This is a weird thread. There's a product that does secure messaging with usernames and only requires user/pass. It's called Keybase. If this is the product you want, then go use it. I don't understand why everyone wants Signal to be something it's not. I quite like Signal as they are and this "incident" demonstrates exactly what happens if a carrier gets compromised: nothing. Nothing happens. Signal decides not to t…
where does Telegram fit in your opinion? genuine question from someone oblivious to messaging advances in the last decade.
Twilio incident: What Signal users need to know
491–500 of 512 posts
Re: Twilio incident: What Signal users need to know
#492Is Signal a thing of the past yet? Do they still try to glue the word "security" and a phone number together? :-/
They recommend that users with higher-than-average security requirements set a PIN, which removes phone number attacks from the threat model, but you're still dependent on the security of SGX.
Users with extreme security requirements can set a 42 character alphanumeric PIN, thus also excluding SGX from the picture, but at that point you're getting owned no matter what you do.
Re: Twilio incident: What Signal users need to know
#493Earlier quoted context omitted.
How does signal allow you to learn someone's phone number from message history? As far as I understand the only thing one can learn by inspecting signal's protocol is that: 1. generally, a certain phone number uses signal (1) happens once, upon registration of your phone number. You don't see history of which phone numbers are communicating, do you? In other words, you don't need Signal to buy someone's location hist…
Sadly the protections you mention are only true if we ignore the last decade of security research and dragnet surveillance activity. Metadata protection in Signal has major asterisks they do not like to talk about which could be activated covertly by warrant, threats, or money. 1. Google, Apple, or Signal could, compile a malicious Signal binary that generates weak keys and deliver it to specific users, or all users,…
(1) is abstractly possible for any software and always has been. Signal cannot directly send my phone a bespoke binary... I got it through the app store. If that was allowed it would be Apple or Googles breach of the model, not Signal.
(2) there were SGX vulnerabilities, yes, but they've been patched and Signal is no longer vulnerable (in the one instance where they were), no?
(3) citation please, these are IP logs for conversations?
(4) this is not Signal's problem to solve. If you buy into what Signal offers, you're saying it's okay that my carrier knows that I registered with Signal because that's all they know. Being able to inspect IP headers for traffic on the internet is possible regardless of the software you're using. If you don't trust the internet with your communications then you need to take them off the internet... I don't know what else to say.
Further, typically companies can't be compelled to do something like (1) because it represents an undue burden on operation of their business. This is why Apple refused to give the FBI a bespoke build of iOS that bypassed the pin code. Not to mention the loss of business when people find out that a breach of trust had happened. Also I thought Signal had reproducible builds in every instance possible.
Idk, it sounds like you really shouldn't use any software you didn't write yourself and hardware you didn't build yourself and network where you don't trust every single node if your threat model involves IP logs and hardware tampering and targeted malicious software... that is hardly practical by any stretch of the imagination.
Re: Twilio incident: What Signal users need to know
#494Is Signal a thing of the past yet? Do they still try to glue the word "security" and a phone number together? :-/
A phone number is fine for 99% of users. They recommend that users with higher-than-average security requirements set a PIN, which removes phone number attacks from the threat model, but you're still dependent on the security of SGX. Users with extreme security requirements can set a 42 character alphanumeric PIN, thus also excluding SGX from the picture, but at that point you're getting owned no matter what you do.
Re: Twilio incident: What Signal users need to know
#495Earlier quoted context omitted.
I don't understand how that's moving the goal post. Urbit developed a novel way to phonetically encode larger amounts of entropy than people are used to dealing with in order to build a network where your cryptographic identifier is your namespace and prime identity. You can spin up an urbit ship/planet and securely message anybody on the network using that short identifier. You suggested just using part of somebody'…
I know nothing of Urbit. My point was just that there is a simple technical solution that Signal could apply if they wanted to make people happy who have no phone number and its moving the goal post to say 'use some other app'.
