Live data from Hacker News

Twilio incident: What Signal users need to know

support.signal.org

401–410 of 512 posts

Re: Twilio incident: What Signal users need to know

#401

Earlier quoted context omitted.

You already have the legal ability to own a rocket launcher - it's not any different from any other "destructive device". The main barrier to ownership is finding someone willing to sell you one, and the price they would likely ask for it. There are rich collectors in US who own tanks (with active turret), artillery etc - mostly older stuff, but still plenty destructive.

A quick google suggests that if you want your tank to have working guns and/or turret you need a Federal Destructive Device Permit, which includes a background check and ATF approval.

Destructive devices are NFA items, true. If you want to own a DD, you need to pay the $200 federal transfer tax, which is done by submitting a form to the ATF and getting a tax stamp from them.

It's not a "permit", though. And there are no special limits on who can own one - if you can legally own a gun, you can legally own a DD or any other NFA item. One doesn't even need to be a US citizen or a permanent resident for that, even people on student and work visas can do it.

Re: Twilio incident: What Signal users need to know

#402

Earlier quoted context omitted.

Requiring SIM registration is nearly universal outside of Europe and NA. https://www.comparitech.com/blog/vpn-privacy/sim-card-regist...

Great link, thanks. Interesting that my intuition was off, although I suppose it makes sense that regulations are loosest in countries with the strongest speech and privacy protections. Although I'm skeptical of how well the rules on paper are enforced in some of the countries listed as requiring registration. I have seen SIMs for sale at roadside stalls in a couple countries listed as requiring registration, and I d…

In some places, the sale itself doesn't require anything, but you need to go to the provider and show an ID to activate.

Re: Twilio incident: What Signal users need to know

#403

Earlier quoted context omitted.

I love Keybase, but I would never recommend it today. Zoom acqui-hired the team in 2020: https://blog.zoom.us/zoom-acquires-keybase-and-announces-goa...

If you're looking for a Keybase replacement, check out Peergos ( https://peergos.org ). Peergos is a P2P E2EE global filesystem and application protocol that's: * fully open source (including the server) and self hostable * has a business model of charging for a hosted version * designed so that you don't need to trust your server * audited by Cure53 * fine-grained access control * identity proofs with controllable v…

Looks interesting. Built on top of IPFS?

Re: Twilio incident: What Signal users need to know

#404
post #393

Earlier quoted context omitted.

I agree, it's an exhausting repeated conversation. It's almost as if there's a frustrating unmet need with signal as it stands for a lot of people that isn't actually placated by the repetition of an argument about how they grow as a ~~business~~ (sorry, as a non-profit). And again, signal is the only thing that can talk to people on signal so "use something else" is not helpful.

Why are you saying they need to grow? You of all people are the first to admit that everyone you need to talk to already uses it.

I'm not saying they need to grow. I'm saying that arguments resting on the importance of phone numbers to the growth of their social graph are also resting on the idea that signal must grow. I am, in fact, saying that while this may be important to them it is not strictly important to me.

And I never said everyone I need to talk to is on it. I have like 6 different messaging apps and accounts because nothing has everyone. And I'm pretty conservative about which ones I'll use compared to most people I know.

I would rather use signal than most of those, other than the fact that I also frequently need to communicate with people who have no business knowing my phone number.

Re: Twilio incident: What Signal users need to know

#405
post #388

Earlier quoted context omitted.

> Signal can't possibly read the data. They literally can. If you can brute force a 4 digit pin, you can access any of the data protected by a 4 digit pin. Some pins are longer, but it's notable that even after a lot of backlash they continue to push for "pins" and not "passwords" knowing that many will continue to use a simple four digit number. > You can prove it to yourself. Go take one of Signal's servers and try…

Let me make this clear: if the data is stored in a way that Signal's service cannot decipher it, then it's not collected by any reasonable definition of collected" . In order for Signal to collect it they would have to obtain it, which they don't, and can't, do. This term isn't just some loose word to be thrown around and abused on message boards. If we take your definition of collected where handling encrypted data…

> Let me make this clear: if the data is stored in a way that Signal's service cannot decipher it, then it's not collected by any reasonable definition of collected".

