Live data from Hacker News

Twilio incident: What Signal users need to know

support.signal.org

341–350 of 512 posts

Re: Twilio incident: What Signal users need to know

#341

"All users can rest assured that their message history, contact lists, profile information, whom they'd blocked, and other personal data remain private and secure and were not affected." I do not understand how you can re-register someone's account to a new phone and not have the data read. If it is re-registered successfully, then you should be able to login. If you can login, you can see the data...right?

The registration means "from now on, any messages sent to [phone number] will be delivered to this device", it's not logging into an account.

Re: Twilio incident: What Signal users need to know

#342

Earlier quoted context omitted.

That may be their product management premise, but it's not why I use it. I use it because people I need to talk to are there and it has proper e2e messaging. I'm not beholden to their expectations of why I want to use their product. Also I'm not advocating for anything to be kept server side, nor do I see any reason why other identifiers couldn't be kept client side. An address book is just a list of identifiers, it'…

Signal replaces messaging services that were all keyed by phone number. Use something else. I don't think anybody can do better than explaining why Signal works this way, and what the benefits are, vs. the (amply articulated) liabilities. This is one of the most boring repeated conversations that occurs on HN. It's incessant. Avoiding these incessant superficial conversations is, in fact, part of the premise of HN.

You sound like people defending PGP when everyone knew there were major downsides and usability issues. How can keeping phone numbers as the only option be more important than everyone being able to publish "Signal:39475638" on someplace like GitHub? Is the phone numbers part of the encryption somehow and you absolutely can't use some other number even in addition to it? Because I refuse to believe you don't understand the downsides of phone numbers and I know you understand the protocol is good enough were it is relevant. So surely then there has to be some technical limitation because what other legitimate reason is there?

Re: Twilio incident: What Signal users need to know

#343

Earlier quoted context omitted.

>Citation needed. I, and probably the majority of the citizens of those countries do not consider the standard test/psych eval/background check/random checks in the future to make sure you're following the rules to be "exceptionally onerous". Just because you've accepted the boot on your neck doesn't make it not a boot. When (not if) a currently free and democratic Western nation decides to be not so democratic anymo…

If it's a choice between wearing a mask at the grocery store and the idiot next door blowing up my house with their mail order rocket launcher, I'll take the mask. If that makes me a bootlicker so be it I suppose.

I have a suspicion that I already know, but why are you jumping to a non-sequitur about masks? I tend to agree with the user to whom you're responding on this particular issue, and I still wear a mask in places such as public transit, enclosed spaces, etc.

So...I guess my point is that you don't _have_ to choose between masks and gun rights. I'm unsure of why you would bring it up.

Re: Twilio incident: What Signal users need to know

#344
post #254

Earlier quoted context omitted.

This doesn't make any sense. My assertion is that Signal would not be Signal if it has usernames. The subtext that I did not state specifically is exactly the question of why more people don't use Keybase regularly. Maybe it's not the winning UX? You don't get to look over at Signal and say "wow what a great user base I need to be a part of that" and then draw the conclusion that "Signal needs to support my idealogic…

fwiw I am a user of signal and I am expressing my need. Allowing it access to my contact list and my phone number is a privilege I extend nearly uniquely to it among similar apps and I want that gone. Because I can't just "not use signal," because signal is where the people I need to talk to are. Users are a key feature of any social product, you can't just "all else equal" them away. It's not really my problem if it…

> It's not really my problem if it's hard. That's for them to figure out.

It's totally your problem.

You want a platform they have figured out they are not interested in building. That cannot possibly be their problem.

If I were a journalist critical of the Saudi regime or an NSA whistleblower or a government leader or the leader of a drug cartel or something similar, I'd also be unhappy with needing to tie a phone number to my Signal app to be able to use it. But there's a who bunch of very suspicious looking drug busts happening over the last year or two which are without doubt related to drug dealers choosing to use AN0M instead of Signal.You need to be _very_ careful when choosing a Signal alternative...

