Live data from Hacker News

Twilio incident: What Signal users need to know

support.signal.org

241–250 of 512 posts

Re: Twilio incident: What Signal users need to know

#241
post #4

>Among the 1,900 phone numbers, the attacker explicitly searched for three numbers, and we’ve received a report from one of those three users that their account was re-registered. I wonder if this was a curious attacker trying to see what they could do with their access, or a targeted attack.

The page is also quite vague about how the attacker got these 1900 phone numbers. It seems to imply that they were just the ones around when the attacker got access. But it doesn’t actually state that clearly. Were they 1900 random numbers or were they chosen somehow? The latter is of course far worse. They also apparently have logs of the attacker searching out three specific accounts within these 1900. That seems o…

Those 1900 phone numbers would be all the accounts that started the registration/re-registration process with Signal during the time the unauthorized access was available. That process is started on Signal's side and Twilio is only used at the midway point to send a device verification SMS.

Any Signal accounts that did not start that process during that time would not be able to be intercepted or accessed since Twilio has no means to begin it. The three specific accounts mentioned would be the cases found that the verification message was accessed through Twilio to register the account on the attacker's device.

So yes, in effect the 1900 were only the ones around when the attacker got access. Whether the specific three were targeted attacks or random messing around isn't clear though.

Re: Twilio incident: What Signal users need to know

#243
post #23
post #13

So that means for the duration of the attack active contacts and groups were exposed?

No. When you sign up to Signal, they send you a text message verification code. This is done via a service called "Twilio." The attackers were able to view outgoing Twilio messages, so they could enter your number on the registration screen, read the code that Twilio sent to you, then use that cod to complete the sign up process. Attackers were not able to view information about your current Signal account (if presen…

But attackers are able to impersonate you to your contacts no?

Re: Twilio incident: What Signal users need to know

#244

Earlier quoted context omitted.

It means that Signal doesn't need you to create or upload a list of your contacts; it uses the existing contact list from your phone. This also lets you use Signal to replace the default text messaging app on Android, automatically upgrading conversations to be encrypted when possible. This in turn means that just using Signal to communicate with someone becomes a normal, everyday activity, and less of a sign of susp…

On an iPhone, what does 'sharing your contact list' imply ? Does the app get just name and phone numbers or all the meta data like address and personal notes that I put into my contacts ? I haven't been able to figure this out - does anyone know what Apple's policy is on this ?

Contact Notes, specifically, require [0] a special entitlement to access them, so normal chat apps should never have access to them on iOS.

All other fields, for all contacts, are accessible once Contacts access is granted.

[0] https://developer.apple.com/documentation/bundleresources/en...

Re: Twilio incident: What Signal users need to know

#245
post #68

Earlier quoted context omitted.

Not only that, I don't want any service that I use tied to a phone number. Partially for the reasons you listed, but also because there are better alternatives; email, authenticator apps, physical keys, cards, etc. I hate looking at my phone. I hate using my phone. I don't want to have even more reasons to keep my phone charged and in my hand. Phones suck.

The Signal desktop app doesn't require your phone to be turned on (once it's been "paired") by the way, as opposed to for example Whatsapp.

By desktop app you mean a website cosplaying as a desktop app.

Re: Twilio incident: What Signal users need to know

#246
post #160

This is a weird thread. There's a product that does secure messaging with usernames and only requires user/pass. It's called Keybase. If this is the product you want, then go use it. I don't understand why everyone wants Signal to be something it's not. I quite like Signal as they are and this "incident" demonstrates exactly what happens if a carrier gets compromised: nothing. Nothing happens. Signal decides not to t…

Isn't Keybase semi-abandoned? There hasn't been a blog post since 2020 when they were acquired by Zoom.

Looks mostly abandoned to me:

https://github.com/keybase/client/graphs/code-frequency

https://github.com/keybase/client/graphs/contributors

Re: Twilio incident: What Signal users need to know

#247

I absolutely do not understand why I have to link my very sensitive Signal account to a very insecure and hard to change ID: my phone number (which can be traced to my identity in too many ways). Why Signal does not allow fully anonymous IDs (like Threema does) is a mystery to me. Signal is fine for most users, but it is inherently _unsafe_ for high-value sensitive communications where participants can expect targete…

Anonymity isn't part of Signal's risk model. If you need to stay anonymous, then there are more suitable options.

