Live data from Hacker News

Twilio incident: What Signal users need to know

support.signal.org

211–220 of 512 posts

Re: Twilio incident: What Signal users need to know

#211
post #131

This incident points to something much more severe. What role was this employee(s) whose credentials were compromised? How did these credentials allow even an employee to get plain text auth codes being sent out to end users? Such a permission should be extremely limited in who it is granted to.

I suspect many Twilio support reps need access to outgoing SMS, because manually looking over those will be an important component of handling a "someone is using your service for spamming" complaint.

I disagree. They would not need to access the full contents of outgoing SMS to perform this duty. For example they could see the auth codes masked.

Re: Twilio incident: What Signal users need to know

#212

Hey look, the centralized nature of Signal has come back to bite it. Who could ever have predicted? Edit to try and make this less snarky and more productive: In n number of threads regarding Matrix, and the Matrix vs Signal controversy[0][1], the point is that Signal took a single, simple approach and tried to proclaim it was necessary because it allows them to be agile and responsive and integrate new features or s…

[deleted]

Re: Twilio incident: What Signal users need to know

#213
post #154

Earlier quoted context omitted.

I refuse to use or recommend Signal due to blatantly bad design choices that put people that need privacy most at risk like security researchers, journalists, abortion seekers, or dissidents. If you learn a contact phone number then you can buy their location history. Requiring phone numbers and requiring you share them with everyone you contact is brain dead. This alone is bad enough to abandon Signal but then consi…

>I refuse to use or recommend Signal due to blatantly bad design choices that put people that need privacy most at risk like security researchers, journalists, abortion seekers, or dissidents. I understand your concerns, and if I was a security researcher, journalist, abortion seeker or dissident, I wouldn't use Signal either. But, like the vast majority of us, I am not any of those things. As such, for my (and most…

With Matrix you can use F-Droid build of the client. And you don't really need to trust the server too much, right? Maybe it's not enough for Snowden, but it's better.

I'm not saying "don't use Signal", in fact I still recommend it to non technical people, since it's just much simpler. But pointing at the flaws is a necessary requirement for them to be fixed

Re: Twilio incident: What Signal users need to know

#214
post #160

This is a weird thread. There's a product that does secure messaging with usernames and only requires user/pass. It's called Keybase. If this is the product you want, then go use it. I don't understand why everyone wants Signal to be something it's not. I quite like Signal as they are and this "incident" demonstrates exactly what happens if a carrier gets compromised: nothing. Nothing happens. Signal decides not to t…

Matrix is the protocol I think one should go to if Signal's requirement of phone numbers is a turn down.

Re: Twilio incident: What Signal users need to know

#215
post #190

Earlier quoted context omitted.

Your 2017 blog post is outdated. See: https://community.signalusers.org/t/can-signal-please-update... and https://community.signalusers.org/t/dont-want-pin-dont-want-... See here for a discussion on how Intel's 'secure' enclave won't save you: https://community.signalusers.org/t/proper-secure-value-secu...

There's a horrible conflation of concepts here. A pretty big one. When people talk about cloud services, they generally mean part of an application that runs on the cloud that participates as a trusted actor in the application's trust model. What people in the linked thread are realizing is that "signal has a server" and they are confused because they thought signal didn't have a server, or something. So, what's impo…

Signal has a "cloud" a server where they collect and store your name, your phone number, your photo, and list of every person you've contacted using Signal. That data isn't some ephemeral encrypted string that is only present when you "sync your profile picture" or when you send a message. It is collected and stored on their server where it will sit for at least as long as you have an account.

The justification for it was so that you could get a new device and have Signal download all of your info from your Signal's server down to your device. The data collection first takes place as soon as you set a pin or opt out of setting one (at which point a pin is assigned for you automatically).

The data is encrypted, but that does not make it impossible for signal or for 3rd parties to access it. see: https://community.signalusers.org/t/proper-secure-value-secu...

If you're a whistleblower or an activist, a list of every person you've been contacting using Signal is a highly sensitive data. No matter how you want to spin it, Signal is hosting that highly sensitive user data on their servers where Signal and 3rd parties alike could possibly gain access to them.

Re: Twilio incident: What Signal users need to know

#217
post #160

This is a weird thread. There's a product that does secure messaging with usernames and only requires user/pass. It's called Keybase. If this is the product you want, then go use it. I don't understand why everyone wants Signal to be something it's not. I quite like Signal as they are and this "incident" demonstrates exactly what happens if a carrier gets compromised: nothing. Nothing happens. Signal decides not to t…

It's interesting to me that you used Keybase as the example. My brain doing its guessing ahead thing assumed you were going to say Matrix. I've seen several popular instances of it, and run in to people actively using it at least monthly where I haven't seen anyone use Keybase in years (since the Zoom acquisition). Do you see a lot of people _actively_ using Keybase still?

I don't use Matrix a bunch so it might just be that I'm not as familiar and out of the loop. To me Keybase (despite all the drama) seems like the most isolated/pure example of a product that took the approach of username/password style accounts and applied it to application layer crypto to achieve secure messaging. Keybase later added all the network-y chat type features that make me think more of a product like Matrix. But if Matrix is good for 1:1 "chat up my contacts and groups thereof", then great. Matrix always seemed more like federated Discord or "crypto" IRC to me with the whole needing to join channels thing.

Re: Twilio incident: What Signal users need to know

#218
post #160

This is a weird thread. There's a product that does secure messaging with usernames and only requires user/pass. It's called Keybase. If this is the product you want, then go use it. I don't understand why everyone wants Signal to be something it's not. I quite like Signal as they are and this "incident" demonstrates exactly what happens if a carrier gets compromised: nothing. Nothing happens. Signal decides not to t…

> If this is the product you want, then go use it.

This is great advice if your goal is to send messages to yourself. In the real world, though, a messaging app that you're the only one using is about as useful as a bag of ice in a snowstorm. People don't need "like signal but with usernames," they need "signal with usernames (or email addresses or...)" so they can communicate with people who use signal.

Re: Twilio incident: What Signal users need to know

#219

If they (Signal) care about privacy, they need to drop the need for phone numbers to use their service, there are many ways of dealing with spam (rate limiting, captchas, ...), a true private/secure messenger app should not require any user identifiable info. And the argument of "Signal was the first e2ee messenger app to go mainstream, so they can keep ignoring user's privacy, .... yada yada..." is naive at best; th…

[deleted]

Re: Twilio incident: What Signal users need to know

#220
post #160

This is a weird thread. There's a product that does secure messaging with usernames and only requires user/pass. It's called Keybase. If this is the product you want, then go use it. I don't understand why everyone wants Signal to be something it's not. I quite like Signal as they are and this "incident" demonstrates exactly what happens if a carrier gets compromised: nothing. Nothing happens. Signal decides not to t…

[deleted]
Post reply on HN