Live data from Hacker News

Twilio incident: What Signal users need to know

support.signal.org

361–370 of 512 posts

Re: Twilio incident: What Signal users need to know

#361

Earlier quoted context omitted.

What part of what I said was inaccurate?

What user data is being stored in the cloud? Can they decrypt it?

The information they collect includes your name, your photo, your phone number, and a list of all the people you've been in contact with using Signal.

They encrypt it using a pin which they ask you to set or one they generate for you. They (and anyone else) can decrypt that data by brute forcing what is often just a 4 digit number.

Re: Twilio incident: What Signal users need to know

#362

Earlier quoted context omitted.

Isn't Keybase semi-abandoned? There hasn't been a blog post since 2020 when they were acquired by Zoom.

I think a lot of people abandoned it after Zoom acquired it.

Anecdata point, I jumped ship as soon as that became public.

Zoom is a looooong way from having the sort of trust that Signal/WhisperSystems have in my mind.

(Which is a pity, I really liked the idea of Keybase.)

Re: Twilio incident: What Signal users need to know

#363

Earlier quoted context omitted.

Why is it laughable? https://www.npr.org/2022/08/12/1117092169/nebraska-cops-used...

I agree none of this is laughable. Irrelevant of your position, please read the entire article that you referenced for facts (pre-RvW overturn, pregnancy at 23~28 (?) weeks, took Pregnot, buried in back yard, Nebraska law was at that time 20 weeks). The Vice article seems to have quite a lot more facts and references. https://www.vice.com/en/article/n7zevd/this-is-the-data-face...

I did read it.

The point is that the mother is being charged with aiding her daughter to have an abortion due to evidence collected from chats they thought were secure, but which were still susceptible to a warrant.

Now, there are other charges. And the time the abortion happened it occurred while the 20 week ban wasn't being enforced, because the state knew it wouldn't hold up under Roe (and is only illegal and chargeable now, with the court having overturned Roe). So, yes, it's super interesting.

But the point is that police are charging someone for aiding an abortion due to texts the sender thought were secure. That's the entire relevancy. Anything else about this particular incident isn't germane.

Re: Twilio incident: What Signal users need to know

#364
post #260

Earlier quoted context omitted.

I disagree. They would not need to access the full contents of outgoing SMS to perform this duty. For example they could see the auth codes masked.

How would Twilio know what portion of the outgoing SMS was auth codes? Are you proposing they add an API where senders can annotate part of their message as private? (Not a bad idea...)

Wouldn't the spammers then just mark 100% of their spam as private?

Re: Twilio incident: What Signal users need to know

#365

Earlier quoted context omitted.

A drop-in replacement would mean that you can still communicate with people on WhatsApp. Matrix protocol allows you to bridge WhatsApp and many other SaaS comms platforms to a single client, truly making is a drop-in replacement for WhatsApp.

I installed signal and it worked. I told a friend to install signal and it worked. I told my mom to install signal and it worked. The interface was basically the same. Any friend who installed it appeared the same way they would appear in WhatsApp. I didn't have to teach any of these people anything to get them to use it. I didn't have to talk them into making an account to use it. That is what I mean by drop in. It'…

[deleted]

Re: Twilio incident: What Signal users need to know

#366
post #298

Earlier quoted context omitted.

Let's concede that using other applications' identifiers is strictly bad. Probably everyone agrees. Now, how do I message you on this pristine application? Using phone numbers is a compromise taken in order to enable a UX that actually wins users. Have we forgotten what that word means?

You've said something like this many many times and I just don't see the logic of the question. You're talking about a feature that you admit is a privacy compromise and then comparing it to an absolutely maximalist alternative, or a world where people only connect in literally one way (through their phone contact lists). Is it really so hard to imagine that other compromises may be possible, or even coexist? The ans…

I'm not comparing to some absolutely maximalist alternative. I'm asking how you get an equivalent product experience without the compromise (which would make everyone happy). I strongly believe the UX afforded by the compromise is how Signal has won all its users. The threat model and all it entails is the value prop.

I genuinely believe there is a lot of commentary on this thread from people who have never designed a secure system. You never get 100% security and 100% privacy. Even if you only use public keys, web3 style, you're still a traceable public key--by definition not private. Okay everyone uses a fresh key for every action. Well now you have a problem figuring out who anybody is and whether you should trust them. Either trust isn't self-sovereign or it is. And we've learned time and time again that self-sovereign trust systems are akin to anarchy. Signal leverages the verifiable short identifiers available to a mobile phone, at the expense of 100% perfect anonymity when asking the question "has this phone number used signal". Literally everything beyond that point is 100% secure and as private as two public keys corresponding can be.

1. As a signal user, I don't want to see the threat model weakened so that we can include email anons, personally.

2. Even if we did, I don't understand how doing so in any way solves the privacy issue. How is email any more private than phone? If an email provider got phished people would be yelling the same thing "how could signal be so stupid to use email, don't you know it's insecure". Email providers can still be compelled into shenanigans, too.

