Live data from Hacker News

Twilio incident: What Signal users need to know

support.signal.org

431–440 of 512 posts

Re: Twilio incident: What Signal users need to know

#431
post #285

Earlier quoted context omitted.

Anonymity isn't part of Signal's risk model. If you need to stay anonymous, then there are more suitable options.

It's not about that, it's pretty much the same as using a dynamic IP to authenticate you

Not really, a phone isn't assigned a random number from a pool every time you turn it on or reconnect to a tower, then given to other users ad hoc.

A static IP maybe, except the IP is portable to a new AS if/when you want to move to a new provider. It's even susceptible to a false BGP route =)

Re: Twilio incident: What Signal users need to know

#432
post #409

Earlier quoted context omitted.

I'm not saying they need to grow. I'm saying that arguments resting on the importance of phone numbers to the growth of their social graph are also resting on the idea that signal must grow. I am, in fact, saying that while this may be important to them it is not strictly important to me. And I never said everyone I need to talk to is on it. I have like 6 different messaging apps and accounts because nothing has ever…

I guess I missed where the growth argument was being used. Sounds like we agree that there's no implicit need for signal to explode into oblivion like a unicorn prancing over a rainbow. I've never regarded a phone number as something extraordinarily personal. The amount of spammers that happen across my phone number is ridiculous. It's nice when you interact with a real human using your phone number (unless it's a re…

I think that people's experience with the privacy and significance of their phone number varies a lot by demographic.

Re: Twilio incident: What Signal users need to know

#433

The attack Twilio suffered is almost identical to the recent attack against Cloudflare: https://blog.cloudflare.com/2022-07-sms-phishing-attacks/ (even down the wording of the text messages, which are nearly identical). Cloudflare’s use of security keys prevented the attackers getting access to any accounts in that case. These attacks are sophisticated and are capable of bypassing TOTP or mobile-app-based MFA. If thi…

I wonder if Twilio corporate culture has an aversion to or outright not-implemented or banned more secure methods of MFA such as security keys because of their $$ acquisition of Authy. Anyone have any insight?

Re: Twilio incident: What Signal users need to know

#434
post #389

Earlier quoted context omitted.

I installed signal and it worked. I told a friend to install signal and it worked. I told my mom to install signal and it worked. The interface was basically the same. Any friend who installed it appeared the same way they would appear in WhatsApp. I didn't have to teach any of these people anything to get them to use it. I didn't have to talk them into making an account to use it. That is what I mean by drop in. It'…

SMS isn't an app as well, neither is Email. But you're right, the site is pretty bad for Matrix

Not sorting by (and making visible) a popularity count or a preferred client per platform presents a potential interested person with an arbitrary decision. Rather than "let's experiment and see if I like the default experience," the marketing would have needed to win me over enough to make the work of researching a good client appealing.

Googling "matrix client" leads you to the matrix website clients page rather than Element or the domain of the most popular client. I have to scroll downward before I even see Element. Element showing up after 2 "best 10 matrix apps" articles is an ecosystem failure and to me communicates immaturity.

When I see signs of immaturity, I immediately assume weak/untested security. I want to know other people are trusting something before I trust it. Signs of immaturity also make me cautious about making recommendations to someone else because I don't want to become someone else's tech support.

FWIW, if you google either e-mail or SMS, there are client(s) in the first 3 results for both.

Re: Twilio incident: What Signal users need to know

#435

I absolutely do not understand why I have to link my very sensitive Signal account to a very insecure and hard to change ID: my phone number (which can be traced to my identity in too many ways). Why Signal does not allow fully anonymous IDs (like Threema does) is a mystery to me. Signal is fine for most users, but it is inherently _unsafe_ for high-value sensitive communications where participants can expect targete…

You don't. Register with Signal using a temporary number.

Re: Twilio incident: What Signal users need to know

#436

Earlier quoted context omitted.

I know. I really wish they had a simple page that explains everything. They've gone to great lengths to be confusing about what they're collecting and how. There were several complaints about misleading communication when this change rolled out Examples: https://community.signalusers.org/t/dont-want-pin-dont-want-... https://old.reddit.com/r/signal/comments/htmzrr/psa_disablin... They've never updated their privacy p…

From your links, Moxie says > We're trying to add support for identifiers that aren't phone numbers, since that's what we've heard from users. If we do that, your signal contacts can't live in your address book anymore. Every other app just stores that in plaintext on their servers, which we don't want to do. I'm not a sec person, but isn't this along the lines of what I was getting to with my original post? Seems li…

I didn't have a problem with Signal wanting to provide a way to restore people's contacts. The problems I had initially were:

- No way to back up this information without cloud storage: why not let users backup their settings and contacts and profile to an encrypted file stored locally that can be copied to SD card, transferred via USB, or even uploaded wherever the user wants?

- No way to opt out entirely: What if I don't want this functionality at all and I don't care if my new phone doesn't have my settings and contacts and profile picture?

They've stated that they have plans to expand the data they're keeping in the cloud for other things down the road. It's not clear yet what they will do with it, but I get the impression that the reason they chose to start collecting user data was to enable them to grow into whatever they become.

