Live data from Hacker News

Twilio incident: What Signal users need to know

support.signal.org

301–310 of 512 posts

Re: Twilio incident: What Signal users need to know

#301
post #298

Earlier quoted context omitted.

These two things are not related in any way. You could clearly have a communicator that stores its contact lists exclusively on the client, but does not abuse identifiers and contact lists of different applications (PSTN calling software).

Let's concede that using other applications' identifiers is strictly bad. Probably everyone agrees. Now, how do I message you on this pristine application? Using phone numbers is a compromise taken in order to enable a UX that actually wins users. Have we forgotten what that word means?

You've said something like this many many times and I just don't see the logic of the question. You're talking about a feature that you admit is a privacy compromise and then comparing it to an absolutely maximalist alternative, or a world where people only connect in literally one way (through their phone contact lists). Is it really so hard to imagine that other compromises may be possible, or even coexist?

The answer is I give them my email or username. They give me theirs. We connect.

Using phone contact lists shortcuts this process, but the exchange still had to happen at some point. Is it really so hard to believe some users might choose to do it again? Or, god forbid, with someone they'd rather not give a phone number to?

Re: Twilio incident: What Signal users need to know

#302

The attack Twilio suffered is almost identical to the recent attack against Cloudflare: https://blog.cloudflare.com/2022-07-sms-phishing-attacks/ (even down the wording of the text messages, which are nearly identical). Cloudflare’s use of security keys prevented the attackers getting access to any accounts in that case. These attacks are sophisticated and are capable of bypassing TOTP or mobile-app-based MFA. If thi…

[deleted]

Re: Twilio incident: What Signal users need to know

#303

I'm reading yet another argument against centralization. Matrix protocol, anybody?

How is this an argument against Signal and/or centralization? Pretty much the exact same thing could have happened with matrix 3pid servers.

I really like Matrix (and Signal), I use it and even run a public Matrix home server, but jesus I can't stand obnoxious Matrix fanboys who feel the need to shoehorn some Matrix plug into literally every conversation involving Signal.

Re: Twilio incident: What Signal users need to know

#304

Earlier quoted context omitted.

If you're looking for a Keybase replacement, check out Peergos ( https://peergos.org ). Peergos is a P2P E2EE global filesystem and application protocol that's: * fully open source (including the server) and self hostable * has a business model of charging for a hosted version * designed so that you don't need to trust your server * audited by Cure53 * fine-grained access control * identity proofs with controllable v…

can communication happen across servers/vendors like in Matrix?

Yes, it's P2P. Anyone on any server can share and communicate with anyone on any other server.

You can also migrate server unilaterally and keep your social graph without needing to tell everyone, all links to your stuff continue to work afterwards.

Re: Twilio incident: What Signal users need to know

#305
post #280

Earlier quoted context omitted.

fwiw I am a user of signal and I am expressing my need. Allowing it access to my contact list and my phone number is a privilege I extend nearly uniquely to it among similar apps and I want that gone. Because I can't just "not use signal," because signal is where the people I need to talk to are. Users are a key feature of any social product, you can't just "all else equal" them away. It's not really my problem if it…

It is certainly fair to be frustrated. Respectfully, I'd challenge anyone who thinks they can build a successful secure messaging platform that concocts the perfect UX while being absolutely privacy preserving to do so. I'd give it a spin.

Except that like I said, users are a feature here. The perfect thing may exist but it doesn't matter if no one's using it. I don't know about you but I lost belief in the idea of a perfectly meritocratic world of social products a long time ago.

Re: Twilio incident: What Signal users need to know

#306
post #284

assigning accounts to numbers is the dumbest thing. I remember when I got a new phone number a few years ago I managed to login into someone else's venmo account. Numbers are like dynamic IPs, why would anyone use this to authenticate you is beyond me.

>Numbers are like dynamic IPs

Maybe for you. For other people who have had the same phone number for years or decades, they're the one of the most persistent forms of communication or identification available.

Re: Twilio incident: What Signal users need to know

#307
post #303

I'm reading yet another argument against centralization. Matrix protocol, anybody?

How is this an argument against Signal and/or centralization? Pretty much the exact same thing could have happened with matrix 3pid servers. I really like Matrix (and Signal), I use it and even run a public Matrix home server, but jesus I can't stand obnoxious Matrix fanboys who feel the need to shoehorn some Matrix plug into literally every conversation involving Signal.

Because all of those users are exposed by the same SaaS fault. Too many digital eggs in one digital basket.

What is there to plug? It's FOSS. Use it, or don't, who fucking cares? Whether you or anybody else use it or not is of absolutely zero consequence to me.

Re: Twilio incident: What Signal users need to know

#308

Earlier quoted context omitted.

fwiw I am a user of signal and I am expressing my need. Allowing it access to my contact list and my phone number is a privilege I extend nearly uniquely to it among similar apps and I want that gone. Because I can't just "not use signal," because signal is where the people I need to talk to are. Users are a key feature of any social product, you can't just "all else equal" them away. It's not really my problem if it…

Allowing the Signal client to access your contact list is literally the premise of Signal; it's the core security UX trade it makes: no durable logs of who's talking to who on the servers, and contact lists stored exclusively on the client.

That may be their product management premise, but it's not why I use it. I use it because people I need to talk to are there and it has proper e2e messaging. I'm not beholden to their expectations of why I want to use their product.

Also I'm not advocating for anything to be kept server side, nor do I see any reason why other identifiers couldn't be kept client side. An address book is just a list of identifiers, it's not magical just because it's phone numbers and already on my phone.

We've had this conversation before though. I remain unconvinced.

Re: Twilio incident: What Signal users need to know

#309
post #200

Earlier quoted context omitted.

I love Keybase, but I would never recommend it today. Zoom acqui-hired the team in 2020: https://blog.zoom.us/zoom-acquires-keybase-and-announces-goa...

I am aware. For one it still works just as well is it ever has, the Zoom acquisition didn't change anything there. So if you care about features, there shouldn't be any problem. For sure it seems to be in maintenance mode, but nothing they were doing of late with Lumens was that exciting anyway (trying to become a crypto wallet like everyone and their mothers). I would pay $/mo for a Keybase reboot with the goal of b…

I've replied in a sibling comment about Peergos which is trying to do just that.
Post reply on HN