I think this is misguided, and confuses the truth. Data collected and stored remotely is being "collected and stored remotely" regardless of how well protected it is.

I will however concede that it is possible to design a system where data is encrypted on a device and then uploaded to the cloud in such a way that simply having that encrypted data on a remote server doesn't put that data at risk. Signal did not design their system in that way.

> If we take your definition of collected where handling encrypted data is collecting it, then "the internet" collects all data. Uh oh.

Again, this isn't about handling encrypted data - it's about the long term storage of highly sensitive but encrypted data - and as I said above, even that is fine if it's done correctly. Signal has done a poor job of designing their system which leaves user's data at risk.

> What signal does is route encrypted messages between principals in a system. That's all they do.

That used to be "all they do". Then, about two years ago they decided they wanted everyone to have profiles which would be kept on the cloud. As soon as you install the software, before you try to send any message to anyone you're asked to provide a pin to secure you data. Once you set one (or opt out of setting it yourself) it collects a bunch of data from your device (not needed for routing anything - remember you've just installed the app and are not trying to send or receive any message at this time) and having collected that data it encrypts it on your device using the pin, then it uploads that data to their cloud. That data can be recovered by you (or anyone else for that matter) by providing the pin that you set. The data they just collected and stored is not used to transmit, route, or delver messages. This data collection takes place in addition to any information needed temporarily to transmit, route, or delver messages.

> Read their subpoena responses, they publish all of them.

That's incorrect. They publish the ones they are allowed to publish under the law (look up "national security letters" for more info) and their refusal to provide one agency with data says nothing about the requests they are forced to comply with. Their favorite examples involve cases where Signal was unable to hand over the data because they didn't collect it in the first place. Today, because of changes in their data collection practices, they now collect exactly the kinds of data they were not collecting before and were therefore unable to provide.

It's unlikely that Signal would be compelled by a standard subpoena to brute force their users pins to access the encrypted data. It is far more likely that the data is already being collected by an agency on-site, and that the data collection is continuous and ongoing (look up "Room 641A" for an example of on-site data collection by the state).

The fact that it is unlikely that Signal would be compelled by a standard subpoena to brute force their users pins does not mean:

- Signal employees can't do it themselves any time they feel like it.

- State actors can't do it whenever they feel like it

- A hacker couldn't gain access to a server and do it

Because of the sensitive nature of the messages sent over the platform, and because they have explicitly marketed themselves to vulnerable groups like whistleblowers and activists it is critical that Signal be honest about the risks of using their software. They insist they don't collect any data, while in practice they do. They say they secure the data they have, in practice that data is exposed by way of multiple vulnerabilities that could very well endanger the freedom or even the lives of the people using Signal.

Re: Twilio incident: What Signal users need to know

#407

Earlier quoted context omitted.

Signal replaces messaging services that were all keyed by phone number. Use something else. I don't think anybody can do better than explaining why Signal works this way, and what the benefits are, vs. the (amply articulated) liabilities. This is one of the most boring repeated conversations that occurs on HN. It's incessant. Avoiding these incessant superficial conversations is, in fact, part of the premise of HN.

You sound like people defending PGP when everyone knew there were major downsides and usability issues. How can keeping phone numbers as the only option be more important than everyone being able to publish "Signal:39475638" on someplace like GitHub? Is the phone numbers part of the encryption somehow and you absolutely can't use some other number even in addition to it? Because I refuse to believe you don't understa…

And yet, there is no PGP replacement in existence despite it having died a thousand deaths and having promised replacements for decades.

> So surely then there has to be some technical limitation because what other legitimate reason is there?