Re: Twilio incident: What Signal users need to know

#248
post #230

Earlier quoted context omitted.

>I'd wonder if it's for self defense why you didn't buy your firearm legally, since, you know, it's legal to do so. Outside of the United States, that's usually not the case. Even if countries do allow private gun ownership, the restrictions on how to obtain them (and what they can legally be used for, what kinds are available, etc.) are exceptionally onerous. And even within the United States, there are individual s…

> Even if countries do allow private gun ownership, the restrictions on how to obtain them (and what they can legally be used for, what kinds are available, etc.) are exceptionally onerous Citation needed. I, and probably the majority of the citizens of those countries do not consider the standard test/psych eval/background check/random checks in the future to make sure you're following the rules to be "exceptionally…

>Citation needed. I, and probably the majority of the citizens of those countries do not consider the standard test/psych eval/background check/random checks in the future to make sure you're following the rules to be "exceptionally onerous".

Just because you've accepted the boot on your neck doesn't make it not a boot. When (not if) a currently free and democratic Western nation decides to be not so democratic anymore (whether due to invasion, international pressure from economic partners like Russia and China, or just that the assholes in power decided to seize even more power) the citizens (or rather subjects) of those countries will have no means of fighting back. You can already see it with several countries' response to covid.

>What would you consider a just middle ground between "onerous requirements" and "everyone can buy any weapon without any requirements but paying for it"?

My feelings on gun control can be summed up as "I want mail order rocket launchers delivered to my doorstep." The state should fear its people, not the other way around, and the best way to ensure that is to give the people the means to put a bullet (or several) into any would-be tyrants.

And, regardless of what "the majority of citizens" feel about bootlicking and trampling on their own natural rights, advances in home manufacturing are quickly making any efforts to do so a pipedream.

Re: Twilio incident: What Signal users need to know

#249
post #68

Earlier quoted context omitted.

Not only that, I don't want any service that I use tied to a phone number. Partially for the reasons you listed, but also because there are better alternatives; email, authenticator apps, physical keys, cards, etc. I hate looking at my phone. I hate using my phone. I don't want to have even more reasons to keep my phone charged and in my hand. Phones suck.

The Signal desktop app doesn't require your phone to be turned on (once it's been "paired") by the way, as opposed to for example Whatsapp.

Whatsapp has finally gotten away from requiring your phone to be on. It works the same way as the Signal app now.

Re: Twilio incident: What Signal users need to know

#250

Earlier quoted context omitted.

>That doesn't make any sense. Signal did the total opposite. It started keeping sensitive user data in the cloud including your name, your photo, your phone number, and a list of your contacts. It stores that data on their servers permanently. This is the first I've heard of that. And if it's true, it's a big problem. Is there any documentation of this behavior that you can direct me to?

You aren't alone. There are a ton of people who have no idea Signal has been collecting and storing sensitive user data on their servers. There was a ton of discussion about it when the update rolled out and a lot of backlash from their users, which they ignored. They've since refused to update their privacy policy as well which I personally see as a canary warning users to avoid their service. https://community.sign…

>You aren't alone. There are a ton of people who have no idea Signal has been collecting and storing sensitive user data on their servers. There was a ton of discussion about it when the update rolled out and a lot of backlash from their users, which they ignored. They've since refused to update their privacy policy as well which I personally see as a canary warning users to avoid their service.

Edit: This bit is apparently not the case. And more's the pity.

====Section affected by edit=========

I can't (and wouldn't try to) speak for anyone else, but if you disable the PIN functionality[0], Signal doesn't upload the information you're talking about.

==== End section affected by edit=========

Which isn't a new change (IIUC, PIN disablement was introduced ~2 years ago). I'd say that using the PIN functionality should be opt-in rather than opt-out, so in that respect I agree.

Further, Signal should probably update their policy documents to reflect the current state of affairs.

But I stand by my previous comment[1].

[0] https://support.signal.org/hc/en-us/articles/360007059792#pi...

[1] https://news.ycombinator.com/item?id=32474579

Post reply on HN