Live data from Hacker News

Twilio incident: What Signal users need to know

support.signal.org

481–490 of 512 posts

Re: Twilio incident: What Signal users need to know

#481
post #68

Earlier quoted context omitted.

The Signal desktop app doesn't require your phone to be turned on (once it's been "paired") by the way, as opposed to for example Whatsapp.

Well sure, but does it require me to use my phone at some point in the process of account creation? That's the part I have an issue with. I had assumed that there would be an alternative to access the service post-creation. My gripe is more with the fact that a phone is a requirement at any point. To put it another way: imagine I had to send a letter to Signal's HQ in order to make an account. Now, obviously I'm not…

Yeah agreed, as I mentioned elsewhere I don't see why phone number should be required. It's a good default (esp. for non-technical users) to use phone number and contacts (= "social network"), but I really don't see what the problem is with using email or just username/password combo and then adding contacts manually from wherever. Why not have that option? Most people would likely still use their phone number for this.

Re: Twilio incident: What Signal users need to know

#482
post #453
post #425

Earlier quoted context omitted.

That comment wasn't directed at any single individual. There's just been a lot of "I imagine you can just type in a username and that would all work, QED. Duh." type of comments across the board, hence my broad statement. I agree Signal could add email addresses specifically, if verified and it wouldn't affect the threat model outside of introducing the network to more spam-able identifiers. Like I've said, if they f…

I've been reading up on the state of things. So Signal actually is working to remove the phone number requirement: https://twitter.com/moxie/status/1281353114063257600?s=20&t=... They've been working on it for years . Their solution is that they have to take client-side ownership of your contacts list, keep it associated with your "account" and sync it across your devices so that when you correspond with someone by u…

> Just tell your users if they want a username they need a strong password.

If their goal is to shift responsbility to the user, that solution works. If their goal is to provide secure communications to the general public, that solution doesn't work. As you probably know, strong passwords are widely recognized as a failed security technology for the general public.

Also, what happens when the user forgets their strong password? Dataloss is not an acceptable outcome for general end users whose priority usually is not ultimate security, but usability. Thus (as I understand it) Signal allows weak passwords ('PINs') that stay with the client, and adds 'invisible' entropy which is backed up to server-side SGX (because the user doesn't know the entropy, it must be backed up off-phone in case the phone is lost). It's a great, no-tradeoff solution IMHO: If SGX is compromised, the user is no worse off than if the supplemental entropy didn't exist at all - they have their (weak) password. If you don't want to depend on the 'supplemental entropy', use a strong password and then Signal's entropy and SGX security become irrelevant.

> Or just generate the entropy for them and only allow the username option to people who also want to take custody of their new 32-bytes of entropy and have a signal-managed synced contact book.

AFAICT, Signal is not interested in implementing features that are valuable only to geeks and that everyone else ignores, and those kinds of features don't seem to fit their mission.

Re: Twilio incident: What Signal users need to know

#483
post #71

This info gives us an interesting opportunity to estimate the rate at which Signal is adding new users. They've been very tight-lipped (understandably) about their usage stats but anecdotally they seem to be an increasingly common presence on my friends' phones, even the non-techies. As far as I can tell, Signal uses Twilio only to send SMS for phone number verification. Verification happens when a user registers a n…

> Verification happens when a user registers a new number or changes the number on their existing account. Doesn't verification also occur when you re-install the app? Between that and how hard Signal makes device device upgrade transfers I wouldn't be surprised if most messages were for existing users.

My wife and me recently bought new phones and had no trouble transferring Signal whatsoever.

Re: Twilio incident: What Signal users need to know

#484
post #153

Earlier quoted context omitted.

I don't think this is true, do you have a source? They store registered users phone numbers and allow discovery by making a request with a hashed version of the phone numbers on your contact list. They add an extra layer to allow attestation of the software doing this using Intel's secure enclave. They give many examples of responding to warrants with only whether the number has been registered and the timestamp of r…

Your 2017 blog post is outdated. See: https://community.signalusers.org/t/can-signal-please-update... and https://community.signalusers.org/t/dont-want-pin-dont-want-... See here for a discussion on how Intel's 'secure' enclave won't save you: https://community.signalusers.org/t/proper-secure-value-secu...

