Live data from Hacker News

Twilio incident: What Signal users need to know

support.signal.org

251–260 of 512 posts

Re: Twilio incident: What Signal users need to know

#251
post #234

Earlier quoted context omitted.

Signal has a "cloud" a server where they collect and store your name, your phone number, your photo, and list of every person you've contacted using Signal. That data isn't some ephemeral encrypted string that is only present when you "sync your profile picture" or when you send a message. It is collected and stored on their server where it will sit for at least as long as you have an account. The justification for i…

You should assume every bit of information sent on the internet is archived in a massive warehouse somewhere, because it is. Thus, we have to trust the cryptography itself. Sending an encrypted message to a peer is no different from sending an encrypted message to yourself (other than the use of symmetric vs asymmetric crypto). The fact that you send a message to yourself which is stored persistently on signal's serv…

> You should assume every bit of information sent on the internet is archived in a massive warehouse somewhere, because it is.

Leaving aside the whataboutism here, you shouldn't assume that when you're using a secure messaging app that claims to be designed to never collect or store user data. Signal makes that claim at the start of their privacy policy and it is a lie. It started out true, but they begain colleting data and they refuse to update their policy.

> Thus, we have to trust the cryptography itself.

No one is suggesting we can't trust cryptography. The fact is that doesn't matter how strong your algprythm is when you're encrypting that data with a 4 digit number. You can 100% "trust the cryptography" and still acknollege that it won't take very long for someone to brute-force your pin and get your data plain text.

> Sending an encrypted message to a peer is no different from sending an encrypted message to yourself... (and it's even opt in AFAIU).

This has nothing to do with "sending data to yourself" and everything to do with Singal collecting data from you and storing it for itself. There is a massive difference between encrypting something yourself and sending that data to yourself and someone else copying data from you, encryping it, and saving it for themselves.

This data collection is also not opt in. At all. You can opt out of setting a pin, but if you do one will be automatically generated for you and your data still gets silently uploaded to Singal servers to be stored. The community spent months begging for Signal to add a way to opt out of this data collection, but they were ignored.

See:

https://community.signalusers.org/t/dont-want-pin-dont-want-...

https://community.signalusers.org/t/mandatory-pin-without-cl...

> Pretty simply, if you don't trust the crypto then you have a very different threat model

"The crypto" isn't the problem here. The problem is Signal collecting sensitive user data and permanently storing it on their servers in a manner that could allow it to be accessed by third parties and then not clearly disclosing that to their users and refusing to update their privacy policy to reflect the change.

Re: Twilio incident: What Signal users need to know

#252
post #128

Is it not possible to use an Authenticator app for Signal, given their privacy setup?

Signal uses phone numbers as (the only) unique identifier in their system currently so SMS (or phone call) is necessary to verify the device owns the number.

They've been talking about moving away from phone numbers as identifiers for a while and have implemented features like account pins that head in that direction but it hasn't happened yet.

Re: Twilio incident: What Signal users need to know

#253
post #160

This is a weird thread. There's a product that does secure messaging with usernames and only requires user/pass. It's called Keybase. If this is the product you want, then go use it. I don't understand why everyone wants Signal to be something it's not. I quite like Signal as they are and this "incident" demonstrates exactly what happens if a carrier gets compromised: nothing. Nothing happens. Signal decides not to t…

> I quite like Signal as they are and this "incident" demonstrates exactly what happens if a carrier gets compromised: nothing. Nothing happens. Signal decides not to trust any phone verifications from the period of compromise and requires affected numbers to reregister.

cool, but entire carriers being compromised has never been a concern. it's state agencies forcing carriers to compromise individuals.

>I don't understand why everyone wants Signal to be something it's not

we don't. we just warn people against using it. it's not a privacy tool, it's a larp toy like a commercial VPN.

Re: Twilio incident: What Signal users need to know

#254
post #160

This is a weird thread. There's a product that does secure messaging with usernames and only requires user/pass. It's called Keybase. If this is the product you want, then go use it. I don't understand why everyone wants Signal to be something it's not. I quite like Signal as they are and this "incident" demonstrates exactly what happens if a carrier gets compromised: nothing. Nothing happens. Signal decides not to t…

> If this is the product you want, then go use it. This is great advice if your goal is to send messages to yourself. In the real world, though, a messaging app that you're the only one using is about as useful as a bag of ice in a snowstorm. People don't need "like signal but with usernames," they need "signal with usernames (or email addresses or...)" so they can communicate with people who use signal.

This doesn't make any sense. My assertion is that Signal would not be Signal if it has usernames. The subtext that I did not state specifically is exactly the question of why more people don't use Keybase regularly. Maybe it's not the winning UX?

You don't get to look over at Signal and say "wow what a great user base I need to be a part of that" and then draw the conclusion that "Signal needs to support my idealogical aversion to using a phone number". You're missing the possibility that Signing is the way it is because it requires users to verify their phone number.

