【】
On Monday,Signal, often viewed as the most secure messaging app, shared that a security breach of its phone number verification service provider affected 1,900 of its users. Due to the breach, these users' phone numbers were exposed.
Tweet may have been deleted
According to Signal's post detailing the situation, the provider, Twilio, was targeted in a phishing attack. In Twilio's own postexplaining the situation, the company says it was a "sophisticated social engineering attack designed to steal employee credentials." The attack was successful in obtaining credentials from some of Twilio's employees. Twilio says that around 125 of its customers had data compromised during the attack. One of these affected customers is Signal.
On the bright side, Signal's reputation as the most secure messaging app is intact thanks to its service being 100 percent end-to-end encrypted. Without access to a Signal user's physical device, a bad actor could not access that user's messaging history. So, any sensitive information that was shared within messages on Signal have not been compromised. Profile data, contact list, and other data also was not compromised, again, thanks to Signal's design.
However, Signal warns that there were issues that arose for the users affected by the breach:
"For about 1,900 users, an attacker could have attempted to re-register their number to another device or learned that their number was registered to Signal. This attack has since been shut down by Twilio."
SEE ALSO:Apple delayed Telegram's iOS app update due to unauthorized use of its emojiAccording to Signal, one of those 1,900 users reported that their account was re-registered on another device without their authorization. Also, as Signal notes, most of its users were not affected at all by the security breach.
That there's been fairly little fallout from this security breach is a testament to Signal's security. But the breach is also a reminder of Signal's one glaring flaw: the requirement that a user registers their phone number to use the messaging service. Signal has previously hinted that it will soon allow people to use usernames instead of their phone number, but there is currently no scheduled roll out for that feature.
TopicsCybersecurity
相关文章
Hiddleswift finally followed each other on Instagram after 3 excruciating days
On Aug. 13, 1961, Germany began construction of the Berlin Wall, perhaps the greatest symbol of the2025-01-18- 龔俊漏勺什麽梗?龔俊漏勺的梗是因為他在很多采訪中都耿直的離譜,什麽都往外說而且毫不在意,每次都在講大實話。漏勺指的是經常把話說漏嘴的人,藏不住消息。龔俊經常被他和張...漏勺是什麽梗?就是撐飯的漏勺梗2025-01-18
- 前言:李子柒的螺螄粉怎麽那麽難吃?因為每個人的口味各不相同螺獅粉為什麽那麽臭?就像魚香肉絲裏沒有魚 ,夫妻肺片裏麵沒有肺片一樣,螺螄粉裏麵沒有螺螄。但,有螺螄不屈不滅的靈魂。在一碗完整的螺螄粉中 ,螺螄是2025-01-18
- 蓮子怎麽曬不會發黑-九州醉餐飲網將蓮子外麵的蓮衣去除,放在陽光下晾曬即可。晾曬蓮子時,需要保持幹燥,避免潮濕雨林等環境,以免蓮子變質。蓮子在晾曬之前,也可以將蓮子心去除,以免。蓮子怎麽曬不會發黑,家裏2025-01-18
Metallica to seek and destroy your eardrums with new album this fall
Metallica was never going to keep quiet forever.。 The band has announced its new album, Hardwired&he2025-01-18- 農村俗語:“男怕柿子女怕梨 ,母豬最怕西瓜皮”是啥意思?有何...農村俗語是千百年來中國文化長河中孕育出來的一種奇特文化,它雖然難登大雅之堂,但它卻深受廣大農民朋友的喜愛,因為它是農民朋友,經過長期生活2025-01-18
最新评论