Live data from Hacker News

Twilio incident: What Signal users need to know

support.signal.org

371–380 of 512 posts

Re: Twilio incident: What Signal users need to know

#371
post #264

Earlier quoted context omitted.

> I quite like Signal as they are and this "incident" demonstrates exactly what happens if a carrier gets compromised: nothing. Nothing happens. Signal decides not to trust any phone verifications from the period of compromise and requires affected numbers to reregister. cool, but entire carriers being compromised has never been a concern. it's state agencies forcing carriers to compromise individuals. >I don't under…

Doesn't everyone get notified when your verification status changes? Don't you need to rescan people's security numbers or whatever they call it? If this is truly a gripe you have couldn't signal also add some sort of delay to the re-verification process so that device resets take weeks to be trusted and with lots of warning and opportunities for both parties to disengage before any hostile actor takes over? As far a…

> Has there been even one "High value target apprehended because Signal" headline?

There have been a few "high value target apprehended because AN0M" headlines, and if you keep an eye out for it way more headlines/articles where you go "Yeah, that's totally another AN0M bust they just haven't publicly attributed it".

I also suspect (but have nothing more than suspicion to go on here) that companies like NSO can probably exploit phones deeply enough that they can exfiltrate screenshots of Signal. But that they do so at such high prices that it is rarely used and even more rarely hinted at publicly.

Re: Twilio incident: What Signal users need to know

#372

Earlier quoted context omitted.

If it's a choice between wearing a mask at the grocery store and the idiot next door blowing up my house with their mail order rocket launcher, I'll take the mask. If that makes me a bootlicker so be it I suppose.

I have a suspicion that I already know, but why are you jumping to a non-sequitur about masks? I tend to agree with the user to whom you're responding on this particular issue, and I still wear a mask in places such as public transit, enclosed spaces, etc. So...I guess my point is that you don't _have_ to choose between masks and gun rights. I'm unsure of why you would bring it up.

From the comment I'm replying to:

> You can already see it with several countries' response to covid.

Perhaps the commenter was going for something else, but at least where I'm at we've had two straight years of people insisting they are muzzles, an infringement on our god-given rights, and the beginning of a slippery slope to tyranny. Perhaps the commenter meant something else, but since they didn't spell out what specifically about the "response to Covid" they intended to solve with a mail-order rocket launcher of all things, I was left to interpret for myself.

Re: Twilio incident: What Signal users need to know

#373
post #73

Earlier quoted context omitted.

Close, but not quite. You see, if the other person didn't use registration lock, now you've got access to complete strangers account. Problem solved!

Which is less scary than it sounds because a signal "account" is a phone number. Oh no your privacy! If you view Signal as "a service that allows you to send E2E messages to phone numbers" then this is fine. Your friends will even get a message that says the chat has been rekeyed once the new person sets up Signal. And if you're worried about government's compelling your cell carrier to turn over your phone number th…

I was actually just trying to make a (poor attempt at a) joke. Honestly, I don't really know, or care, how Signal works.

I have no respect or interest in using any service which requires a cellphone to use it by fiat.

I don't really have any great concern about the government requesting my information, not because I "don't have anything to hide" or "because I'm too boring to care about" but simply because I don't care if they do. They will do what they will do. I will do what I will do. It's immaterial for me to worry and fret over the actions of someone else. Governments are simply a form of authority which protect those who pay up, and harm those who don't. It's neither my protector or my enemy, it's just a thing that demands money from me from time to time.

As far as secure communications are concerned, if someone is truly concerned about such things, the only reliable method I'm aware of is a one-time pad. [1] For most, such a system would be far too bulky and cumbersome to bother with, meaning that the communication itself is, in actuality, not worth securing to the highest degree. This, in turn, makes the thousands of digital alternatives "good enough" for all but nation-state threat actors. [2]

[1] https://en.wikipedia.org/wiki/One-time_pad

[2] https://nordvpn.com/blog/nation-state-threat-actors/

Re: Twilio incident: What Signal users need to know

#374

Earlier quoted context omitted.

A drop-in replacement would mean that you can still communicate with people on WhatsApp. Matrix protocol allows you to bridge WhatsApp and many other SaaS comms platforms to a single client, truly making is a drop-in replacement for WhatsApp.

I installed signal and it worked. I told a friend to install signal and it worked. I told my mom to install signal and it worked. The interface was basically the same. Any friend who installed it appeared the same way they would appear in WhatsApp. I didn't have to teach any of these people anything to get them to use it. I didn't have to talk them into making an account to use it. That is what I mean by drop in. It'…

This is as daft as Googling "email" and expecting a de facto client. You're on HN, it's nerdville, expect more interest in the protocol than clients.

People search for "email clients. Try searching for "Matrix clients". Element is the best thus far, IMO.

"Widespread adoption" includes the EU's military, healthcare and government, so I wouldn't be so certain you'll end up being right. It's hit 60m publicly addressable accounts, which doesn't include any private servers or any kind of healthcare, gov or military: https://news.itsfoss.com/matrix-sixty-million-users/

EU is forcing interoperability standards. I have a gut feeling that you will look silly in five years time, but I'll buy you a very nice craft beer if I'm wrong. Hit me up on the bet in 5 years time: me@hammyhavoc.com

You were discussing "drop-in replacements", I gave you a drop-in replacement that still maintains interoperability with WhatsApp et al, which Signal does not. Classic shifting of the goalposts.