Re: Twilio incident: What Signal users need to know

#346
post #71

This info gives us an interesting opportunity to estimate the rate at which Signal is adding new users. They've been very tight-lipped (understandably) about their usage stats but anecdotally they seem to be an increasingly common presence on my friends' phones, even the non-techies. As far as I can tell, Signal uses Twilio only to send SMS for phone number verification. Verification happens when a user registers a n…

> This info gives us an interesting opportunity to estimate the rate at which Signal is adding new users. They've been very tight-lipped (understandably) about their usage stats but anecdotally they seem to be an increasingly common presence on my friends' phones, even the non-techies.

I am assuming US or Germany.

I can't remember which thing it was exactly but there was a huge privacy scare in the US at some point which got people to switch in droves to Signal. Maybe the WhatsApp T&C change?

German's have always been more privacy-aware (hence they have a much bigger cash payment culture than almost anywhere else in North-West Europe) and it seems like a steady trickle is switching over.

But for example here in The Netherlands, I'd say 99% of people is on WhatsApp, 10% is on Telegram, and 0.1% is on privacy-focussed messaging services.

Re: Twilio incident: What Signal users need to know

#348

Earlier quoted context omitted.

> anonymized "user token" to add a buddy would be too "tech" for them? I refuse to believe a word of what you're saying. How do you transmit said anonymous user token securely? Using the secure messaging app you're already using? Meeting up in real life? Posting it on keybase? Each of these has downsides that are all solved by a phone number.

I don't see why the user token ("account name") has to be secret in every conceivable way. It just needs to be anonymous. What's wrong with meeting in real life, or exchanging account names in whatever way you initially exchanged phone numbers? You don't seem concerned over the security problem of account activation codes being sent over SMS , so I don't see why you should be concerned over exchanging anonymous accou…

> What's wrong with meeting in real life

I regularly DM people I haven't seen in person in years. I'm not going to fly cross-country to bootstrap a communication channel.

> or exchanging account names in whatever way you initially exchanged phone numbers?

Well because I exchanged phone numbers irl 7 years ago. I do not have a time machine.

> You don't seem concerned over the security problem of account activation codes being sent over SMS, so I don't see why you should be concerned over exchanging anonymous account names in the same or more secure ways.

Correct, because the bit of information "I have a signal account" is far less revealing than the bit of information "I have shared my signal account with a particular individual".

You avoid that only with some kind of public attestation of your signal identity (in keybase or on twitter or whatever) which is the best option, but generally requires everyone have a known public index of their forms of contact, which my friends from high school, generally speaking, don't.

Re: Twilio incident: What Signal users need to know

#350

Earlier quoted context omitted.

Allowing the Signal client to access your contact list is literally the premise of Signal; it's the core security UX trade it makes: no durable logs of who's talking to who on the servers, and contact lists stored exclusively on the client.

That may be their product management premise, but it's not why I use it. I use it because people I need to talk to are there and it has proper e2e messaging. I'm not beholden to their expectations of why I want to use their product. Also I'm not advocating for anything to be kept server side, nor do I see any reason why other identifiers couldn't be kept client side. An address book is just a list of identifiers, it'…

> I use it. I use it because people I need to talk to are there

This is exactly what makes it "your problem".

Signal worked out a way to provide E2E messaging that practically everybody who cares and all their friends use. You can choose to accept their phone number requirement compromise and take advantage of that huge and growing network of users, or you can go your own way and somehow convince "the people you need to talk to" to also use some alternative that more closely meets your specific needs.

> I remain unconvinced.

I get that. I understand and even partly agree with your stance. But the pragmatist in me is way happier with having a significant portion of the people in my contact list also on Signal and having a zero effort was to have an E2E encrypted chat with them. I am old enough to have gone to PGP keyparties in the late 90s. I have verified private keys for a handful of friends with some combination of privacy/security/paranoia outlooks. I can't remember the last time I sent or decrypted a PGP message (that wasn't a computer generated alert). Person to person encryption key exchange has been tried and has never gained anything like a ubiquitous network. Signal isn't perfect, but it's got very close to that, which makes it day to day usable and extremely useful. At least for me and all my friends and most of my business contacts. YMMV.

Post reply on HN