I just wanted to thank you for the information and the ensuing thread. Very interesting.

Re: Twilio incident: What Signal users need to know

#485
post #453

Earlier quoted context omitted.

I've been reading up on the state of things. So Signal actually is working to remove the phone number requirement: https://twitter.com/moxie/status/1281353114063257600?s=20&t=... They've been working on it for years . Their solution is that they have to take client-side ownership of your contacts list, keep it associated with your "account" and sync it across your devices so that when you correspond with someone by u…

> Just tell your users if they want a username they need a strong password. If their goal is to shift responsbility to the user, that solution works. If their goal is to provide secure communications to the general public, that solution doesn't work. As you probably know, strong passwords are widely recognized as a failed security technology for the general public. Also, what happens when the user forgets their stron…

I agree almost completely. It's just that my guess is that nobody actually cares about usernames either, just the few people who can't use a phone for . So I'm thinking they're already kinda in the realm of building out this feature for nobody which is why I was suggesting something more wallet-like like generating 32bytes of entropy and showing users the mnemonic representation and telling them not to lose it (which is familiar, despite being a terrible UX, at least). Perhaps I'm underestimating how many people actually would use a username instead of their phone number in which case I think your 100% spot on.

Re: Twilio incident: What Signal users need to know

#486
post #407

Earlier quoted context omitted.

And yet, there is no PGP replacement in existence despite it having died a thousand deaths and having promised replacements for decades. > So surely then there has to be some technical limitation because what other legitimate reason is there? It's like people aren't reading the whole thread and just responding to specific comments they don't like. The premise of Signal, or at least what's made it practically useable,…

None of these are a reason to not to also have a different number that you can publish publicly without giving someone your phone number. You can have your phone number for everyone in your phone book and a one way derived or random number for everyone else. > When I first reach out to someone on Signal I know the person I'm reaching out to is the owner of the identifier I used unless their phone carrier is actively…

I think you're being hyperbolic about how weak phone numbers are. Yes, you can get sim swapped. But you pretty much know immediately since your phone stops working. We've never even heard of an attack where someone was swapped for days, weeks, or months and didn't know about it. It's an active attack and while it's possible and yes future messages with Signal users are vulnerable while it's happening, it's not a persistent threat. And your contacts will see your safety numbers change and reach out and make sure you're really you. That leaves a problem of somebody reaching out for the first time to contact you while you're actively being simjacked as the only real damage.

But, none of this even matters if you turn on registration lock. Sim swapping attack thwarted.

I've read your request worded in different ways many times and what people keep doing is pointing a finger at phone numbers, yelling "they're insecure", and then pointing at usernames and saying "look, it can be better". Nobody has actually argued how it could be better, just that phones suck. I don't find that a compelling argument, sorry.

Usernames/email are no less susceptible to whatever service you use to register them getting jacked. There is literally zero security difference and emails are easier to spam. Usernames just don't have KYC baggage that phones do in the US. But honestly as Signal has shown time and time again, all that law enforcement can get from Signal is that a given phone number registered with Signal. Because they have impeccable application layer crypto which is what actually matters.

Okay so what if Signal uses a username/password DB and doesn't allow email reset. That removes the 3rd party from the equation and now Signal takes the burden of being the central authority for usernames. And, while possible, it entirely inverts the whole premise of Signal in the first place.

Good news for you, that's not just my argument, it's actually happening. Signal is trying to add support for usernames by forcing everyone to add a pin. It's not clear at all that this pin is now the password to a signal account that is used to sync your contacts data and profile. That's not a problem in and of itself because it's all theoretically good crypto. The problem is that it isn't good crypto. It's a 4 digit pin for the majority of users. Signal knows this is in a bind trying to slip things in that they know would piss off half their users because it's shit security just in order to make usernames possible. And they're getting called out for it.

aside: It's not passwords per-say that are bad (even though they are because people and UX). It's that Signal is telling everyone "hey add this quick pin" and people don't realize that's actually a password for your whole account and that the whole model is changing underneath them. If you know and set a strong passpin, you're fine.

