On Monday,Signal, often viewed as the most secure messaging app, shared that a security breach of its phone number verification service provider affected 1,900 of its users. Due to the breach, these users' phone numbers were exposed.
Tweet may have been deleted
According to Signal's post detailing the situation, the provider, Twilio, was targeted in a phishing attack. In Twilio's own postexplaining the situation, the company says it was a "sophisticated social engineering attack designed to steal employee credentials." The attack was successful in obtaining credentials from some of Twilio's employees. Twilio says that around 125 of its customers had data compromised during the attack. One of these affected customers is Signal.
On the bright side, Signal's reputation as the most secure messaging app is intact thanks to its service being 100 percent end-to-end encrypted. Without access to a Signal user's physical device, a bad actor could not access that user's messaging history. So, any sensitive information that was shared within messages on Signal have not been compromised. Profile data, contact list, and other data also was not compromised, again, thanks to Signal's design.
However, Signal warns that there were issues that arose for the users affected by the breach:
"For about 1,900 users, an attacker could have attempted to re-register their number to another device or learned that their number was registered to Signal. This attack has since been shut down by Twilio."
SEE ALSO: Apple delayed Telegram's iOS app update due to unauthorized use of its emojiAccording to Signal, one of those 1,900 users reported that their account was re-registered on another device without their authorization. Also, as Signal notes, most of its users were not affected at all by the security breach.
That there's been fairly little fallout from this security breach is a testament to Signal's security. But the breach is also a reminder of Signal's one glaring flaw: the requirement that a user registers their phone number to use the messaging service. Signal has previously hinted that it will soon allow people to use usernames instead of their phone number, but there is currently no scheduled roll out for that feature.
Copyright © 2023 Powered by
Twilio hack results in security issue for 1,900 Signal users-如火燎原网
sitemap
文章
82898
浏览
59
获赞
5
5 Great Chrome Extensions You Should Install
With almost 60 percent share of the browser market, Chrome is around three times more popular than iAmazon Prime could include cell service someday
Maybe someday Amazon Prime will include your rent and health insurance, too.Well, probably not, butMaking Migrants Disappear
Taylor Mitchell ,November 20, 2023 MakingBest free ChatGPT courses
TL;DR:A wide range of ChatGPT courses are available to take for free on Udemy. Udemy is a popular huSorry gardeners, you can't buy foreign seeds on Amazon anymore
Amazon has a new rule in place governing seed and plant imports for U.S. customers: Nope.The onlineBluesky reveals early look at Bluesky+, its subscription service
This week, we got an early look at the potential details of Bluesky+, the social media site's planneDoomsday Diaries
Sarah Aziza ,October 18, 2023 Doomsday DiaAre We Undone?
Fiction10 dogs who really loved their puppucinos
Forget the Dragonfruit Frappucino. Starbucks's best secret menu item is the puppuccino, and everyoneBest gift card deals: Hulu, Lyft, DoorDash, Meta Quest, Instacart, and more
The best gift card deals at a glance as of Dec. 10: OUR TOP PICKHere's why your Spotify desktop app looks so different
Most Spotify users listen to music on their phones but a new look is coming for those of us who stilBorrowed to the Hilt
Elizabeth Tandy Shermer ,October 11, 2023Tim Cook on Hong Kong protest app removal: We did it to protect our users
Apple has received a fair amount of backlash over its decision to ban an app that allows Hong Kong pBest free AI courses you can take online
TL;DR:A wide range of AI courses are available to take for free on Udemy. The conversation about theUsing ChatGPT to write resumes is a dealbreaker for some recruiters
New graduates aren't afraid to use ChatGPT when applying for jobs — and some professionals are