3. Signal as a product has to facilitate a key exchange. I'm pretty sure you can checkout their source code and run their protocol and solve the key exchange portion differently if you so desire. You could have "signal without phone numbers or email" tomorrow if you wanted. As long as your users are willing to copy and paste public keys into their messenger, that is.

To sum up: the key exchange and distribution is the entire problem. And Signal presents an adequate solution: bind phone numbers to asymmetric crypto, add perfect forward secrecy and give people secure messaging. Surely it's not for everyone, but this incident in my eyes only further validated that this premise is solid.

Re: Twilio incident: What Signal users need to know

#367
post #154

Earlier quoted context omitted.

I refuse to use or recommend Signal due to blatantly bad design choices that put people that need privacy most at risk like security researchers, journalists, abortion seekers, or dissidents. If you learn a contact phone number then you can buy their location history. Requiring phone numbers and requiring you share them with everyone you contact is brain dead. This alone is bad enough to abandon Signal but then consi…

>I refuse to use or recommend Signal due to blatantly bad design choices that put people that need privacy most at risk like security researchers, journalists, abortion seekers, or dissidents. I understand your concerns, and if I was a security researcher, journalist, abortion seeker or dissident, I wouldn't use Signal either. But, like the vast majority of us, I am not any of those things. As such, for my (and most…

What a terrible argument. You might as well just switch to Telegram

Re: Twilio incident: What Signal users need to know

#368

Earlier quoted context omitted.

>Citation needed. I, and probably the majority of the citizens of those countries do not consider the standard test/psych eval/background check/random checks in the future to make sure you're following the rules to be "exceptionally onerous". Just because you've accepted the boot on your neck doesn't make it not a boot. When (not if) a currently free and democratic Western nation decides to be not so democratic anymo…

>My feelings on gun control can be summed up as "I want mail order rocket launchers delivered to my doorstep." I don't know. I'm a believer in extreme gun rights as well, but giving people the power to have rocket launching systems like MANPADS just seems a bit, dangerous.

You already have the legal ability to own a rocket launcher - it's not any different from any other "destructive device". The main barrier to ownership is finding someone willing to sell you one, and the price they would likely ask for it. There are rich collectors in US who own tanks (with active turret), artillery etc - mostly older stuff, but still plenty destructive.

Re: Twilio incident: What Signal users need to know

#369

>it was possible for them to attempt to register the phone numbers they accessed to another device using the SMS verification code That's a thing? If my number expires and gets reassigned to someone else, and they register for Signal, I'll get locked out of my account just like that? And they'll start getting all the messages that were addressed to me?

It's not your account any more. The new owner gets "your" SMS and phone calls too. The identity is backed by the ownership of the number, not your person. Importantly the safety number will change since it's a new device. If you care about stuff like this, verify the new device out of band and distrust any unexpected changes. Most people don't care and they still see a huge improvement over plain SMS.

Though note that your message history is still private, as you have to manually export and import the local message history whenever you get a new device.

Re: Twilio incident: What Signal users need to know

#370
post #291

Earlier quoted context omitted.

> You should assume every bit of information sent on the internet is archived in a massive warehouse somewhere, because it is. Leaving aside the whataboutism here, you shouldn't assume that when you're using a secure messaging app that claims to be designed to never collect or store user data. Signal makes that claim at the start of their privacy policy and it is a lie. It started out true, but they begain colleting…

Signal can't possibly read the data . How is that for itself? Only you can decrypt it! Signal doesn't have your data. They have garbage bits of effectively random noise. You can prove it to yourself. Go take one of Signal's servers and try to find someone else's data there. You won't. Why would Signal update their privacy policy to reflect the desire of misguided fear mongers? I certainly wouldn't do that if I were t…

> Signal can't possibly read the data.

They literally can. If you can brute force a 4 digit pin, you can access any of the data protected by a 4 digit pin. Some pins are longer, but it's notable that even after a lot of backlash they continue to push for "pins" and not "passwords" knowing that many will continue to use a simple four digit number.

> You can prove it to yourself. Go take one of Signal's servers and try to find someone else's data there. You won't.

um... what?

> Why would Signal update their privacy policy

To accurately reflect the data they collect and how it is used? So that they don't lie to their users by making claims that are demonstrably false? To notify whistleblowers and activists that their information and the information of those who they are in contact with could be discovered by state actors who can force Signal to give them access? There's three good reasons right there.

I'm sorry you're so upset by this. I know the reality is uncomfortable but that doesn't make it "fear mongering". I honestly wish it wasn't true. I wish they weren't collecting user data, I wish they were doing more to secure what they do collect, and most of all I wish they were honest and forthcoming about what they are doing, but wishes can't change what is. I hope that regardless of if you use Signal or not, you'll try to accept facts even when they aren't easy to accept.

Post reply on HN