/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Signal says attackers accessed the phone numbers and SMS verification codes for around 1,900 users as part of the recent Twilio breach

just reasons I don't understand. Can somebody explain those reasons to me? https://twitter.com/... Joseph Menn / @josephmenn : Every time there is a high-end attack on a critical end-to-end encrypted app that fails to obtain content, I am reminded how many even Western officials want to stop end-to-end encryption, which is close to the only thing in tech security that actually works. https://twitter.com/... Jenn / @jennschiffer : between digital ocean emailing yesterday about impact from a mailchimp hack, the heroku disaster, and now this - it's truly the year of learning the ingredients in the platforms we consume 😅🤘 https://twitter.com/... @freedomofpress : A recent breach of Twilio could have allowed attackers to take over users' accounts by registering their Signal number on a new device. This is why we recommend journalists enable “Registration Lock” on Signal. Here's how: https://freedom.press/... https://twitter.com/... Dino A. Dai Zovi / @dinodaizovi : It's a testament to Signal's design that a Twilio breach only allows an attacker to assume a target account's phone number (which also notifies all conversations of their new safety number) and doesn't compromise *any* data. Good proactive security designs prepare for breaches. https://twitter.com/... @signalapp : We have identified and are contacting the 1,900 potentially affected users. We are prompting them to re-register their Signal numbers and encouraging them to enable registration lock. We are also working with Twilio to ensure they upgrade their security practices. 3/ @nohackme : i ❤️ that @signalapp considered this very attack in their threat modeling, and developed a mitigation. settings>account>registration lock https://twitter.com/... Alex Radocea / @defendtheworld : I feel like signal continues to underplay how terrible of an idea phone-number based identity is despite being convenient for adoption. Twilio's customer support isn't the weakest point for SMS... it's the global telephony system itself. https://support.signal.org/... @combat_boot : Oopsie. Especially as certain organisation was touting app as most secure thing ever. Nothing is 100% & leading ppl to believe that it is, encourages risky behaviour. Trivial number of users involved but some targeted. Should serve as warning ref trust https://www.bleepingcomputer.com/ ... https://twitter.com/... J. A. Guerrero-Saade / @juanandres_gs : Honestly, let's take a minute to appreciate that @signalapp was built to guard precisely against this sort of attack. Reward and applaud well thought out security engineering in action! (h/t @dinodaizovi for the perspective) https://twitter.com/... Amanda Silberling / @asilbwrites : If you're a journalist using Signal to talk to sources, go to settings —> account and change your pin + turn on registration lock https://twitter.com/... Carly Page / @carlypage_ : so it looks like one of those 125 customers was... Signal 😳 https://techcrunch.com/... @briankrebs : Learned something new about Signal from their rundown of how some users were affected by the Twilio phishing incident: “Registration lock,” which requires your Signal PIN to register your phone number again with Signal https://support.signal.org/... Kevin Collier / @kevincollier : Last week Twilio said 125 customers had been affected in its recent breach. Looks like “customers” meant individual orgs, and Signal was one of those. How many others do we know about? (And if you know of any that aren't public, please reach out) https://support.signal.org/...

TechCrunch Carly Page

Discussion

  • @signalapp @signalapp on x
    Recently @twilio, which provides SMS verification services for Signal, suffered a phishing attack. Via Twilio, attackers may have accessed phone numbers & SMS registration codes for 1,900 Signal users. 1/
  • @signalapp @signalapp on x
    Message history, profile info, contact lists, & other data were NOT & could not be accessed. The information attackers accessed could allow them to attempt to register a Signal user's phone number on a new device if that user had not enabled registration lock. 2/
  • @jsrailton John Scott-Railton on x
    PSA: Do you use Signal? Turn on registration lock today. Here's why... 1/ https://twitter.com/... https://twitter.com/...
  • @erratarob @erratarob on x
    Signal still depends on valid phone numbers and I still don't understand why. I think it's absurd, yet I respect them and thus believe they have solid reasons — just reasons I don't understand. Can somebody explain those reasons to me? https://twitter.com/...
  • @josephmenn Joseph Menn on x
    Every time there is a high-end attack on a critical end-to-end encrypted app that fails to obtain content, I am reminded how many even Western officials want to stop end-to-end encryption, which is close to the only thing in tech security that actually works. https://twitter.com/…
  • @jennschiffer Jenn on x
    between digital ocean emailing yesterday about impact from a mailchimp hack, the heroku disaster, and now this - it's truly the year of learning the ingredients in the platforms we consume 😅🤘 https://twitter.com/...
  • @freedomofpress @freedomofpress on x
    A recent breach of Twilio could have allowed attackers to take over users' accounts by registering their Signal number on a new device. This is why we recommend journalists enable “Registration Lock” on Signal. Here's how: https://freedom.press/... https://twitter.com/...
  • @dinodaizovi Dino A. Dai Zovi on x
    It's a testament to Signal's design that a Twilio breach only allows an attacker to assume a target account's phone number (which also notifies all conversations of their new safety number) and doesn't compromise *any* data. Good proactive security designs prepare for breaches. h…
  • @signalapp @signalapp on x
    We have identified and are contacting the 1,900 potentially affected users. We are prompting them to re-register their Signal numbers and encouraging them to enable registration lock. We are also working with Twilio to ensure they upgrade their security practices. 3/
  • @nohackme @nohackme on x
    i ❤️ that @signalapp considered this very attack in their threat modeling, and developed a mitigation. settings>account>registration lock https://twitter.com/...
  • @defendtheworld Alex Radocea on x
    I feel like signal continues to underplay how terrible of an idea phone-number based identity is despite being convenient for adoption. Twilio's customer support isn't the weakest point for SMS... it's the global telephony system itself. https://support.signal.org/...
  • @combat_boot @combat_boot on x
    Oopsie. Especially as certain organisation was touting app as most secure thing ever. Nothing is 100% & leading ppl to believe that it is, encourages risky behaviour. Trivial number of users involved but some targeted. Should serve as warning ref trust https://www.bleepingcompute…
  • @juanandres_gs J. A. Guerrero-Saade on x
    Honestly, let's take a minute to appreciate that @signalapp was built to guard precisely against this sort of attack. Reward and applaud well thought out security engineering in action! (h/t @dinodaizovi for the perspective) https://twitter.com/...
  • @carlypage_ Carly Page on x
    so it looks like one of those 125 customers was... Signal 😳 https://techcrunch.com/...
  • @asilbwrites Amanda Silberling on x
    If you're a journalist using Signal to talk to sources, go to settings —> account and change your pin + turn on registration lock https://twitter.com/...
  • @briankrebs @briankrebs on x
    Learned something new about Signal from their rundown of how some users were affected by the Twilio phishing incident: “Registration lock,” which requires your Signal PIN to register your phone number again with Signal https://support.signal.org/...
  • @kevincollier Kevin Collier on x
    Last week Twilio said 125 customers had been affected in its recent breach. Looks like “customers” meant individual orgs, and Signal was one of those. How many others do we know about? (And if you know of any that aren't public, please reach out) https://support.signal.org/...