Allegedly, Signalgate was caused by Apple helpfully mapping the wrong number to a name. Then Signal mapped that number to the wrong cryptographic identity.
> Allegedly, Signalgate was caused by Apple helpfully mapping the wrong number to a name.
In what system is Apple mapping numbers to names? The address book is maintained by users. An AppleID? How could that happen? And it would seem to result in many errors before the Signal error.
I thought it was simply caused by someone adding the wrong person to the chat?
> The Intercept
Per that article, the cause is unknown. The speculated cause in the article is that The Intercept somehow lost control of the user id, and Signal recycles user ids. That seems like a bad practice generally and with this predictable consequence, and especially bad for an application people trust with security.
> Twilio
This was Twilio employees caught by a phishing attack. I wonder what more secure, and affordable, options Signal has. Operate their own SMS infrastructure - would that be more secure that Twilio's? Use something besides SMS - would on-boarding become too hard? Stop using phone numbers - they need some spammer and bot filter, so what replaces it?
> Russian State-Backed Hackers
A phishing attack on Signal users, using a QR or link to make the attacker a linked device. That setup seems risky for non-technical users; I wonder how Signal could better secure it.
That and other attacks are described here. The other attacks all require compromising the device on which Signal is installed:
A Third Party Breached The Intercept’s Signal Tip Line and Has Been Soliciting Whistleblowers https://www.dropsitenews.com/p/intercept-signal-tip-line-bre...
Twilio Incident: What Signal Users Need to Know https://support.signal.org/hc/en-us/articles/4850133017242-T...
Russian State-Backed Hackers Intensify Attacks on Signal Messenger Accounts https://thecyberexpress.com/signal-attacks-russian-fackers-t...