Put simply, telling Signal to add usernames is like telling the existing users to "use something else" because that's what Signal must turn itself into to satisfy the "I need usernames right now" crowd.
Re: Twilio incident: What Signal users need to know
#496Earlier quoted context omitted.
That comment wasn't directed at any single individual. There's just been a lot of "I imagine you can just type in a username and that would all work, QED. Duh." type of comments across the board, hence my broad statement. I agree Signal could add email addresses specifically, if verified and it wouldn't affect the threat model outside of introducing the network to more spam-able identifiers. Like I've said, if they f…
I've been reading up on the state of things. So Signal actually is working to remove the phone number requirement: https://twitter.com/moxie/status/1281353114063257600?s=20&t=... They've been working on it for years . Their solution is that they have to take client-side ownership of your contacts list, keep it associated with your "account" and sync it across your devices so that when you correspond with someone by u…
I don't understand why your takeaway from the fact that they're implementing it is that the people saying they want or need it are irrational and only exist on hn instead of "hmm, maybe I'm wrong and this is a legitimate feature request".
Anyways, let me assure you that the people who get "reamed" are in fact anyone who even causally mentions they want this feature who get a bunch of very dedicated people telling them how utterly wrong they are, no one should ever want that and anyways it's impossible actually.
Trust me.
Re: Twilio incident: What Signal users need to know
#497Earlier quoted context omitted.
> if I was a security researcher, journalist, abortion seeker or dissident, I wouldn't use Signal either. I mean that's really bad, right? Supposedly Signal is the go-to alternative to doing things the hard way (e.g. GPG over email), but apparently it's just not good enough for those with the highest security needs. Given that the alternative is that these people go back to using extremely brittle software, shouldn't…
>I mean that's really bad, right? Supposedly Signal is the go-to alternative to doing things the hard way (e.g. GPG over email), but apparently it's just not good enough for those with the highest security needs. Is it? If that's what you got from my comment, then I certainly didn't communicate my thoughts clearly. Signal is great for what it is. And that's as a centralized encrypted messaging platform that's easy to…
I agree. Signal absolutely should not abandon this. Rather, it should add other user identifiers that can be used alongside phone numbers.
> Storing anything on systems accessible to the Internet is risky. Plain text is much worse than encrypted blobs, but there's definitely still a non-zero risk. That alone makes it unsuitable for those whose life may depend on their ability to maintain secure communications.
I strongly disagree. A lot of critical work has been done with email + PGP, and that's about as leaky (in terms of metadata) as it gets. Obviously there are use cases where you do worry about this, but "storing data on the Internet" is not as such always a problem for those who need the highest security guarantees. Signal adopting alternative user identifiers would open it to use in some of these extreme cases, but would not (of course) make it usable in every situation - and that's okay.
Re: Twilio incident: What Signal users need to know
#498Earlier quoted context omitted.
> This info gives us an interesting opportunity to estimate the rate at which Signal is adding new users. They've been very tight-lipped (understandably) about their usage stats but anecdotally they seem to be an increasingly common presence on my friends' phones, even the non-techies. I am assuming US or Germany. I can't remember which thing it was exactly but there was a huge privacy scare in the US at some point w…
You might be in a different bubble than I am in :) Netherlands here. 80 contacts on my phone. 20 on Signal, of which 10 are quite normal people. Almost all 80 are on Whatsapp. No idea about Telegram.
Re: Twilio incident: What Signal users need to know
#499Re: Twilio incident: What Signal users need to know
#500Earlier quoted context omitted.
I know nothing of Urbit. My point was just that there is a simple technical solution that Signal could apply if they wanted to make people happy who have no phone number and its moving the goal post to say 'use some other app'.
Claiming that the solution is simple is the problem. Signal actually has been trying to add usernames for years. It involves an account, contacts book, trusting Signal, trusting Intel, SGX remote attestation, Raft, and passpins. They are getting reamed for it because it's not really possible to treat a 4 digit pin as a strong password but they're trying to do it anyway. It inverts the whole value prop of Signal on it…