If you can't use a phone number but need to talk to people who do, securely, then you need to convince them to use a product that accommodates your niche. Why can't you use PGP and email, or Keybase, or ?

Sure, signal could add support for usernames. But how do you know there'd be anyone left after they did for you to talk to? Maybe it's not what Signal's users need.

Anyway, if Signal found a way to support usernames that didn't compromise on all the reasons I use signal and also didn't open the network up for tons of spam and low quality content, I don't think I'd complain. But that's a big IF.

Re: Twilio incident: What Signal users need to know

#255
post #68

Earlier quoted context omitted.

The Signal desktop app doesn't require your phone to be turned on (once it's been "paired") by the way, as opposed to for example Whatsapp.

Whatsapp has finally gotten away from requiring your phone to be on. It works the same way as the Signal app now.

Ah, didn't know that, but you're right (just tried it)! That's cool. I ran into this issue around a year ago when my phone broke.

Re: Twilio incident: What Signal users need to know

#256
post #200

Earlier quoted context omitted.

I love Keybase, but I would never recommend it today. Zoom acqui-hired the team in 2020: https://blog.zoom.us/zoom-acquires-keybase-and-announces-goa...

I am aware. For one it still works just as well is it ever has, the Zoom acquisition didn't change anything there. So if you care about features, there shouldn't be any problem. For sure it seems to be in maintenance mode, but nothing they were doing of late with Lumens was that exciting anyway (trying to become a crypto wallet like everyone and their mothers). I would pay $/mo for a Keybase reboot with the goal of b…

Yeah I'd rather use Keybase which has username / password than the disaster that Signal is right now. Especially when you have both Twitter and Twilio breaches, SS7 attacks, SIM swapping attacks, etc.

Keybase still works and for a simple messaging app does the job better than Signal or any other messaging app that requires a phone number. This is a total disaster.

> but nothing they were doing of late with Lumens was that exciting anyway (trying to become a crypto wallet like everyone and their mothers).

Just like Signal did, with their own private crypto wallet and cryptocurrency that they have been working suspiciously in the background for a year after being questioned.

Re: Twilio incident: What Signal users need to know

#257

Earlier quoted context omitted.

I love Keybase, but I would never recommend it today. Zoom acqui-hired the team in 2020: https://blog.zoom.us/zoom-acquires-keybase-and-announces-goa...

It's kept updated, we use it to interact with the Chia Blockchain team heavily and you just can't substitute for its identity feature to know who you're talking to.

Barely so. looks more like bare minimum life support. The slump in code contributions can speak for themselves after the acquisition.

https://github.com/keybase/client/graphs/contributors

Re: Twilio incident: What Signal users need to know

#258

Earlier quoted context omitted.

You aren't alone. There are a ton of people who have no idea Signal has been collecting and storing sensitive user data on their servers. There was a ton of discussion about it when the update rolled out and a lot of backlash from their users, which they ignored. They've since refused to update their privacy policy as well which I personally see as a canary warning users to avoid their service. https://community.sign…

>You aren't alone. There are a ton of people who have no idea Signal has been collecting and storing sensitive user data on their servers. There was a ton of discussion about it when the update rolled out and a lot of backlash from their users, which they ignored. They've since refused to update their privacy policy as well which I personally see as a canary warning users to avoid their service. Edit: This bit is app…

> I can't (and wouldn't try to) speak for anyone else, but if you disable the PIN functionality[0], Signal doesn't upload the information you're talking about.

This is also incorrect. If you opt out of setting a pin, Signal creates a pin for you and uses that to encrypt the data it uploads to their servers. Again, not your fault. Signal has gone out of their way to avoid answering direct questions about this in a plain way.

See: https://old.reddit.com/r/signal/comments/htmzrr/psa_disablin...

Re: Twilio incident: What Signal users need to know

#259
post #254

Earlier quoted context omitted.

> If this is the product you want, then go use it. This is great advice if your goal is to send messages to yourself. In the real world, though, a messaging app that you're the only one using is about as useful as a bag of ice in a snowstorm. People don't need "like signal but with usernames," they need "signal with usernames (or email addresses or...)" so they can communicate with people who use signal.

This doesn't make any sense. My assertion is that Signal would not be Signal if it has usernames. The subtext that I did not state specifically is exactly the question of why more people don't use Keybase regularly. Maybe it's not the winning UX? You don't get to look over at Signal and say "wow what a great user base I need to be a part of that" and then draw the conclusion that "Signal needs to support my idealogic…

[deleted]

Re: Twilio incident: What Signal users need to know

#260
post #131

Earlier quoted context omitted.

I suspect many Twilio support reps need access to outgoing SMS, because manually looking over those will be an important component of handling a "someone is using your service for spamming" complaint.

I disagree. They would not need to access the full contents of outgoing SMS to perform this duty. For example they could see the auth codes masked.

How would Twilio know what portion of the outgoing SMS was auth codes?

Are you proposing they add an API where senders can annotate part of their message as private? (Not a bad idea...)

Post reply on HN