Live data from Hacker News

Twilio incident: What Signal users need to know

support.signal.org

381–390 of 512 posts

Re: Twilio incident: What Signal users need to know

#381
post #317

This incident points to something much more severe. What role was this employee(s) whose credentials were compromised? How did these credentials allow even an employee to get plain text auth codes being sent out to end users? Such a permission should be extremely limited in who it is granted to.

Totally agree. The message content should be private and not accessible by employees. Kind of scary when you think that so many 2FA codes are sent via Twilio.

Exactly. A malicious employee could login as any user to popular services like WhatsApp, Telegram and others that are SMS auth only, simply by knowing which endpoint to hit to kickoff an auth session initiation. I hope I am not understanding this exploit correctly. This would be a massive failure on Twilio part to allow employees access to the auth code.

Re: Twilio incident: What Signal users need to know

#382

Earlier quoted context omitted.

That may be their product management premise, but it's not why I use it. I use it because people I need to talk to are there and it has proper e2e messaging. I'm not beholden to their expectations of why I want to use their product. Also I'm not advocating for anything to be kept server side, nor do I see any reason why other identifiers couldn't be kept client side. An address book is just a list of identifiers, it'…

> I use it. I use it because people I need to talk to are there This is exactly what makes it "your problem". Signal worked out a way to provide E2E messaging that practically everybody who cares and all their friends use. You can choose to accept their phone number requirement compromise and take advantage of that huge and growing network of users, or you can go your own way and somehow convince "the people you need…

> This is exactly what makes it "your problem".

No, it’s still signal’s problem too. There is no reason to bootlick here.

> Signal isn't perfect, but it's got very close to that,

It’s really far from it. Being tied to SMS and phone numbers is a nearly fatal flaw.

Re: Twilio incident: What Signal users need to know

#383
post #213

Earlier quoted context omitted.

With Matrix you can use F-Droid build of the client. And you don't really need to trust the server too much, right? Maybe it's not enough for Snowden, but it's better. I'm not saying "don't use Signal", in fact I still recommend it to non technical people, since it's just much simpler. But pointing at the flaws is a necessary requirement for them to be fixed

I like Matrix, but I admit its E2 EE rooms seem to leak more metadata (users in th room, reactionss, maybe replies, display names, avatars) than Signal.

They leak metadata to the operators of the server. So does Signal, albeit anchored to SGX nodes they pretend they cannot access. Signal also has phone numbers making even worse.

With matrix at least you can pick a server operator you trust to provide your metadata to, or host a server yourself.

Re: Twilio incident: What Signal users need to know

#384

Earlier quoted context omitted.

What user data is being stored in the cloud? Can they decrypt it?

The information they collect includes your name, your photo, your phone number, and a list of all the people you've been in contact with using Signal. They encrypt it using a pin which they ask you to set or one they generate for you. They (and anyone else) can decrypt that data by brute forcing what is often just a 4 digit number.

Can you show me this? I'd guess it would have to be in the server code, so where is it? I don't see any real information about this on their site. Their website suggests that this information is stored locally

https://support.signal.org/hc/en-us/articles/360007459591-Si...

Re: Twilio incident: What Signal users need to know

#386

Earlier quoted context omitted.

I have a suspicion that I already know, but why are you jumping to a non-sequitur about masks? I tend to agree with the user to whom you're responding on this particular issue, and I still wear a mask in places such as public transit, enclosed spaces, etc. So...I guess my point is that you don't _have_ to choose between masks and gun rights. I'm unsure of why you would bring it up.

From the comment I'm replying to: > You can already see it with several countries' response to covid. Perhaps the commenter was going for something else, but at least where I'm at we've had two straight years of people insisting they are muzzles, an infringement on our god-given rights, and the beginning of a slippery slope to tyranny. Perhaps the commenter meant something else, but since they didn't spell out what s…

Fair enough, I suppose. I immediately thought of (what I consider to be) excessive lockdowns and enforcement in countries like Australia, but I can see how you went to masks.

Re: Twilio incident: What Signal users need to know

#387
post #260

Earlier quoted context omitted.

