Live data from Hacker News

Twilio incident: What Signal users need to know

support.signal.org

471–480 of 512 posts

Re: Twilio incident: What Signal users need to know

#471
post #254

Earlier quoted context omitted.

This doesn't make any sense. My assertion is that Signal would not be Signal if it has usernames. The subtext that I did not state specifically is exactly the question of why more people don't use Keybase regularly. Maybe it's not the winning UX? You don't get to look over at Signal and say "wow what a great user base I need to be a part of that" and then draw the conclusion that "Signal needs to support my idealogic…

fwiw I am a user of signal and I am expressing my need. Allowing it access to my contact list and my phone number is a privilege I extend nearly uniquely to it among similar apps and I want that gone. Because I can't just "not use signal," because signal is where the people I need to talk to are. Users are a key feature of any social product, you can't just "all else equal" them away. It's not really my problem if it…

I use signal/whatsapp etc without giving them access to my contacts. I have to type in the phone number (only first time) with whom I want to chat. And that's okay.

Re: Twilio incident: What Signal users need to know

#472
post #331
post #160

This is a weird thread. There's a product that does secure messaging with usernames and only requires user/pass. It's called Keybase. If this is the product you want, then go use it. I don't understand why everyone wants Signal to be something it's not. I quite like Signal as they are and this "incident" demonstrates exactly what happens if a carrier gets compromised: nothing. Nothing happens. Signal decides not to t…

> It's really difficult to build a useable security product, and Signal has done it successfully. I'd argue it hasn't. Signal still has no way of backing up your chat history (with photos, etc). Lose your phone and it's all gone forever. The PIN that the app annoyingly tells you to set up does not serve as an encryption key for your backups. There are no backups. Once again, if your phone dies (this happened to me re…

"Data in Signal" isn't a thing.

Save messages and media you want to keep outside of your encrypted chats...

Re: Twilio incident: What Signal users need to know

#473
post #214
post #160

This is a weird thread. There's a product that does secure messaging with usernames and only requires user/pass. It's called Keybase. If this is the product you want, then go use it. I don't understand why everyone wants Signal to be something it's not. I quite like Signal as they are and this "incident" demonstrates exactly what happens if a carrier gets compromised: nothing. Nothing happens. Signal decides not to t…

Matrix is the protocol I think one should go to if Signal's requirement of phone numbers is a turn down.

If the phone number requirement is the only part you dislike, buy a tourist Sim card with cash. The greatest lie of online identity is that phone numbers are tied to individuals forever.

Re: Twilio incident: What Signal users need to know

#474
post #437

Earlier quoted context omitted.

> I consider this unacceptable. On the other hand, I consider this a feature. I'm not saying you are wrong, but I am saying different people have different ideas and requirements about how they want things like this to work. For me, most of my Signal chats have disappearing messages enabled, to intentionally ensure there is no long term archive of conversations (assuming you trust the other people to not be screensho…

> different people have different ideas and requirements about how they want things like this to work Agreed. But I can't convince people and family to use Signal if I know that one day they will inevitably lose the pictures of their loved ones. Because that's how most people use communicator apps.

Let me show you this picture of my grandson....

opens Signal, scrolls for weeks

You could show them where the Save button is — that's how "most" people use messaging apps. Even "friends and family".

Re: Twilio incident: What Signal users need to know

#475
post #427

Earlier quoted context omitted.

All of your answers are in the links I provided, I'm more than happy to help, but please make an effort too. Here is the data that gets collected and stored in the cloud: https://github.com/signalapp/Signal-Android/blob/3553a28683d... > It also doesn't store any lists of who you contact; this claim is false. The entire point of Signal adding pins was to protect the data Signal now stores so that you can recover it. T…

The protobuf you linked does not support your claim that Signal uploads your contact lists. You'll note that AccountRecord does not contain a list of ContactRecords other than those pinned (4 max). Indeed the application UX does not either. I've asked for evidence twice and you have supplied none.

protobuf files just contain data structure definitions. StorageService.proto contains only one reference to StorageRecord, but Signal actually syncs hundreds of StorageRecords.

Instead of linking to source code examples, which is easily misunderstood, here is Matthew Green's summary:

https://blog.cryptographyengineering.com/2020/07/10/a-few-th...

Alternatively, you can just open the app settings, which tells you that it will attempt to restore your contacts if you create a PIN:

> PINs keep information stored with Signal encrypted so only you can access it. Your profile, settings, and contacts will restore when you reinstall. You won’t need your PIN to open the app

Re: Twilio incident: What Signal users need to know

#476

Earlier quoted context omitted.

