Live data from Hacker News

Twilio incident: What Signal users need to know

support.signal.org

331–340 of 512 posts

Re: Twilio incident: What Signal users need to know

#331
post #160

This is a weird thread. There's a product that does secure messaging with usernames and only requires user/pass. It's called Keybase. If this is the product you want, then go use it. I don't understand why everyone wants Signal to be something it's not. I quite like Signal as they are and this "incident" demonstrates exactly what happens if a carrier gets compromised: nothing. Nothing happens. Signal decides not to t…

> It's really difficult to build a useable security product, and Signal has done it successfully.

I'd argue it hasn't. Signal still has no way of backing up your chat history (with photos, etc). Lose your phone and it's all gone forever. The PIN that the app annoyingly tells you to set up does not serve as an encryption key for your backups. There are no backups.

Once again, if your phone dies (this happened to me recently), all your data in Signal is gone forever. And there is no way to prevent that.

In this day and age, I consider this unacceptable. That is not a "useable security product".

Re: Twilio incident: What Signal users need to know

#332

Earlier quoted context omitted.

If you're looking for a Keybase replacement, check out Peergos ( https://peergos.org ). Peergos is a P2P E2EE global filesystem and application protocol that's: * fully open source (including the server) and self hostable * has a business model of charging for a hosted version * designed so that you don't need to trust your server * audited by Cure53 * fine-grained access control * identity proofs with controllable v…

Hmm, I'm looking for a Keybase replacement but one of the main reasons I use Keybase is their native apps that let you mount the cloud storage as a FUSE or FUSE-like (Dokan) native storage device. This is great for distributing encrypted keychains/configuration files and the such across various platforms (where many apps are not cloud-aware but are happy interacting with the filesystem). So far the "mount" approach s…

We have a FUSE mount and CLI. For details see: https://github.com/peergos/peergos#fuse-native-folder-mounti...

Re: Twilio incident: What Signal users need to know

#333
post #230

Earlier quoted context omitted.

> Even if countries do allow private gun ownership, the restrictions on how to obtain them (and what they can legally be used for, what kinds are available, etc.) are exceptionally onerous Citation needed. I, and probably the majority of the citizens of those countries do not consider the standard test/psych eval/background check/random checks in the future to make sure you're following the rules to be "exceptionally…

>Citation needed. I, and probably the majority of the citizens of those countries do not consider the standard test/psych eval/background check/random checks in the future to make sure you're following the rules to be "exceptionally onerous". Just because you've accepted the boot on your neck doesn't make it not a boot. When (not if) a currently free and democratic Western nation decides to be not so democratic anymo…

If it's a choice between wearing a mask at the grocery store and the idiot next door blowing up my house with their mail order rocket launcher, I'll take the mask. If that makes me a bootlicker so be it I suppose.

Re: Twilio incident: What Signal users need to know

#334
post #331
post #160

This is a weird thread. There's a product that does secure messaging with usernames and only requires user/pass. It's called Keybase. If this is the product you want, then go use it. I don't understand why everyone wants Signal to be something it's not. I quite like Signal as they are and this "incident" demonstrates exactly what happens if a carrier gets compromised: nothing. Nothing happens. Signal decides not to t…

> It's really difficult to build a useable security product, and Signal has done it successfully. I'd argue it hasn't. Signal still has no way of backing up your chat history (with photos, etc). Lose your phone and it's all gone forever. The PIN that the app annoyingly tells you to set up does not serve as an encryption key for your backups. There are no backups. Once again, if your phone dies (this happened to me re…

Signal on my Android phone makes an encrypted backup every day, this includes photos and I can copy the file off my phone if I desire (plus I point the backups to my microsd card which should still be good if the phone dies).

Re: Twilio incident: What Signal users need to know

#335
post #319

Earlier quoted context omitted.

It is not about being anonymous (though this also could be nice in some situations), it is about identity theft and credentials theft. There are numerous ways to steal my phone number and then impersonate me on Signal. For me, it is not a big deal (though a dedicated hater can probably ruin my life with that). For many people in sensitive positions, this is literally a matter of life and death.

On average, stealing a phone number is much more difficult than stealing someone's password, because of the frequency of password reuse and data breaches. If someone were to do that, it would be blocked by registration lock (which it prompts you to do). If they were to guess that, all your contacts would be notified that your identity has changed.

My phone number (and probably yours) are in the Facebook 2019-2021 leaks. These are easily downloadable.

Re: Twilio incident: What Signal users need to know

#336
post #331
post #160

This is a weird thread. There's a product that does secure messaging with usernames and only requires user/pass. It's called Keybase. If this is the product you want, then go use it. I don't understand why everyone wants Signal to be something it's not. I quite like Signal as they are and this "incident" demonstrates exactly what happens if a carrier gets compromised: nothing. Nothing happens. Signal decides not to t…

> It's really difficult to build a useable security product, and Signal has done it successfully. I'd argue it hasn't. Signal still has no way of backing up your chat history (with photos, etc). Lose your phone and it's all gone forever. The PIN that the app annoyingly tells you to set up does not serve as an encryption key for your backups. There are no backups. Once again, if your phone dies (this happened to me re…

Those are features.

