Live data from Hacker News

Twilio incident: What Signal users need to know

support.signal.org

351–360 of 512 posts

Re: Twilio incident: What Signal users need to know

#351
post #71

This info gives us an interesting opportunity to estimate the rate at which Signal is adding new users. They've been very tight-lipped (understandably) about their usage stats but anecdotally they seem to be an increasingly common presence on my friends' phones, even the non-techies. As far as I can tell, Signal uses Twilio only to send SMS for phone number verification. Verification happens when a user registers a n…

> Verification happens when a user registers a new number or changes the number on their existing account.

Doesn't verification also occur when you re-install the app? Between that and how hard Signal makes device device upgrade transfers I wouldn't be surprised if most messages were for existing users.

Re: Twilio incident: What Signal users need to know

#352
post #260

Earlier quoted context omitted.

I disagree. They would not need to access the full contents of outgoing SMS to perform this duty. For example they could see the auth codes masked.

How would Twilio know what portion of the outgoing SMS was auth codes? Are you proposing they add an API where senders can annotate part of their message as private? (Not a bad idea...)

grep [0-9]+ should cover enough of the problem space.

Re: Twilio incident: What Signal users need to know

#353
post #160

This is a weird thread. There's a product that does secure messaging with usernames and only requires user/pass. It's called Keybase. If this is the product you want, then go use it. I don't understand why everyone wants Signal to be something it's not. I quite like Signal as they are and this "incident" demonstrates exactly what happens if a carrier gets compromised: nothing. Nothing happens. Signal decides not to t…

Isn't Keybase semi-abandoned? There hasn't been a blog post since 2020 when they were acquired by Zoom.

I think a lot of people abandoned it after Zoom acquired it.

Re: Twilio incident: What Signal users need to know

#354
post #284

assigning accounts to numbers is the dumbest thing. I remember when I got a new phone number a few years ago I managed to login into someone else's venmo account. Numbers are like dynamic IPs, why would anyone use this to authenticate you is beyond me.

>Numbers are like dynamic IPs Maybe for you. For other people who have had the same phone number for years or decades, they're the one of the most persistent forms of communication or identification available.

The ability to transfer phone numbers when changing mobile provides has been around for a very long time in US, but it wasn't the case in some other countries until recently.

Re: Twilio incident: What Signal users need to know

#355
post #146

Earlier quoted context omitted.

Close, but not quite. You see, if the other person didn't use registration lock, now you've got access to complete strangers account. Problem solved!

Not exactly. Registering again will make an entirely new identity with different key pair. The new phone holder won't get access to your contacts or your message history. I believe your contacts will also know about signature change as well.

Fair enough. I was just making a bit of a joke. :)

Re: Twilio incident: What Signal users need to know

#356
post #154

Earlier quoted context omitted.

I refuse to use or recommend Signal due to blatantly bad design choices that put people that need privacy most at risk like security researchers, journalists, abortion seekers, or dissidents. If you learn a contact phone number then you can buy their location history. Requiring phone numbers and requiring you share them with everyone you contact is brain dead. This alone is bad enough to abandon Signal but then consi…

>I refuse to use or recommend Signal due to blatantly bad design choices that put people that need privacy most at risk like security researchers, journalists, abortion seekers, or dissidents. I understand your concerns, and if I was a security researcher, journalist, abortion seeker or dissident, I wouldn't use Signal either. But, like the vast majority of us, I am not any of those things. As such, for my (and most…

> if I was a security researcher, journalist, abortion seeker or dissident, I wouldn't use Signal either.

I mean that's really bad, right? Supposedly Signal is the go-to alternative to doing things the hard way (e.g. GPG over email), but apparently it's just not good enough for those with the highest security needs. Given that the alternative is that these people go back to using extremely brittle software, shouldn't someone do something about that?

The implication of course is that Signal should do something about that, because they already have the user base and are in a position to adopt user identifiers that are not based on phone numbers.

Re: Twilio incident: What Signal users need to know

#357

Earlier quoted context omitted.

Signal replaces messaging services that were all keyed by phone number. Use something else. I don't think anybody can do better than explaining why Signal works this way, and what the benefits are, vs. the (amply articulated) liabilities. This is one of the most boring repeated conversations that occurs on HN. It's incessant. Avoiding these incessant superficial conversations is, in fact, part of the premise of HN.