It's like people aren't reading the whole thread and just responding to specific comments they don't like. The premise of Signal, or at least what's made it practically useable, is that the short identifiers are immediately available and verifiable on a mobile device. When I first reach out to someone on Signal I know the person I'm reaching out to is the owner of the identifier I used unless their phone carrier is actively compromised when I exchange the first message. To Signal's users, this is an acceptable compromise. On top of that, I don't need to do a key exchange dance every time I want to talk to a new person because I have a contacts list of their phone numbers, which Signal has verified and bound to their keys.

Signal is really pretty simple: trade key exchange parties for the phone numbers already acquired though countless years of past parties and have locally grown crypto sans intrusive cloud services. And, do it explicitly not-for-profit so there's no possible motivation to abuse this contract with users in service of shareholders.

Obviously Signal could implement whatever random people felt the need for at any given moment. But they don't and it doesn't seem like whining about it is changing anything. If you don't like that then go use one of the many alternatives or build a replacement. I'm honestly surprised nobody's built one at this point. Literally spin up a signal server, make a build of their mobile app, and let users paste in pubkeys instead of phone numbers when starting a message. See how many people use your product. Or just change the phone number db to a shortname db and remove the verification step.

Yes, these conversations are exhausting. What's even more exhausting is the perpetual outrage from "hardcore" "security" "nuts" and absurd anons driveling on about why all the practical solutions that work for users are nonsense and how they could be made "better" but who balk at actually building the solution they think the world deserves. It's a tale as old as time in the security community, sadly.

It's funny, Moxie actually did something about it and it still isn't good enough. Signal is probably the closest thing to a PGP+email replacement we've ever had. What more do people want?

Re: Twilio incident: What Signal users need to know

#408

Earlier quoted context omitted.

If you're looking for a Keybase replacement, check out Peergos ( https://peergos.org ). Peergos is a P2P E2EE global filesystem and application protocol that's: * fully open source (including the server) and self hostable * has a business model of charging for a hosted version * designed so that you don't need to trust your server * audited by Cure53 * fine-grained access control * identity proofs with controllable v…

Looks interesting. Built on top of IPFS?

Yep, we built a super minimal ipfs replacement - ipfs-nucleus (https://github.com/peergos/ipfs-nucleus) with added block level access control, which is also post-quantum.

Re: Twilio incident: What Signal users need to know

#409
post #393

Earlier quoted context omitted.

Why are you saying they need to grow? You of all people are the first to admit that everyone you need to talk to already uses it.

I'm not saying they need to grow. I'm saying that arguments resting on the importance of phone numbers to the growth of their social graph are also resting on the idea that signal must grow. I am, in fact, saying that while this may be important to them it is not strictly important to me. And I never said everyone I need to talk to is on it. I have like 6 different messaging apps and accounts because nothing has ever…

I guess I missed where the growth argument was being used. Sounds like we agree that there's no implicit need for signal to explode into oblivion like a unicorn prancing over a rainbow.

I've never regarded a phone number as something extraordinarily personal. The amount of spammers that happen across my phone number is ridiculous. It's nice when you interact with a real human using your phone number (unless it's a recruiter ffs), so the more I give it to the more likely that is to happen. I guess I just don't understand what's personally revealing about a phone number. I give my phone number to mundane things all the time so people can communicate with me. The "need to know" bar for my phone number is pretty low. It plays about the same role as an email address in my life.

Re: Twilio incident: What Signal users need to know

#410
post #337

Earlier quoted context omitted.

Signal's SMS registration codes expire after a few minutes, so you wouldn't even need to know the duration of the incident. Let's be conservative and say the codes expire after 5 minutes (it's probably shorter), then Signal is registering 380 devices a minute.

380 devices / minute would imply Signal is adding 547,200 users / day, or 199,728,000 users / year. That seems way too high. Granted some could be multiple devices per user, but still...

That sounds right.
Post reply on HN