Re: Twilio incident: What Signal users need to know

#337
post #71

This info gives us an interesting opportunity to estimate the rate at which Signal is adding new users. They've been very tight-lipped (understandably) about their usage stats but anecdotally they seem to be an increasingly common presence on my friends' phones, even the non-techies. As far as I can tell, Signal uses Twilio only to send SMS for phone number verification. Verification happens when a user registers a n…

Signal's SMS registration codes expire after a few minutes, so you wouldn't even need to know the duration of the incident. Let's be conservative and say the codes expire after 5 minutes (it's probably shorter), then Signal is registering 380 devices a minute.

380 devices / minute would imply Signal is adding 547,200 users / day, or 199,728,000 users / year. That seems way too high. Granted some could be multiple devices per user, but still...

Re: Twilio incident: What Signal users need to know

#338

Earlier quoted context omitted.

I don't think it's stated enough just how easy signal is as a drop in replacement for WhatsApp, the main communication method for a significant portion of the world. The ability to install a new app, use your phones contact database, and be able to use the app nearly exactly the same way you used WhatsApp is an incredible feature. With almost zero effort you can significantly reduce (capitalist or nationstate) survei…

A drop-in replacement would mean that you can still communicate with people on WhatsApp. Matrix protocol allows you to bridge WhatsApp and many other SaaS comms platforms to a single client, truly making is a drop-in replacement for WhatsApp.

I installed signal and it worked. I told a friend to install signal and it worked. I told my mom to install signal and it worked. The interface was basically the same. Any friend who installed it appeared the same way they would appear in WhatsApp. I didn't have to teach any of these people anything to get them to use it. I didn't have to talk them into making an account to use it. That is what I mean by drop in.

It's not a drop in for the behavior (talk to other people who use Facebook owned services in a way where Facebook can read all of your conversations), it's a drop in for interface (communicate with others who use the app in the same way you communicated with others using WhatsApp).

I just spent time looking at matrix.

  google "matrix"
  oh right, name space collision with popular 90s movie
  google "matrix app"
  oh, this is some library or something, not an app
  searching the page for client. "Maybe under matrix live?"
  see clients button in sub menu
  see 10 plus options I don't recognize the name of and immediately lose interest

  search "matrix" on app store
  see apps with 2 stars or less than 10 reviews, nothing official.
Matrix is what you get from the people who say "isn't Dropbox just rsync?" "isn't a chat client just a GUI for a protocol?"

100 bespoke solutions to the same problem (10 different desktop clients) is an engineering nightmare and it robs a service of "economies of scale" enabled improvements.

I don't want to read a wall of text to understand something and neither does my mom. We want to search a keyword (or "best chat app"), download an app, and use it for its purpose. That might not be optimal, but you won't see wide spread adoption without it. If you tell me "matrix is best for chat" and I can't search for matrix on google, one click download a client, and be chatting with another person who did the same with minimal setup, it's not just a non starter as far as getting widespread adoption, but it's very far from "drop in." I don't personally have a single friend who has asked me to use matrix/a matrix client, or told me how awesome matrix is. Matrix supporters should ask themselves why the main place you ever see Matrix mentioned on hacker news is in posts about Signal.

Protocols don't win customers, user interfaces do. The average end user wants to download an app and use it without having to understand what "federation" or what the security implications of something is or who owns what data. They want their most knowledgeable friend (or reddit/hn) to tell them what to use and then use it and trust that they know what they are talking about.

I'm pretty confident that as long as this page: https://matrix.org/clients/ looks like that, matrix will never see widespread adoption and it will never be the obvious choice except among the people who prefer to move their documents around with rsync and know what IRC is.

Matrix being a brand for a protocol rather than a full chat app is another self harm. The customer for a protocol is software engineers. The customer for a chat app is all humans with a phone.

Re: Twilio incident: What Signal users need to know

#340
post #331
post #160

This is a weird thread. There's a product that does secure messaging with usernames and only requires user/pass. It's called Keybase. If this is the product you want, then go use it. I don't understand why everyone wants Signal to be something it's not. I quite like Signal as they are and this "incident" demonstrates exactly what happens if a carrier gets compromised: nothing. Nothing happens. Signal decides not to t…

> It's really difficult to build a useable security product, and Signal has done it successfully. I'd argue it hasn't. Signal still has no way of backing up your chat history (with photos, etc). Lose your phone and it's all gone forever. The PIN that the app annoyingly tells you to set up does not serve as an encryption key for your backups. There are no backups. Once again, if your phone dies (this happened to me re…

> I consider this unacceptable.

On the other hand, I consider this a feature.

I'm not saying you are wrong, but I am saying different people have different ideas and requirements about how they want things like this to work.

For me, most of my Signal chats have disappearing messages enabled, to intentionally ensure there is no long term archive of conversations (assuming you trust the other people to not be screenshotting everything). It gets you into the habit of storing message that may be useful later (mostly for me stuff like event details or addresses), with the benefit of making everybody in the conversation a little more inclined to treat it all as ephemeral and be somewhat more candid then you might be in SMS or email. Not _quite_ as candid as face to face in private, but closer.

There's a widely used and agreed on signal for most of my group chats, where setting disappearing messages to 5 minutes is understood to mean "juicy gossip or legal grey area chat is about to follow" and setting it back to 8 hours or 1 week means "OK, we're done with that discussion, back to regular chat".

Post reply on HN