I agree, it's an exhausting repeated conversation. It's almost as if there's a frustrating unmet need with signal as it stands for a lot of people that isn't actually placated by the repetition of an argument about how they grow as a ~~business~~ (sorry, as a non-profit). And again, signal is the only thing that can talk to people on signal so "use something else" is not helpful.

> It's almost as if there's a frustrating unmet need with signal as it stands

Do you have an alternative suggestion? Is there an app and platform you'd rather use over Signal? Maybe Wickr? Matrix? (AN0M? )

My take is there's a very small "unmet need" that frustrates such a small number of people that everybody who's tried to usurp Signal has effectively failed.

Signal has literally become "SMS but secure" for everybody I know.

> signal is the only thing that can talk to people on signal

That's untrue. There is nobody in my signal messages that I cannot talk to over the phone, via SMS, and almost everybody I can talk to via email (with a vanishingly small number of those for whom I have trusted PGP keys).

A agree with your premise that it'd be really nice to piggyback Signal's contact graph without having to do the work and make the compromises Signal have done to create that graph. But that's a totally unreasonable expectation.

(And FWIW, I think Signal totally lucked out early on by being in the right place at the right time to build their contact graph. My network of friends/colleagues exploded back when WhatsApp fucked up their messaging/policy a few years back, and practically overnight my "normal" and non privacy focussed or recreationally paranoid friends all rage quit Facebook messaging and encouraged each other to move to Signal. There was a super obvious step change in who my available Signal contacts became back then, and I'm not convinced Signal would be what it is today without that fuckup by Facebook back then.)

Re: Twilio incident: What Signal users need to know

#358
post #230

Earlier quoted context omitted.

> Even if countries do allow private gun ownership, the restrictions on how to obtain them (and what they can legally be used for, what kinds are available, etc.) are exceptionally onerous Citation needed. I, and probably the majority of the citizens of those countries do not consider the standard test/psych eval/background check/random checks in the future to make sure you're following the rules to be "exceptionally…

>Citation needed. I, and probably the majority of the citizens of those countries do not consider the standard test/psych eval/background check/random checks in the future to make sure you're following the rules to be "exceptionally onerous". Just because you've accepted the boot on your neck doesn't make it not a boot. When (not if) a currently free and democratic Western nation decides to be not so democratic anymo…

>My feelings on gun control can be summed up as "I want mail order rocket launchers delivered to my doorstep."

I don't know. I'm a believer in extreme gun rights as well, but giving people the power to have rocket launching systems like MANPADS just seems a bit, dangerous.

Re: Twilio incident: What Signal users need to know

#359
post #208

Earlier quoted context omitted.

The US is actually the only exception I am aware of world wide which gives us a distorted view of this problem.

Unless things have changed in the last few years, there are apparently countries in Europe that don't require registration: https://www.reddit.com/r/europe/comments/9ziqfi/european_cou... And that's a quite high regulation part of the world, I'd be surprised if South American or African countries were stricter.

Requiring SIM registration is nearly universal outside of Europe and NA.

https://www.comparitech.com/blog/vpn-privacy/sim-card-regist...

Re: Twilio incident: What Signal users need to know

#360
post #68

Earlier quoted context omitted.

Not only that, I don't want any service that I use tied to a phone number. Partially for the reasons you listed, but also because there are better alternatives; email, authenticator apps, physical keys, cards, etc. I hate looking at my phone. I hate using my phone. I don't want to have even more reasons to keep my phone charged and in my hand. Phones suck.

The Signal desktop app doesn't require your phone to be turned on (once it's been "paired") by the way, as opposed to for example Whatsapp.

Well sure, but does it require me to use my phone at some point in the process of account creation? That's the part I have an issue with.

I had assumed that there would be an alternative to access the service post-creation. My gripe is more with the fact that a phone is a requirement at any point.

To put it another way: imagine I had to send a letter to Signal's HQ in order to make an account. Now, obviously I'm not going to be sending and receiving letters constantly to/from Signal, but the mere fact that writing and sending a letter would be a requirement as part of the process would be at the users personal detriment. That's the point I was trying to get at - that it is forcing the user into a specific method which is undesired, arbitrary, and frustratingly unnecessary.

Post reply on HN