How would Twilio know what portion of the outgoing SMS was auth codes? Are you proposing they add an API where senders can annotate part of their message as private? (Not a bad idea...)

Are you familiar with their API? We use their SMS auth service at my employer. Twilio is the one composing the outbound message including auth code. The API caller is not providing Twilio with an auth code and phone number. Twilio 100% knows which portion of the outgoing SMS is the auth code.

sorry, not familiar with an Auth API. About 5 years ago I worked at a company that used their API, but we just used it as a service for sending texts to specific numbers. (And mostly we used different services, because it was more expensive than our other options)

Do we know that Signal was using the Twilio Auth product and not something custom on top of Twilio?

Re: Twilio incident: What Signal users need to know

#388
post #291

Earlier quoted context omitted.

Signal can't possibly read the data . How is that for itself? Only you can decrypt it! Signal doesn't have your data. They have garbage bits of effectively random noise. You can prove it to yourself. Go take one of Signal's servers and try to find someone else's data there. You won't. Why would Signal update their privacy policy to reflect the desire of misguided fear mongers? I certainly wouldn't do that if I were t…

> Signal can't possibly read the data. They literally can. If you can brute force a 4 digit pin, you can access any of the data protected by a 4 digit pin. Some pins are longer, but it's notable that even after a lot of backlash they continue to push for "pins" and not "passwords" knowing that many will continue to use a simple four digit number. > You can prove it to yourself. Go take one of Signal's servers and try…

Let me make this clear: if the data is stored in a way that Signal's service cannot decipher it, then it's not collected by any reasonable definition of collected". In order for Signal to collect it they would have to obtain it, which they don't, and can't, do.

This term isn't just some loose word to be thrown around and abused on message boards. If we take your definition of collected where handling encrypted data is collecting it, then "the internet" collects all data. Uh oh.

What signal does is route encrypted messages between principals in a system. That's all they do. They don't collect personal information. Read their subpoena responses, they publish all of them.

Re: Twilio incident: What Signal users need to know

#389

Earlier quoted context omitted.

A drop-in replacement would mean that you can still communicate with people on WhatsApp. Matrix protocol allows you to bridge WhatsApp and many other SaaS comms platforms to a single client, truly making is a drop-in replacement for WhatsApp.

I installed signal and it worked. I told a friend to install signal and it worked. I told my mom to install signal and it worked. The interface was basically the same. Any friend who installed it appeared the same way they would appear in WhatsApp. I didn't have to teach any of these people anything to get them to use it. I didn't have to talk them into making an account to use it. That is what I mean by drop in. It'…

SMS isn't an app as well, neither is Email.

But you're right, the site is pretty bad for Matrix

Re: Twilio incident: What Signal users need to know

#390
post #366

Earlier quoted context omitted.

I'm not comparing to some absolutely maximalist alternative. I'm asking how you get an equivalent product experience without the compromise (which would make everyone happy). I strongly believe the UX afforded by the compromise is how Signal has won all its users. The threat model and all it entails is the value prop. I genuinely believe there is a lot of commentary on this thread from people who have never designed…

You’re angrily lashing out at strawmen to justify why the lookup key is constrained to a phone number. That does not need to be bound to a phone number, it could be an identifier someone just types in. What you’re arguing for is the recovery mechanism to get back online when you lose your private key, which is totally unrelated and could be solved independently for people who choose to give a phone number vs those us…

1. I'm not angry at all.

2. Let me make this clear: an imperative component of signal's product is that the identifier used is verifiable, and that the only thing they store for a period of time is that users in-fact did verify their number. Everyone arguing for typed in identifiers is missing this point. That wouldn't be Signal. That's the core of what I'm saying. That would be something else where people claim short identifiers and then have to share them with each other via some other channel which I'd have to independently verify, etc.

3. Nobody arguing for non-phone-number short identifiers has proposed a solution for how you verify them and manage them that doesn't change Signal's fundamental threat model and information architecture, which, at the end of the day, is what many users are bought into. I use Keybase, feel free to hit me up there if you need a messaging platform with socially verified short identifiers. My proof is in my profile. If you want an unverified short id, email works great, I respond to that too. Point being there are existing options for "type in a short id and send it a message".

Post reply on HN