort since there are legal ways to accomplish the same, but I wouldn't doubt the need of this person for a secure messaging platform.

Re: Twilio incident: What Signal users need to know

#200
post #160

This is a weird thread. There's a product that does secure messaging with usernames and only requires user/pass. It's called Keybase. If this is the product you want, then go use it. I don't understand why everyone wants Signal to be something it's not. I quite like Signal as they are and this "incident" demonstrates exactly what happens if a carrier gets compromised: nothing. Nothing happens. Signal decides not to t…

I love Keybase, but I would never recommend it today. Zoom acqui-hired the team in 2020: https://blog.zoom.us/zoom-acquires-keybase-and-announces-goa...

I am aware. For one it still works just as well is it ever has, the Zoom acquisition didn't change anything there. So if you care about features, there shouldn't be any problem. For sure it seems to be in maintenance mode, but nothing they were doing of late with Lumens was that exciting anyway (trying to become a crypto wallet like everyone and their mothers).

I would pay $/mo for a Keybase reboot with the goal of building a sustainable business like Signal did instead of taking VC money for a shot at the moon. Until someone does that, Keybase continues to work as a messaging app with usernames instead of phone numbers.

Post reply on HN