On Monday,Signal, often viewed as the most secure messaging app, shared that a security breach of its phone number verification service provider affected 1,900 of its users. Due to the breach, these users' phone numbers were exposed.
This Tweet is currently unavailable. It might be loading or has been removed.
According to Signal's post detailing the situation, the provider, Twilio, was targeted in a phishing attack. In Twilio's own postexplaining the situation, the company says it was a "sophisticated social engineering attack designed to steal employee credentials." The attack was successful in obtaining credentials from some of Twilio's employees. Twilio says that around 125 of its customers had data compromised during the attack. One of these affected customers is Signal.
On the bright side, Signal's reputation as the most secure messaging app is intact thanks to its service being 100 percent end-to-end encrypted. Without access to a Signal user's physical device, a bad actor could not access that user's messaging history. So, any sensitive information that was shared within messages on Signal have not been compromised. Profile data, contact list, and other data also was not compromised, again, thanks to Signal's design.
However, Signal warns that there were issues that arose for the users affected by the breach:
"For about 1,900 users, an attacker could have attempted to re-register their number to another device or learned that their number was registered to Signal. This attack has since been shut down by Twilio."
SEE ALSO: Apple delayed Telegram's iOS app update due to unauthorized use of its emojiAccording to Signal, one of those 1,900 users reported that their account was re-registered on another device without their authorization. Also, as Signal notes, most of its users were not affected at all by the security breach.
That there's been fairly little fallout from this security breach is a testament to Signal's security. But the breach is also a reminder of Signal's one glaring flaw: the requirement that a user registers their phone number to use the messaging service. Signal has previously hinted that it will soon allow people to use usernames instead of their phone number, but there is currently no scheduled roll out for that feature.
Copyright © 2023 Powered by
Twilio hack results in security issue for 1,900 Signal users-叶瘦花残网
sitemap
文章
91444
浏览
89171
获赞
15
Zoom adds two
Many of us have come to rely on Zoom video calls as a way of interacting with friends and family safTwitter is adding encrypted direct messages very soon
Messaging on Twitter is about to become a lot more private. According to the company's CEO and overlElon Musk's tweet about Mars is confusing the internet
A few weeks ago, U.S. president Donald Trump received a fair share of mocking after tweeting that thOpen letter seeks pause on AI experiments: What it says, who signed it
AI experts, technologists, and business leaders are among the 1,000 plus petitioners imploring AI laDid Trump forget about his TikTok ban? TikTok would like to know.
President Trump has been very busy with his re-election campaign and, of late, dubious legal challenGPU Availability and Pricing Update: October 2021
Welcome back to another month of looking at how expensive graphics cards are at retail at the momentApple bans ChatGPT use by employees, report says
Apple employees will reportedly be restricted from using ChatGPT and other artificial intelligence tMeta slapped with $1.3 billion fine for sending EU user data to the U.S.
Facebook's parent company Meta has been fined 1.2 billion euro ($1.3 billion) for breaching the EuroHow the Twitter hack highlights the dangers of Slack
Slack holds the keys to its customers' kingdoms, and has long been aware how problematic that is. TwExtreme locust plagues shown swarming Kenya in new video
No, these aren't fields blossoming with yellow flowers. It's a swarm of ravenous locusts. A biologisWhy reigning Fat Bear Week champ Beadnose isn't competing this year
Welcome to Fat Bear Week 2019! Katmai National Park's bears spent the summer gorging on 4,500-caloriOpen letter seeks pause on AI experiments: What it says, who signed it
AI experts, technologists, and business leaders are among the 1,000 plus petitioners imploring AI laMeghan Markle opens up about the impact media scrutiny has had on her
In a rare interview, Meghan Markle has spoken candidly about the impact of the intense media scrutinTwitter will only show verified accounts on its 'For You' page
Elon Musk says that Twitter will only display the tweets of verified users on its For You page, starThe Trump admin really doesn’t want you to see this climate science
The same scientific agencies that rocketed Neil Armstrong to the moon and forecast the landfall of h