There are lots of ways Signal could have improved their data collection and storage practices to better protect their users. Requiring strong passwords instead of pins would have been great! Not depending on the security of an enclave that has already been proven to be vulnerable to attacks would have been even better. Not storing user data at all would be ideal, but yeah, I get that they are within their rights to change the scope of their product to include data collection and cloud storage in order to offer new features.

My real issue with Signal is that this change was so poorly communicated that a lot of people (as evidenced by many in this discussion) aren't even aware that they are collecting data at all. All of the this confusion is entirely Signal's fault, and it'd be a bad look for any company, but this is a product where trust is critical. Where literal lives are on the line. Anyone using Signal deserves to know what their risks are, and Signal has worked to make that extremely difficult.

The fact that they are being deceptive, even after all this time, makes me think it's possible the service has been compromised and they are communicating to users to avoid using Signal as loudly as the law will allow. Not updating their privacy policy works wonderfully as a canary.

For what it's worth, I was a big fan of Signal. I loved the app. I recommended it to everyone! One of the most disappointing things about this entire fiasco is that there's no replacement I've seen that is as good! I've been playing around with a few alternatives, but Signal had the polish that made it ideal for both secured communications and plain old SMS/MMS. It's damaged goods now though. If I were fine with using an app I couldn't trust I might as well use whatever shipped with my phones.

Re: Twilio incident: What Signal users need to know

#437
post #331

Earlier quoted context omitted.

> It's really difficult to build a useable security product, and Signal has done it successfully. I'd argue it hasn't. Signal still has no way of backing up your chat history (with photos, etc). Lose your phone and it's all gone forever. The PIN that the app annoyingly tells you to set up does not serve as an encryption key for your backups. There are no backups. Once again, if your phone dies (this happened to me re…

> I consider this unacceptable. On the other hand, I consider this a feature. I'm not saying you are wrong, but I am saying different people have different ideas and requirements about how they want things like this to work. For me, most of my Signal chats have disappearing messages enabled, to intentionally ensure there is no long term archive of conversations (assuming you trust the other people to not be screensho…

> different people have different ideas and requirements about how they want things like this to work

Agreed. But I can't convince people and family to use Signal if I know that one day they will inevitably lose the pictures of their loved ones. Because that's how most people use communicator apps.

Re: Twilio incident: What Signal users need to know

#438
post #173
post #160

This is a weird thread. There's a product that does secure messaging with usernames and only requires user/pass. It's called Keybase. If this is the product you want, then go use it. I don't understand why everyone wants Signal to be something it's not. I quite like Signal as they are and this "incident" demonstrates exactly what happens if a carrier gets compromised: nothing. Nothing happens. Signal decides not to t…

where does Telegram fit in your opinion? genuine question from someone oblivious to messaging advances in the last decade.

Telegram is first and foremost a social network, and that type of service is incompatible with what we expect from a modern secure chats.

Re: Twilio incident: What Signal users need to know

#439
post #337

Earlier quoted context omitted.

Signal's SMS registration codes expire after a few minutes, so you wouldn't even need to know the duration of the incident. Let's be conservative and say the codes expire after 5 minutes (it's probably shorter), then Signal is registering 380 devices a minute.

380 devices / minute would imply Signal is adding 547,200 users / day, or 199,728,000 users / year. That seems way too high. Granted some could be multiple devices per user, but still...

It would also include re-registrations, fwiw.

Re: Twilio incident: What Signal users need to know

#440
post #419

Earlier quoted context omitted.

Link to the lines of code on the server that store the data in the way you describe or stop slinging mud. You linked to a repository that uses Intel SGX which is used in this instance specifically to address your false claim that the e2e encryption used is easily bruteforced. It also doesn't store any lists of who you contact; this claim is false. You've already been asked once for code references for your inaccurate…

All of your answers are in the links I provided, I'm more than happy to help, but please make an effort too. Here is the data that gets collected and stored in the cloud: https://github.com/signalapp/Signal-Android/blob/3553a28683d... > It also doesn't store any lists of who you contact; this claim is false. The entire point of Signal adding pins was to protect the data Signal now stores so that you can recover it. T…

I guess I'm just confused because I don't see how what you're linking answers my question. For example, the github link here shows mostly bool values and bytes. The strings I do see do include name, so I do get the argument that your name is stored (though you choose your name). But the code makes me think it is only storing a string to tell the program where your profile picture is. As I understand it, the server holds this information (encrypted) but still requires your phone to decrypt and even provide the source for things like the profile picture. This doesn't seem as bad as what you suggested previously.

As for SGX, my understanding is that 1) this exploit is pretty technical 2) it requires physical access and 3) that it is not the primary method of security, but a secondary one. If I understand this correctly I don't really see why this is an issue.

I'm not quite sure what I'm missing here, but I do appreciate your responses. I'm more than willing to admit that I just don't know/understand. I'm not sure where the breakdown in communication is happening (I'm not a security expert so it very well might be me).

Post reply on HN