All of your answers are in the links I provided, I'm more than happy to help, but please make an effort too. Here is the data that gets collected and stored in the cloud: https://github.com/signalapp/Signal-Android/blob/3553a28683d... > It also doesn't store any lists of who you contact; this claim is false. The entire point of Signal adding pins was to protect the data Signal now stores so that you can recover it. T…

I guess I'm just confused because I don't see how what you're linking answers my question. For example, the github link here shows mostly bool values and bytes. The strings I do see do include name, so I do get the argument that your name is stored (though you choose your name). But the code makes me think it is only storing a string to tell the program where your profile picture is. As I understand it, the server ho…

This is the line which remotely stores your contacts encrypted E.164-formatted phone numbers:

https://github.com/signalapp/Signal-Android/blob/main/app/sr...

Re: Twilio incident: What Signal users need to know

#477
post #473
post #214

Earlier quoted context omitted.

Matrix is the protocol I think one should go to if Signal's requirement of phone numbers is a turn down.

If the phone number requirement is the only part you dislike, buy a tourist Sim card with cash. The greatest lie of online identity is that phone numbers are tied to individuals forever.

That's a lot of work considering XMPP or Matrix providers get this right.

Re: Twilio incident: What Signal users need to know

#478
post #407

Earlier quoted context omitted.

You sound like people defending PGP when everyone knew there were major downsides and usability issues. How can keeping phone numbers as the only option be more important than everyone being able to publish "Signal:39475638" on someplace like GitHub? Is the phone numbers part of the encryption somehow and you absolutely can't use some other number even in addition to it? Because I refuse to believe you don't understa…

And yet, there is no PGP replacement in existence despite it having died a thousand deaths and having promised replacements for decades. > So surely then there has to be some technical limitation because what other legitimate reason is there? It's like people aren't reading the whole thread and just responding to specific comments they don't like. The premise of Signal, or at least what's made it practically useable,…

None of these are a reason to not to also have a different number that you can publish publicly without giving someone your phone number. You can have your phone number for everyone in your phone book and a one way derived or random number for everyone else.

> When I first reach out to someone on Signal I know the person I'm reaching out to is the owner of the identifier I used unless their phone carrier is actively compromised when I exchange the first message.

Compromising is in this case rather common in sim swapping and spoofing (you can barely even call it spoofing). Phone numbers are not useful as some sort of continued point of trust. And I doubt Signal uses it like that under the hood.

> What more do people want?

Before you complain about other people maybe you should give other people the courtesy of reading what they wrote first. I have already said what I want, a public id I can publish on for example GitHub without the implications of publishing a phone number. Implications which anyone with a relevant opinion should already understand.

Re: Twilio incident: What Signal users need to know

#479
post #331
post #160

This is a weird thread. There's a product that does secure messaging with usernames and only requires user/pass. It's called Keybase. If this is the product you want, then go use it. I don't understand why everyone wants Signal to be something it's not. I quite like Signal as they are and this "incident" demonstrates exactly what happens if a carrier gets compromised: nothing. Nothing happens. Signal decides not to t…

> It's really difficult to build a useable security product, and Signal has done it successfully. I'd argue it hasn't. Signal still has no way of backing up your chat history (with photos, etc). Lose your phone and it's all gone forever. The PIN that the app annoyingly tells you to set up does not serve as an encryption key for your backups. There are no backups. Once again, if your phone dies (this happened to me re…

Run the desktop client on a Pi in a VNC session at home and automatically receive the identical messages - no problem!

Not a proper solution but a hacky workaround possibility.

Re: Twilio incident: What Signal users need to know

#480
post #429

Earlier quoted context omitted.

Yeah but the whole point of Signal is to allow secure very secure communication. With little effort they could allow this usecase. It would address a major criticism and they already have the underlying infrastructure. But I guess you can just keep moving the goal post.

I don't understand how that's moving the goal post. Urbit developed a novel way to phonetically encode larger amounts of entropy than people are used to dealing with in order to build a network where your cryptographic identifier is your namespace and prime identity. You can spin up an urbit ship/planet and securely message anybody on the network using that short identifier. You suggested just using part of somebody'…

I know nothing of Urbit.

My point was just that there is a simple technical solution that Signal could apply if they wanted to make people happy who have no phone number and its moving the goal post to say 'use some other app'.

Post reply on HN