时间:2025-01-18 19:12:21 来源:网络整理编辑:綜合
On Monday, Signal, often viewed as the most secure messaging app, shared that a security breach of i
On Monday,Signal, often viewed as the most secure messaging app, shared that a security breach of its phone number verification service provider affected 1,900 of its users. Due to the breach, these users' phone numbers were exposed.
Tweet may have been deleted
According to Signal's post detailing the situation, the provider, Twilio, was targeted in a phishing attack. In Twilio's own postexplaining the situation, the company says it was a "sophisticated social engineering attack designed to steal employee credentials." The attack was successful in obtaining credentials from some of Twilio's employees. Twilio says that around 125 of its customers had data compromised during the attack. One of these affected customers is Signal.
On the bright side, Signal's reputation as the most secure messaging app is intact thanks to its service being 100 percent end-to-end encrypted. Without access to a Signal user's physical device, a bad actor could not access that user's messaging history. So, any sensitive information that was shared within messages on Signal have not been compromised. Profile data, contact list, and other data also was not compromised, again, thanks to Signal's design.
However, Signal warns that there were issues that arose for the users affected by the breach:
"For about 1,900 users, an attacker could have attempted to re-register their number to another device or learned that their number was registered to Signal. This attack has since been shut down by Twilio."
SEE ALSO:Apple delayed Telegram's iOS app update due to unauthorized use of its emojiAccording to Signal, one of those 1,900 users reported that their account was re-registered on another device without their authorization. Also, as Signal notes, most of its users were not affected at all by the security breach.
That there's been fairly little fallout from this security breach is a testament to Signal's security. But the breach is also a reminder of Signal's one glaring flaw: the requirement that a user registers their phone number to use the messaging service. Signal has previously hinted that it will soon allow people to use usernames instead of their phone number, but there is currently no scheduled roll out for that feature.
TopicsCybersecurity
Pole vaulter claims his penis is not to blame2025-01-18 19:04
官方:三家伊朗俱樂部被取消2022賽季亞冠聯賽的參賽資格2025-01-18 18:59
女足留洋再添加一人!上海00後球員楊淑慧登陸法甲2025-01-18 18:02
C羅遭遇信任危機!他讓隊友變糟 ?他隻配替補 ?2025-01-18 17:50
Is Samsung's Galaxy Note7 really the best phone?2025-01-18 17:47
津門虎未來仍需推進股改 人員結構存隱患下賽季怎麽踢?2025-01-18 17:33
FIFA年度最佳門將3人候選 :巴黎拜仁切爾西三強PK2025-01-18 17:32
越南公布備戰中國30人大名單 :主教練內部洗牌7新人入隊2025-01-18 17:25
Mom discovers security cameras hacked, kids' bedroom livestreamed2025-01-18 16:42
草蜢隊主帥 :李磊是紀律性很強的球員 有很多國際比賽經驗2025-01-18 16:32
Did our grandparents have the best beauty advice?2025-01-18 18:45
飛來橫禍 !哈弗茨進球後手指骨折 半場就被換下場2025-01-18 18:33
曝廣州隊球員將看股改結果定去留 有俱樂部已進行接洽2025-01-18 17:43
越南公布備戰中國30人大名單 :主教練內部洗牌7新人入隊2025-01-18 17:39
U.S. pole vaulter skids to a halt for national anthem2025-01-18 17:36
一盤散沙!C羅11月曾組織曼聯聚餐 有球員拒絕出席2025-01-18 17:18
C羅遭遇信任危機 !他讓隊友變糟?他隻配替補?2025-01-18 17:06
曝深足外援金特羅已決定離開球隊 重返老東家河床隊2025-01-18 16:49
Early Apple2025-01-18 16:34
鄭智下賽季大概率繼續執教廣州隊 是否會有離隊潮仍未可知2025-01-18 16:30