Re: Twilio incident: What Signal users need to know

#375
post #115

Earlier quoted context omitted.

Most people will choose weak passwords given the option. And so I think it's the responsibility of the developer to enforce strong requirements ( edit: when dealing with data encryption susceptible to brute-force attacks ): entropy estimations, 128(+)-bit static keys, etc. If any user has chosen a weak passphrase, and still believes it to be secure, the developer has likely failed.

> when dealing with data encryption susceptible to brute-force attacks The "brute-force attacks" imagined here are a bad guy somehow controls Signal's systems, or else the US government seizes them and then decides to try to brute force them, right ? But these are attacks where for various rival systems it was already game over. So your assumption is that Signal's casual users, people who maybe were also considering…

I do think considering the average use case is paramount. That's why I think remote encrypted contacts storage should have never been implemented: most people won't choose strong passwords. Giving them the false notion that their sensitive stored data is cryptographically indecipherable is wrong.

As it stands now, people who create a Signal PIN aren't even warned about the security implications of using weak numeric PINs, which is among the worst of all possible worlds.

If this feature is critical, it should have been gated behind prominent passphrase entropy warnings, along with the data being put at risk [1], or it should have enforced actual strength requirements.

Signal is still better than most other messengers. I am mostly comparing it to its former self. And its former self worked flawlessly without needing to upload persisted contacts information.

1. https://github.com/signalapp/Signal-Android/blob/main/libsig...

Re: Twilio incident: What Signal users need to know

#376
post #260

Earlier quoted context omitted.

I disagree. They would not need to access the full contents of outgoing SMS to perform this duty. For example they could see the auth codes masked.

How would Twilio know what portion of the outgoing SMS was auth codes? Are you proposing they add an API where senders can annotate part of their message as private? (Not a bad idea...)

Are you familiar with their API? We use their SMS auth service at my employer. Twilio is the one composing the outbound message including auth code. The API caller is not providing Twilio with an auth code and phone number. Twilio 100% knows which portion of the outgoing SMS is the auth code.

Re: Twilio incident: What Signal users need to know

#377
post #160

This is a weird thread. There's a product that does secure messaging with usernames and only requires user/pass. It's called Keybase. If this is the product you want, then go use it. I don't understand why everyone wants Signal to be something it's not. I quite like Signal as they are and this "incident" demonstrates exactly what happens if a carrier gets compromised: nothing. Nothing happens. Signal decides not to t…

I love Keybase, but I would never recommend it today. Zoom acqui-hired the team in 2020: https://blog.zoom.us/zoom-acquires-keybase-and-announces-goa...

Lately I've been pretty happy with Jami. It's still a little unpolished, but it's been good to me so far.

Re: Twilio incident: What Signal users need to know

#378
post #366

Earlier quoted context omitted.

You've said something like this many many times and I just don't see the logic of the question. You're talking about a feature that you admit is a privacy compromise and then comparing it to an absolutely maximalist alternative, or a world where people only connect in literally one way (through their phone contact lists). Is it really so hard to imagine that other compromises may be possible, or even coexist? The ans…

I'm not comparing to some absolutely maximalist alternative. I'm asking how you get an equivalent product experience without the compromise (which would make everyone happy). I strongly believe the UX afforded by the compromise is how Signal has won all its users. The threat model and all it entails is the value prop. I genuinely believe there is a lot of commentary on this thread from people who have never designed…

You’re angrily lashing out at strawmen to justify why the lookup key is constrained to a phone number. That does not need to be bound to a phone number, it could be an identifier someone just types in.

What you’re arguing for is the recovery mechanism to get back online when you lose your private key, which is totally unrelated and could be solved independently for people who choose to give a phone number vs those using an email or some other arbitrary identifier.

Re: Twilio incident: What Signal users need to know

#379

Earlier quoted context omitted.

>My feelings on gun control can be summed up as "I want mail order rocket launchers delivered to my doorstep." I don't know. I'm a believer in extreme gun rights as well, but giving people the power to have rocket launching systems like MANPADS just seems a bit, dangerous.

You already have the legal ability to own a rocket launcher - it's not any different from any other "destructive device". The main barrier to ownership is finding someone willing to sell you one, and the price they would likely ask for it. There are rich collectors in US who own tanks (with active turret), artillery etc - mostly older stuff, but still plenty destructive.

A quick google suggests that if you want your tank to have working guns and/or turret you need a Federal Destructive Device Permit, which includes a background check and ATF approval.

Re: Twilio incident: What Signal users need to know

#380
post #337

Earlier quoted context omitted.

Signal's SMS registration codes expire after a few minutes, so you wouldn't even need to know the duration of the incident. Let's be conservative and say the codes expire after 5 minutes (it's probably shorter), then Signal is registering 380 devices a minute.

380 devices / minute would imply Signal is adding 547,200 users / day, or 199,728,000 users / year. That seems way too high. Granted some could be multiple devices per user, but still...

200M users/yr does not sound unrealistic to me given the network effects of Signal. I'm certainly not suggesting that's the actual rate - but I'd be willing to believe it's within an order of magnitude.

Here's an article from last year mentioning 50M+ downloads in 10 days. https://webcache.googleusercontent.com/search?q=cache:hsVnnQ...

Post reply on HN