On Monday,Signal, often viewed as the most secure messaging app, shared that a security breach of its phone number verification service provider affected 1,900 of its users. Due to the breach, these users' phone numbers were exposed.
Tweet may have been deleted
According to Signal's post detailing the situation, the provider, Twilio, was targeted in a phishing attack. In Twilio's own postexplaining the situation, the company says it was a "sophisticated social engineering attack designed to steal employee credentials." The attack was successful in obtaining credentials from some of Twilio's employees. Twilio says that around 125 of its customers had data compromised during the attack. One of these affected customers is Signal.
On the bright side, Signal's reputation as the most secure messaging app is intact thanks to its service being 100 percent end-to-end encrypted. Without access to a Signal user's physical device, a bad actor could not access that user's messaging history. So, any sensitive information that was shared within messages on Signal have not been compromised. Profile data, contact list, and other data also was not compromised, again, thanks to Signal's design.
However, Signal warns that there were issues that arose for the users affected by the breach:
"For about 1,900 users, an attacker could have attempted to re-register their number to another device or learned that their number was registered to Signal. This attack has since been shut down by Twilio."
SEE ALSO: Apple delayed Telegram's iOS app update due to unauthorized use of its emojiAccording to Signal, one of those 1,900 users reported that their account was re-registered on another device without their authorization. Also, as Signal notes, most of its users were not affected at all by the security breach.
That there's been fairly little fallout from this security breach is a testament to Signal's security. But the breach is also a reminder of Signal's one glaring flaw: the requirement that a user registers their phone number to use the messaging service. Signal has previously hinted that it will soon allow people to use usernames instead of their phone number, but there is currently no scheduled roll out for that feature.
Copyright © 2023 Powered by
Twilio hack results in security issue for 1,900 Signal users-燕尔新婚网
sitemap
文章
64855
浏览
23423
获赞
5279
Snapchat removes Juneteenth filter that prompted users to smile to break chains
Snapchat apologized for its insensitive Juneteenth filter that asked users to smile to break chainsSnapchat's My AI chatbot posted a Story then stopped responding. Users freaked out.
Snapchat users have reported that the messaging app's AI chatbot had a few issues on Tuesday night.Remembering V Live, K
V Live, the hugely influential live-streaming platform that ushered Korean pop music to global promiFacebook might start bypassing Apple and Google's app stores in the EU
Facebook is thinking about letting users in the European Union download apps directly through ads onWatch Kathryn Hahn stare longingly at Rachel Weisz set to the 'Carol' score
Kathryn Hahn and Rachel Weisz are made to be together, forever -- at least in queer fanfiction on TuHow to enable Screen Distance in iOS 17 to protect your kid's eyes
Want to make sure your kids aren't holding their phones dangerously close to their eyes? Apple has aSamsung Galaxy Z Fold 5 vs Fold 4: Specs, price, cameras
Last year, Samsung's Galaxy Z Fold 4 impressed us with an eminently useful tablet-like form factor.Amid Reddit Blackout, CEO downplays API protest as subreddits vow to keep fighting
The 48-hour Reddit "Blackout" is technically coming close to an end. However, the company's blas&eacTwoSeven review: Group streaming for all of your favorite services
The search for the perfect group streaming service for the age of social distancing isn't over, butAuthor's tweet about a disappointing book signing draws support from literary legends
Forging a career as a writer is no easy feat, whether it's finding an agent, getting a publishing deMicrosoft announces Bing Chat for business with built
On Wednesday, Microsoft announced a business-friendly version of Bing Chat, so you can use the AI chMeta avatars now work in Messenger video calls
Not ready to show your real face in a Messenger or Instagram video call? You now have the option ofBitcoin wipes coronavirus losses, passes $10,000 again
There's a popular meme that shows Bitcoin on a perpetual rollercoaster. It's true: The world's largeMicrosoft might be saving your conversations with Bing Chat
Uh-oh — Microsoft might be storing information from your Bing chats.This is probably totally fSnapchat's My AI chatbot posted a Story then stopped responding. Users freaked out.
Snapchat users have reported that the messaging app's AI chatbot had a few issues on Tuesday night.