3 ms·
Assuming you’re using Signal for organizing something the government doesn’t want you organizing, if one member of the group gets rubber-hosed into unlocking th
by K2L8M11N2 6y ago
Assuming you’re using Signal for organizing something the government doesn’t want you organizing, if one member of the group gets rubber-hosed into unlocking their phone, the govt instantly gets a list of verifiably correct names of people involved. In contrast, with a service that lets you use usernames that maneuver would reveal nothing but those usernames (which are as pseudonymous as it gets).
- fossuser 6y agoThanks - the concern makes sense to me given that context.
- walrus01 6y agoOne of the other problems with using phone numbers, is that it provides an opening for adversaries. Now they know your phone number, which can be used for social-engineering attacks to attempt to bypass 2FA for any other online services tied to your phone number. Either for 2FA or for account-recovery/i-forgot-my-password functionality. 2FA by SMS is wrong and broken and nobody should use it, but they do. Adversaries will attempt to social engineer customer service for your phone carrier into issuing them a new SIM or porting out the number, so they can receive verification SMS and phone calls.
- goatsi 6y agoSignal uses a registration pin to prevent that exact attack.
- vinay427 6y agoMaybe I misread, but the GP doesn't seem to be talking about impersonating a user on Signal, but rather impersonating that user on other websites that depend on SMS 2FA sent to their phone number that is now visible through Signal.