3 ms·
> Then, from the article, others can reuse the username too. This sounds like a potential security hole. You have to be sure that your contact hasn't reset the
by Jabbles 3y ago
> Then, from the article, others can reuse the username too.
This sounds like a potential security hole. You have to be sure that your contact hasn't reset their username as you add them. Or maybe that's what the username registration timestamp is for? To show that this username has been in use by the same person for a while?
- wolverine876 3y agoIt would seem to make sense for a persistant attacker to collect well-publicized usernames when the original owner changes them. Imagine a journalist who publicizes a username, then changes it. The original username would linger on the Internet, in people's address books, etc. A persistant attacker might acquire it, and snap up contacts as they come in. Maybe Signal should have made usernames non-reusable, at least as an option. They still could dissociate the username from the phone number when the user 'deletest' it. The deleted username would just be shifted to the null user.