Signal says attackers accessed the phone numbers and SMS verification codes for around 1,900 users as part of the recent Twilio breach
just reasons I don't understand. Can somebody explain those reasons to me? https://twitter.com/... Joseph Menn / @josephmenn : Every time there is a high-end attack on a critical end-to-end encrypted app that fails to obtain content, I am reminded how many even Western officials want to stop end-to-end encryption, which is close to the only thing in tech security that actually works. https://twitter.com/... Jenn / @jennschiffer : between digital ocean emailing yesterday about impact from a mailchimp hack, the heroku disaster, and now this - it's truly the year of learning the ingredients in the platforms we consume 😅🤘 https://twitter.com/... @freedomofpress : A recent breach of Twilio could have allowed attackers to take over users' accounts by registering their Signal number on a new device. This is why we recommend journalists enable “Registration Lock” on Signal. Here's how: https://freedom.press/... https://twitter.com/... Dino A. Dai Zovi / @dinodaizovi : It's a testament to Signal's design that a Twilio breach only allows an attacker to assume a target account's phone number (which also notifies all conversations of their new safety number) and doesn't compromise *any* data. Good proactive security designs prepare for breaches. https://twitter.com/... @signalapp : We have identified and are contacting the 1,900 potentially affected users. We are prompting them to re-register their Signal numbers and encouraging them to enable registration lock. We are also working with Twilio to ensure they upgrade their security practices. 3/ @nohackme : i ❤️ that @signalapp considered this very attack in their threat modeling, and developed a mitigation. settings>account>registration lock https://twitter.com/... Alex Radocea / @defendtheworld : I feel like signal continues to underplay how terrible of an idea phone-number based identity is despite being convenient for adoption. Twilio's customer support isn't the weakest point for SMS... it's the global telephony system itself. https://support.signal.org/... @combat_boot : Oopsie. Especially as certain organisation was touting app as most secure thing ever. Nothing is 100% & leading ppl to believe that it is, encourages risky behaviour. Trivial number of users involved but some targeted. Should serve as warning ref trust https://www.bleepingcomputer.com/ ... https://twitter.com/... J. A. Guerrero-Saade / @juanandres_gs : Honestly, let's take a minute to appreciate that @signalapp was built to guard precisely against this sort of attack. Reward and applaud well thought out security engineering in action! (h/t @dinodaizovi for the perspective) https://twitter.com/... Amanda Silberling / @asilbwrites : If you're a journalist using Signal to talk to sources, go to settings —> account and change your pin + turn on registration lock https://twitter.com/... Carly Page / @carlypage_ : so it looks like one of those 125 customers was... Signal 😳 https://techcrunch.com/... @briankrebs : Learned something new about Signal from their rundown of how some users were affected by the Twilio phishing incident: “Registration lock,” which requires your Signal PIN to register your phone number again with Signal https://support.signal.org/... Kevin Collier / @kevincollier : Last week Twilio said 125 customers had been affected in its recent breach. Looks like “customers” meant individual orgs, and Signal was one of those. How many others do we know about? (And if you know of any that aren't public, please reach out) https://support.signal.org/...
Recently @twilio, which provides SMS verification services for Signal, suffered a phishing attack. Via Twilio, attackers may have accessed phone numbers & SMS registration codes for 1,900 Signal users. 1/
Message history, profile info, contact lists, & other data were NOT & could not be accessed. The information attackers accessed could allow them to attempt to register a Signal user's phone number on a new device if that user had not enabled registration lock. 2/
Signal still depends on valid phone numbers and I still don't understand why. I think it's absurd, yet I respect them and thus believe they have solid reasons — just reasons I don't understand. Can somebody explain those reasons to me? https://twitter.com/...
Every time there is a high-end attack on a critical end-to-end encrypted app that fails to obtain content, I am reminded how many even Western officials want to stop end-to-end encryption, which is close to the only thing in tech security that actually works. https://twitter.com/…
between digital ocean emailing yesterday about impact from a mailchimp hack, the heroku disaster, and now this - it's truly the year of learning the ingredients in the platforms we consume 😅🤘 https://twitter.com/...
A recent breach of Twilio could have allowed attackers to take over users' accounts by registering their Signal number on a new device. This is why we recommend journalists enable “Registration Lock” on Signal. Here's how: https://freedom.press/... https://twitter.com/...
It's a testament to Signal's design that a Twilio breach only allows an attacker to assume a target account's phone number (which also notifies all conversations of their new safety number) and doesn't compromise *any* data. Good proactive security designs prepare for breaches. h…
We have identified and are contacting the 1,900 potentially affected users. We are prompting them to re-register their Signal numbers and encouraging them to enable registration lock. We are also working with Twilio to ensure they upgrade their security practices. 3/
i ❤️ that @signalapp considered this very attack in their threat modeling, and developed a mitigation. settings>account>registration lock https://twitter.com/...
I feel like signal continues to underplay how terrible of an idea phone-number based identity is despite being convenient for adoption. Twilio's customer support isn't the weakest point for SMS... it's the global telephony system itself. https://support.signal.org/...
Oopsie. Especially as certain organisation was touting app as most secure thing ever. Nothing is 100% & leading ppl to believe that it is, encourages risky behaviour. Trivial number of users involved but some targeted. Should serve as warning ref trust https://www.bleepingcompute…
Honestly, let's take a minute to appreciate that @signalapp was built to guard precisely against this sort of attack. Reward and applaud well thought out security engineering in action! (h/t @dinodaizovi for the perspective) https://twitter.com/...
If you're a journalist using Signal to talk to sources, go to settings —> account and change your pin + turn on registration lock https://twitter.com/...
Learned something new about Signal from their rundown of how some users were affected by the Twilio phishing incident: “Registration lock,” which requires your Signal PIN to register your phone number again with Signal https://support.signal.org/...
Last week Twilio said 125 customers had been affected in its recent breach. Looks like “customers” meant individual orgs, and Signal was one of those. How many others do we know about? (And if you know of any that aren't public, please reach out) https://support.signal.org/...