Live data from Hacker News

Twilio incident: What Signal users need to know

support.signal.org

461–470 of 512 posts

Re: Twilio incident: What Signal users need to know

#461

Earlier quoted context omitted.

FWIW, everybody has different results on Google. They vary between mobile and desktop, regionally, and can even be personalized.

Are you saying your results are different?

Yes. They can and will vary significantly. I'm in the UK FWIW.

Re: Twilio incident: What Signal users need to know

#462
post #160

This is a weird thread. There's a product that does secure messaging with usernames and only requires user/pass. It's called Keybase. If this is the product you want, then go use it. I don't understand why everyone wants Signal to be something it's not. I quite like Signal as they are and this "incident" demonstrates exactly what happens if a carrier gets compromised: nothing. Nothing happens. Signal decides not to t…

There is also Session (getsession.org) which is a fork of Signal without phone numbers or centralization.

Re: Twilio incident: What Signal users need to know

#463
post #337

Earlier quoted context omitted.

380 devices / minute would imply Signal is adding 547,200 users / day, or 199,728,000 users / year. That seems way too high. Granted some could be multiple devices per user, but still...

200M users/yr does not sound unrealistic to me given the network effects of Signal. I'm certainly not suggesting that's the actual rate - but I'd be willing to believe it's within an order of magnitude. Here's an article from last year mentioning 50M+ downloads in 10 days. https://webcache.googleusercontent.com/search?q=cache:hsVnnQ...

> Here's an article from last year mentioning 50M+ downloads in 10 days.

That was a period in which WhatsApp had just announced their new ToS, indicating that the data about their users was to be merged with Facebook's. Consequently, many users became aware of the enormous privacy issues with all Facebook/Meta products, and abandoned WhatsApp for other services, mostly Signal and Telegram.

I doubt that this period can be used to interpolate the Signal growth for the rest of the year, although the network effect has probably resulted in a much higher growth rate than before the WhatsApp exodus.

Edit: a Tweet from Elon Musk ("use Signal") most probably contributed a lot to that raise in awareness, and the one-time surge of increased growth for Signal.

Re: Twilio incident: What Signal users need to know

#464

I absolutely do not understand why I have to link my very sensitive Signal account to a very insecure and hard to change ID: my phone number (which can be traced to my identity in too many ways). Why Signal does not allow fully anonymous IDs (like Threema does) is a mystery to me. Signal is fine for most users, but it is inherently _unsafe_ for high-value sensitive communications where participants can expect targete…

You don't. Register with Signal using a temporary number.

I cannot do it in my country without physically going to some office and showing my passport. Doesn’t feel “temporary” to me.

SIM cloning is a thing. S7 hacking is a thing. Phone numbers are _insecure_ as IDs, as simple as that. Signal’s insistence to use nothing but phone numbers is somewhat suspicious these days.

(Both major competitors in secure messaging, Wire and Theeema, allow pseudonymous temporary IDs in addition to phone numbers).

Re: Twilio incident: What Signal users need to know

#465
post #160

This is a weird thread. There's a product that does secure messaging with usernames and only requires user/pass. It's called Keybase. If this is the product you want, then go use it. I don't understand why everyone wants Signal to be something it's not. I quite like Signal as they are and this "incident" demonstrates exactly what happens if a carrier gets compromised: nothing. Nothing happens. Signal decides not to t…

I don't think it's stated enough just how easy signal is as a drop in replacement for WhatsApp, the main communication method for a significant portion of the world. The ability to install a new app, use your phones contact database, and be able to use the app nearly exactly the same way you used WhatsApp is an incredible feature. With almost zero effort you can significantly reduce (capitalist or nationstate) survei…

No post body was provided.

Re: Twilio incident: What Signal users need to know

#466
post #462
post #160

This is a weird thread. There's a product that does secure messaging with usernames and only requires user/pass. It's called Keybase. If this is the product you want, then go use it. I don't understand why everyone wants Signal to be something it's not. I quite like Signal as they are and this "incident" demonstrates exactly what happens if a carrier gets compromised: nothing. Nothing happens. Signal decides not to t…

There is also Session (getsession.org) which is a fork of Signal without phone numbers or centralization.

Too bad it is owned by a crypto company, Loki.

