时间:2025-03-07 11:03:20 来源:网络整理编辑:綜合
On Monday, Signal, often viewed as the most secure messaging app, shared that a security breach of i
On Monday,Signal, often viewed as the most secure messaging app, shared that a security breach of its phone number verification service provider affected 1,900 of its users. Due to the breach, these users' phone numbers were exposed.
Tweet may have been deleted
According to Signal's post detailing the situation, the provider, Twilio, was targeted in a phishing attack. In Twilio's own postexplaining the situation, the company says it was a "sophisticated social engineering attack designed to steal employee credentials." The attack was successful in obtaining credentials from some of Twilio's employees. Twilio says that around 125 of its customers had data compromised during the attack. One of these affected customers is Signal.
On the bright side, Signal's reputation as the most secure messaging app is intact thanks to its service being 100 percent end-to-end encrypted. Without access to a Signal user's physical device, a bad actor could not access that user's messaging history. So, any sensitive information that was shared within messages on Signal have not been compromised. Profile data, contact list, and other data also was not compromised, again, thanks to Signal's design.
However, Signal warns that there were issues that arose for the users affected by the breach:
"For about 1,900 users, an attacker could have attempted to re-register their number to another device or learned that their number was registered to Signal. This attack has since been shut down by Twilio."
SEE ALSO:Apple delayed Telegram's iOS app update due to unauthorized use of its emojiAccording to Signal, one of those 1,900 users reported that their account was re-registered on another device without their authorization. Also, as Signal notes, most of its users were not affected at all by the security breach.
That there's been fairly little fallout from this security breach is a testament to Signal's security. But the breach is also a reminder of Signal's one glaring flaw: the requirement that a user registers their phone number to use the messaging service. Signal has previously hinted that it will soon allow people to use usernames instead of their phone number, but there is currently no scheduled roll out for that feature.
TopicsCybersecurity
17 questions you can answer if you're a good communicator2025-03-07 10:57
粵媒 :李鐵辭職大概率得到批準 是否下課很快將揭曉2025-03-07 10:37
不愧是你!克羅斯:祝賀梅西獲金球獎 我的選擇是本澤馬2025-03-07 10:09
2021金球獎排名實時更新2025-03-07 09:56
Airbnb activates disaster response site for Louisiana flooding2025-03-07 09:44
申花三外援出戰保級組賽事 積分優勢較大將重點鍛煉新人2025-03-07 09:42
金球獎將增加兩個全新獎項 隊報 :最佳球隊和前鋒2025-03-07 09:41
上限在哪?梅西七奪金球創曆史 明年最後一搏世界杯2025-03-07 09:33
J.K. Rowling makes 'Harry Potter' joke about Olympics event2025-03-07 09:20
日韓周報 :南野拓實助利物浦連勝 鐮田大地歐戰破門2025-03-07 09:15
Cat gets stuck in the most awkward position ever2025-03-07 10:24
不易!斑馬鋒線找到射門靴 迪巴拉莫拉塔同破球荒2025-03-07 10:07
國足換帥12月2日之後或有定論 李霄鵬接手呼聲最高2025-03-07 09:47
圖赫爾當選IFFHS2021年最佳主教練 力壓瓜帥弗裏克2025-03-07 09:42
Singapore rolls out video2025-03-07 09:17
唐淼:球隊沒人說老板不好 希望廣州城挺過難關2025-03-07 09:15
前途無量!佩德裏榮膺2021科帕獎 此前剛拿金童獎2025-03-07 09:02
梅開二度助武漢拿下第四個冠軍 王霜和新的中國女足踏上征程2025-03-07 09:01
More than half of women in advertising have faced sexual harassment, report says2025-03-07 08:42
王霜 :實現了去年的承諾 江山易打不易守來年繼續戰鬥2025-03-07 08:36