Anyway, the catcher is this: instead of having to deal with what it means to have passwords and get users up to speed, they developed some technically really cool but batshit insane system to throttle pin attempts so that the burden of trust gets moved from your carrier to Intel and they can wash their hands of how insanely bad a 4 digit pin is in terms of entropy. So you want usernames because you don't trust your carrier? Did you know that would come at the cost of trusting Intel instead? They don't really have a great track record recently...

My entire point is not that people are stupid for asking for usernames or something. It's that they don't come "for free" as everyone seems to think. If you want traditional username/password, then the world changes so that Signal becomes a cloud service you must trust to maintain a new global contacts book of usernames just for use on Signal. Signal didn't like that and that's definitely a problem for all the people who use Signal because they don't have their fingers in that cookie jar. So they punted and are moving the trust point to Intel.

They've been working on this for years.

Re: Twilio incident: What Signal users need to know

#487

Earlier quoted context omitted.

And if Element is not the desired application to use matrix, then there are plenty of others, and available across many device and OS platforms: https://matrix.org/clients/ ...Of course, Element remains the oldest and likely still most feature-full app.

I haven't really looked into Matrix. I appreciate the nudge!

Beyond any research that you undertakevaround matrix, i would add: while its not new (having existed for several years now), its popularity has increased quite a bit in the last year or 2. So in my opinion its still early days. Althougj its evolved quite nicely. So some rough edges might be encountered - more so on the client/apps side, less on protocol side - but as the superfan that i am, i really feel it represents the future of distributed messaging, which one use-case is chat. Good luck!

Re: Twilio incident: What Signal users need to know

#488
post #390

Earlier quoted context omitted.

You’re angrily lashing out at strawmen to justify why the lookup key is constrained to a phone number. That does not need to be bound to a phone number, it could be an identifier someone just types in. What you’re arguing for is the recovery mechanism to get back online when you lose your private key, which is totally unrelated and could be solved independently for people who choose to give a phone number vs those us…

1. I'm not angry at all. 2. Let me make this clear: an imperative component of signal's product is that the identifier used is verifiable , and that the only thing they store for a period of time is that users in-fact did verify their number. Everyone arguing for typed in identifiers is missing this point. That wouldn't be Signal. That's the core of what I'm saying. That would be something else where people claim sho…

Following up on:

> Nobody arguing for non-phone-number short identifiers has proposed a solution for how you verify them and manage them that doesn't change Signal's fundamental threat model and information architecture, which, at the end of the day, is what many users are bought into.

So it turns out Signal is building support for usernames and their solution is indeed rather involved. In order to achieve usernames they've:

1. added a contacts book and profile

2. added a passpin by introducing Intel as a trusted actor. the pin you enter when using signal is actually your Signal account password

3. presumably adding support for usernames and username-based verification

They've been working on this for years. They're not just sitting on their hands. So my point seems to stand: it's not just "add a username field and let people type shit in we have input fields amirite". It's a massive overhaul of their fundamental architecture. And sadly it's not happening very publicly because the stuff they're doing to make it happen is also not okay according to the other half of the security community. Carriers? Not okay? Well how about usernames? Oh, you're using 4 digit pins as passwords and SGX to throttle login attempts? Well that's not okay either SGX has been pwned a billion times. Lose/lose for Signal. I pity them, honestly. It sucks.

I'm not personally enraged or anything. I think the SGX stuff is actually a pretty cool compromise. But, alas, it's still a compromise in order to make usernames equally feasible as phone numbers. Either way you're compromising. And that's what this thread is about: to make security accessible you can't live in an ivory tower and demand perfection. You have to get down in the field and make compromises in order to build a successful product that people will actually use.

Re: Twilio incident: What Signal users need to know

#489

Earlier quoted context omitted.

Hmm, I'm looking for a Keybase replacement but one of the main reasons I use Keybase is their native apps that let you mount the cloud storage as a FUSE or FUSE-like (Dokan) native storage device. This is great for distributing encrypted keychains/configuration files and the such across various platforms (where many apps are not cloud-aware but are happy interacting with the filesystem). So far the "mount" approach s…

We have a FUSE mount and CLI. For details see: https://github.com/peergos/peergos#fuse-native-folder-mounti...

Ooh, good to know. This should really be advertised a bit more in the website... I want straight to the website and it doesn't mention local mounting in the features at all and no screenshots show anything about local mounts either...
Post reply on HN