Re: Twilio incident: What Signal users need to know

#467
post #230

Earlier quoted context omitted.

> Even if countries do allow private gun ownership, the restrictions on how to obtain them (and what they can legally be used for, what kinds are available, etc.) are exceptionally onerous Citation needed. I, and probably the majority of the citizens of those countries do not consider the standard test/psych eval/background check/random checks in the future to make sure you're following the rules to be "exceptionally…

>Citation needed. I, and probably the majority of the citizens of those countries do not consider the standard test/psych eval/background check/random checks in the future to make sure you're following the rules to be "exceptionally onerous". Just because you've accepted the boot on your neck doesn't make it not a boot. When (not if) a currently free and democratic Western nation decides to be not so democratic anymo…

> want mail order rocket launchers delivered to my doorstep." The state should fear its people, not the other way around, and the best way to ensure that is to give the people the means to put a bullet (or several) into any would-be tyrants.

You should look into France and it's protest culture. When the people are unhappy with the government's action, they go out on the street and protest. Without any weapons, this being a civilized country where violence is only a last resort. And you know what? Governments listen and adapt, even without the fear of direct death.

So i find your premise wrong to begin with. There is no natural right to murder, so i disagree that owning a weapon is a natural right.

And i find it extremely funny that the country that is so proud in their "everyone should be armed so the government is afraid of the people" culture has such shitty dysfunctional governments that act against the people's interests extremely often. Where are the armed uprisings against the Patriot act, civil asset forfeiture, racist abuse, abortion restrictions, failures to combat climate change or wasting money in useless wars abroad? No? When then?

Re: Twilio incident: What Signal users need to know

#468

Earlier quoted context omitted.

This is as daft as Googling "email" and expecting a de facto client. You're on HN, it's nerdville, expect more interest in the protocol than clients. People search for "email clients. Try searching for "Matrix clients". Element is the best thus far, IMO. "Widespread adoption" includes the EU's military, healthcare and government, so I wouldn't be so certain you'll end up being right. It's hit 60m publicly addressable…

I think we meant different things when we said "drop in replacement" and therefore were referencing different ideas of what makes something a "drop in replacement," which is why it sounds like there are feelings of goal posts shifting. If the messages are still sent via Facebook servers, that is not a WhatsApp replacement, it's an alternative WhatsApp Client, it's still at it's core "performing" WhatsApp. It is not a…

The flaw in your reasoning is that Matrix is like the web, and Element is like a browser. Just as mainstream folks don’t say “go look at my Chrome site”, but are smart enough to say “go look at my website with your web browser”, the same goes for Matrix too.

The only reason this doesn’t happen yet is that Matrix clients like Element are still too geeky, and joe public doesn’t care about the advantages of open decentralised e2ee comms. Our plan to fix that is to transform Element’s UX; hide the decentralisation complexities, and let it punch its own weight againdt the centralised alternatives - https://matrix.org/blog/2022/08/15/the-matrix-summer-special... has more details.

The user would still need to understand it’s talking on an open network though, because that’s what it is. But they don’t need to care that much about it.

Re: Twilio incident: What Signal users need to know

#469
post #291

Earlier quoted context omitted.

> You should assume every bit of information sent on the internet is archived in a massive warehouse somewhere, because it is. Leaving aside the whataboutism here, you shouldn't assume that when you're using a secure messaging app that claims to be designed to never collect or store user data. Signal makes that claim at the start of their privacy policy and it is a lie. It started out true, but they begain colleting…

Signal can't possibly read the data . How is that for itself? Only you can decrypt it! Signal doesn't have your data. They have garbage bits of effectively random noise. You can prove it to yourself. Go take one of Signal's servers and try to find someone else's data there. You won't. Why would Signal update their privacy policy to reflect the desire of misguided fear mongers? I certainly wouldn't do that if I were t…

[deleted]

Re: Twilio incident: What Signal users need to know

#470

Using phone numbers as an identifier is terrible, use session! https://getsession.org/ Your private key that is used to encrypt the messages and the public key is your identifier

It's ridiculous this is down voted. Client is a fork of Signal on all platforms. The fix is made, use it.

Arguments are usually just "ad hominem" against blockchain.

Post reply on HN