时间:2025-11-22 04:55:32 来源:网络整理编辑:百科
On Monday, Signal, often viewed as the most secure messaging app, shared that a security breach of i
On Monday,Signal, often viewed as the most secure messaging app, shared that a security breach of its phone number verification service provider affected 1,900 of its users. Due to the breach, these users' phone numbers were exposed.
Tweet may have been deleted
According to Signal's post detailing the situation, the provider, Twilio, was targeted in a phishing attack. In Twilio's own postexplaining the situation, the company says it was a "sophisticated social engineering attack designed to steal employee credentials." The attack was successful in obtaining credentials from some of Twilio's employees. Twilio says that around 125 of its customers had data compromised during the attack. One of these affected customers is Signal.
On the bright side, Signal's reputation as the most secure messaging app is intact thanks to its service being 100 percent end-to-end encrypted. Without access to a Signal user's physical device, a bad actor could not access that user's messaging history. So, any sensitive information that was shared within messages on Signal have not been compromised. Profile data, contact list, and other data also was not compromised, again, thanks to Signal's design.
However, Signal warns that there were issues that arose for the users affected by the breach:
"For about 1,900 users, an attacker could have attempted to re-register their number to another device or learned that their number was registered to Signal. This attack has since been shut down by Twilio."
SEE ALSO:Apple delayed Telegram's iOS app update due to unauthorized use of its emojiAccording to Signal, one of those 1,900 users reported that their account was re-registered on another device without their authorization. Also, as Signal notes, most of its users were not affected at all by the security breach.
That there's been fairly little fallout from this security breach is a testament to Signal's security. But the breach is also a reminder of Signal's one glaring flaw: the requirement that a user registers their phone number to use the messaging service. Signal has previously hinted that it will soon allow people to use usernames instead of their phone number, but there is currently no scheduled roll out for that feature.
TopicsCybersecurity
Visualizing July's astounding global temperature records2025-11-22 04:49
發燒先消炎還是先退燒2025-11-22 04:48
懷孕5個月應該補什麽2025-11-22 04:39
開了一指半還要多久生2025-11-22 04:33
Early Apple2025-11-22 04:04
如何看待 2018 俄羅斯世界杯阿根廷 0:3 不敵克羅地亞 ?(18年阿根廷被誰淘汰)2025-11-22 03:37
姨媽來了一點又沒有了2025-11-22 03:26
肺部活檢和穿刺的區別是什麽?2025-11-22 03:16
Balloon fanatic Tim Kaine is also, of course, very good at harmonica2025-11-22 02:40
卵泡太大了是不是不好2025-11-22 02:34
Airbnb activates disaster response site for Louisiana flooding2025-11-22 04:48
巴薩貸款經濟獲得緩衝,梅西會在邁阿密退役?拜仁 :巴黎違反規則(梅西什麽時候退休)2025-11-22 04:44
周歲寶寶發燒38度怎麽辦2025-11-22 04:28
如何看待 2018 俄羅斯世界杯阿根廷 0:3 不敵克羅地亞?(18年阿根廷被誰淘汰)2025-11-22 04:11
Katy Perry talks 'Rise,' her next batch of songs, and how to survive Twitter2025-11-22 04:08
最新消息:波蘭名哨確認執法世界杯決賽 ,球迷擔心陰謀論要成真(英格蘭名哨)2025-11-22 03:21
經常熬夜的人怎麽補身體呢 ?2025-11-22 03:10
三色玉米粒的做法是怎樣的 ?2025-11-22 03:07
Richard Branson 'thought he was going to die' in bike accident2025-11-22 03:03
化療後臉腫了怎麽回事2025-11-22 02:37