Live data from Hacker News

Twilio incident: What Signal users need to know

support.signal.org

201–210 of 512 posts

Re: Twilio incident: What Signal users need to know

#201
post #107

Earlier quoted context omitted.

No, sealed sender messages are not authenticated. The sender's client uploads two things: 1) an encrypted message (with sender id encrypted), and 2) a zero-knowledge proof that the sender's client knows the recipient's delivery token. There is no authentication by the sender, and the sender does not upload any credentials.

I guess I have to rephrase myself: the API calls are authenticated, because the API endpoints will not consume anonymous requests. I'd be glad if you could point me to documentation proving that the messaging API uses completely different credentials than those for user login, and that the two are also disassociated.

This doesn't prove anything, but:

> Without authenticating, hand the encrypted envelope to the service along with the recipient’s delivery token.

Source: https://signal.org/blog/sealed-sender/#:~:text=Without%20aut...

The sender's client sends a certificate derived from the recipient's profile key.

This certificate is sent to the server as the header "Unidentified-Access-Key" - you can see how this header is derived from the Signal clients' source.

So yes, these API calls are authenticated, but not using the sender's credentials in any way.

Re: Twilio incident: What Signal users need to know

#202

Earlier quoted context omitted.

I agree that Signal does have several questionable design decisions, but that's not one of them. You can get a sim, register with it, and take it back out. There, no location. Or even better, you can simply get a voip number. Bottom-line, despite Signal's issues it is still the #1 IM app that I recommend to "normal people" seeking to have private conversations. No, it's not perfect, yes, it's a massive improvement ov…

> still the #1 IM app that I recommend to "normal people" What app do you recommend to HN types? (I'm getting ready to switch messaging platforms. All my friends use iMessage and I'm so tired of typing on my phone at them. They can be lured over to something else with the promise of encryption.)

Try Element.

Effectively the same crypto as Signal but you can be anonymous as needed. Also decentralized with many app options.

Re: Twilio incident: What Signal users need to know

#203
post #167

Earlier quoted context omitted.

With your username?

How do you text a username?

By opening signal, putting in the username and sending a text. Signal only uses MMS as a fallback when communicating with someone not on signal. When both parties are on signal SMS/MMS is not used. Presumably they are OK with not being able to communicate with people not on signal.

Re: Twilio incident: What Signal users need to know

#204
post #159

Earlier quoted context omitted.

I think the problem is that it's a requirement, not a feature you can choose to use. I'd be more inclined to use Signal if I choose to use only a user/pass. Just need a block function.

How would other people contact you?

You do know that sharing your contact list is optional?

Re: Twilio incident: What Signal users need to know

#205

Earlier quoted context omitted.

I think they are. I just also think the problem is a lot harder than people give it credit for. If they just go with a standard username (as in some form of a database lookup) then I'll be upset. But I'll be upset because this effectively doesn't solve any issue, and introduces others that have big privacy impacts and requires Signal to be a trusted source (which is antithetical to Signal's proposed mission). I do wi…

Signal is a trusted source already – you trust them telling you which number is which user.

You aren't supposed to trust Signal on that; you are supposed to verify it out-of-band using Safety Numbers.

Re: Twilio incident: What Signal users need to know

#207

Earlier quoted context omitted.

I wonder how the people putting "abortion seekers" on such lists would feel if I included "self-defense rights advocates" for people 3d printing guns or smuggling them in from abroad on similar lists.

I'd wonder if it's for self defense why you didn't buy your firearm legally, since, you know, it's legal to do so. I haven't done a deep dive, but as far as I can tell in most cases it's legal to 3d print too, though admittedly that's something that there are some semi-serious efforts to change. In other words I'd suspect the classification of "self defense advocate" to be a self serving branding effort since there a…

>I'd wonder if it's for self defense why you didn't buy your firearm legally, since, you know, it's legal to do so.

Outside of the United States, that's usually not the case. Even if countries do allow private gun ownership, the restrictions on how to obtain them (and what they can legally be used for, what kinds are available, etc.) are exceptionally onerous.

And even within the United States, there are individual states that have attempted to severely curtail private firearm ownership. Were it not for certain Supreme Court decisions, handgun ownership would be outright illegal in the District of Columbia and likely in several other states.

Re: Twilio incident: What Signal users need to know

#208
post #176

Earlier quoted context omitted.

You can not buy a sim without KYC in almost all countries. Also most users will not realize these consequences and will just assume the defaults on Signal protect them with their every day phone number and SIM. Also facebook/instagram/whatsapp/telegram/etc are not trying to advertise themselves for the high risk use cases Signal is actively promoted for. I obviously do not recommend anyone use those either, regardles…

> You can not buy a sim without KYC in almost all countries. I'd be curious to see stats on this. At least in the US, it is very easy to buy a SIM and sign up for a pre-paid plan with zero KYC.

The US is actually the only exception I am aware of world wide which gives us a distorted view of this problem.

Re: Twilio incident: What Signal users need to know

#209

Earlier quoted context omitted.

> it had to do with not wanting to own the user’s contact list. Using a phone number allowed them to rely on a contact list on the users phone, which is not tied to the signal account. That doesn't make any sense. Signal did the total opposite. It started keeping sensitive user data in the cloud including your name, your photo, your phone number, and a list of your contacts. It stores that data on their servers perma…

>That doesn't make any sense. Signal did the total opposite. It started keeping sensitive user data in the cloud including your name, your photo, your phone number, and a list of your contacts. It stores that data on their servers permanently. This is the first I've heard of that. And if it's true, it's a big problem. Is there any documentation of this behavior that you can direct me to?

You aren't alone. There are a ton of people who have no idea Signal has been collecting and storing sensitive user data on their servers. There was a ton of discussion about it when the update rolled out and a lot of backlash from their users, which they ignored. They've since refused to update their privacy policy as well which I personally see as a canary warning users to avoid their service.

https://community.signalusers.org/t/proper-secure-value-secu...

https://community.signalusers.org/t/what-contact-info-does-t...

https://community.signalusers.org/t/can-signal-please-update...

https://community.signalusers.org/t/dont-want-pin-dont-want-...

https://community.signalusers.org/t/sgx-cacheout-sgaxe-attac...

Re: Twilio incident: What Signal users need to know

#210
post #160

This is a weird thread. There's a product that does secure messaging with usernames and only requires user/pass. It's called Keybase. If this is the product you want, then go use it. I don't understand why everyone wants Signal to be something it's not. I quite like Signal as they are and this "incident" demonstrates exactly what happens if a carrier gets compromised: nothing. Nothing happens. Signal decides not to t…

Isn't Keybase semi-abandoned? There hasn't been a blog post since 2020 when they were acquired by Zoom.

I got a 6.0.1 update for Keybase like yesterday. I agree with the sentiment, though, feels like it's in maintenance mode. But its core value prop and feature has never stopped working. Point was that it's there and it works and if it's the UX model you prefer then by all means, use it at least until someone comes and reboots the concept.
Post reply on HN