News: 1660653186

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

1,900 Signal users exposed: Twilio attacker 'explicitly' looked for certain numbers

(2022/08/16)


The security breach at Twilio earlier this month affected at least one high-value customer, Signal, and led to the exposure of the phone number and SMS registration codes for 1,900 users of the encrypted messaging service, it confirmed.

However, Signal – considered one of the better secured of all the encrypted messaging apps – claims the attacker would not have been able to access the message history, contact lists, profile information, or other personal data associated with these user accounts. The non-profit organization said in a [1]security note on its site that it has identified and is notifying the 1,900 users directly, and prompting them to re-register Signal on their devices.

The company had already come under fire for its practice of SMS verification in the past, something which has rebounded in the wake of the disclosure.

[2]

According to Signal, Twilio provides SMS verification services for its platform. Twilio provides messaging, call center and two-factor authentication services, among others, to about [3]256,000 customers altogether – although it said in an earlier incident report about the breach that only 125 of its customers had data "accessed by malicious actors for a limited period of time."

[4]

[5]

The news that Signal was one of the 125 has raised questions about the identity of other Twilio customers, especially as the encrypted comms platform is known for its [6]transparency . Others may be less forthcoming.

According to Signal's security note, when Twilio was hit by a phishing attack earlier this month, this may potentially have led to the phone number of 1,900 Signal users being revealed as registered to a specific Signal account. The encryption app platform added that the users' SMS verification codes were also exposed.

[7]

It appears that during the window of time that the [8]attacker had access to Twilio's customer support systems, it would have been possible for them to attempt to re-register the phone numbers they had accessed, transferring the account to another device under their own control, using the SMS verification code. It also stresses that the attacker no longer has this access, and that the attack had been shut down by Twilio.

Intriguingly, Signal states that the attacker explicitly searched for three phone numbers among the 1,900 accessed, and the organization has since received a report from one of those three users that their account was indeed re-registered.

In this case, where an attacker was able to re-register an account, they would then be able to send and receive Signal messages from that phone number, Signal confirmed.

[9]

We asked Signal if there was any explanation as to why the attacker should target these three specific users, and we will update the story if we get a response.

Signal was at pains to point out that message history is stored only on the user's device so Signal does not have copies of these that could be accessed. Contact lists, profile information and other private data can only be recovered with the user's Signal PIN, which the organization could not access.

Furthermore, Signal said that its vulnerability to the Twilio attackers was one it has already sought to address through features such as registration lock and the Signal PIN.

Registration lock prevents anyone from registering a user's phone number onto a new phone unless they have the PIN associated with that account. This feature must be activated by the user, and Signal is now strongly encouraging users to enable it.

[10]Cloudflare: Someone tried to pull the Twilio phishing tactic on us too

[11]Twilio customer data exposed after its staffers got phished

[12]Reckon Russian spies are lurking in your inbox? Check for these IOCs, Microsoft says

[13]Cisco admits corporate network compromised by gang with links to Lapsus$

Signal states that if users see a banner saying their device is no longer registered when opening Signal, it may indicate their account has been re-registered, but it cautions that users may no longer be registered for other reasons, such as if they have not been active on the service for a long period of time.

The [14]Twilio breach earlier this month was a sophisticated phishing attack, whereby employees received text messages claiming to be from Twilio's IT department asking them to login and change their password, linking to a phony web page designed to look like Twilio's real sign-in page. If anyone fell for the ruse, the attacker used their credentials to access Twilio's internal systems.

Last week, content delivery network Cloudflare revealed that it had been the target of a [15]very similar breach attempt , but that attack failed because employees are required to use hardware security keys as part of their login process. ®

Get our [16]Tech Resources



[1] https://support.signal.org/hc/en-us/articles/4850133017242

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Yvu-KAbTBDhx9Fn4djTZuwAAAI8&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://www.twilio.com/press/releases/twilio-announces-fourth-quarter-and-full-year-2021-results

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Yvu-KAbTBDhx9Fn4djTZuwAAAI8&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Yvu-KAbTBDhx9Fn4djTZuwAAAI8&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[6] https://signal.org/bigbrother/santaclara/

[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Yvu-KAbTBDhx9Fn4djTZuwAAAI8&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[8] https://www.twilio.com/blog/august-2022-social-engineering-attack

[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Yvu-KAbTBDhx9Fn4djTZuwAAAI8&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[10] https://www.theregister.com/2022/08/10/cloudflare_twilio_phishing/

[11] https://www.theregister.com/2022/08/08/twilio_phishing_attack/

[12] https://www.theregister.com/2022/08/16/microsoft_russian_spies/

[13] https://www.theregister.com/2022/08/11/cisco_corporate_network_compromised/

[14] https://www.theregister.com/2022/08/08/twilio_phishing_attack/

[15] https://www.theregister.com/2022/08/10/cloudflare_twilio_phishing/

[16] https://whitepapers.theregister.com/



How do you choose a Cloud Security Provider?

Doctor Syntax

Really?

As Wikipedia would say…

Anonymous Coward

> Signal – considered one of the best secured of all the encrypted messaging apps

By whom? I certainly don't consider a platform where I can be looked up by anybody in a position to know my phone number to be "secure" in any way that is useful to me.

I note that, cleverly, they don't make any explicit claims to the effect of being "most secure". I only hear that from journalists and people repeating what they read on the news.

I would ordinarily suggest to provide a source for the claim that it is "one of the best secured of all the encrypted messaging apps". But that is logically true (there is even an XKCD about things being "one of the ").

(Totally expect down votes for pointing out that the emperor has no clothes)

Re: As Wikipedia would say…

Doctor Syntax

I think your downvotes might be for not having researched how it actually works.

How can be…

Anonymous Coward

…something where your phone number is your ID be presented as a tool suitable for use by such people as whistleblowers and dissidents?

What's worse, I understand that it *requires* you to have it installed on a mobile phone for it to work, even though (so I understand) there is also an Electron (yes, Electron) client available. A mobile phone is almost by definition an eavesdropping device, for Torvalds sake!

Re: How can be…

Doctor Syntax

You do realise, don't you, that a burner phone can be used for registration? Viewing the YT videos on how to do this might be educational.

Do as I say, not as I do

drand

A company that provides 2FA services does not require its own employees to use 2FA when logging in/changing passwords. Peak tech company.

Re: Do as I say, not as I do

iron

If you read earlier stories that went into more details about the Twilio breach you'd know they do use 2FA.

The note about Cloudflare is because they use hardware keys, not an app or SMS for 2FA.

Those three 'searched for' numbers

Nifty

Would have been the 'proof of concept' numbers already owned by the hackers to check it was all working as expected...

It's intriguing that Signal seems to know for sure which 1,900 numbers got their details stolen, and that no others have been. If Signal can manage all that, how come it can't secure the database in the first place?

Obviously your filters are throwing away mail from Randal. :-)
-- Larry Wall in <199710221937.MAA25131@wall.org>