時尚

【】

字号+作者:囫圇吞棗網来源:焦點2025-03-01 00:50:28我要评论(0)

On Monday, Signal, often viewed as the most secure messaging app, shared that a security breach of i

On Monday,Signal, often viewed as the most secure messaging app, shared that a security breach of its phone number verification service provider affected 1,900 of its users. Due to the breach, these users' phone numbers were exposed.

According to Signal's post detailing the situation, the provider, Twilio, was targeted in a phishing attack. In Twilio's own postexplaining the situation, the company says it was a "sophisticated social engineering attack designed to steal employee credentials." The attack was successful in obtaining credentials from some of Twilio's employees. Twilio says that around 125 of its customers had data compromised during the attack. One of these affected customers is Signal.

On the bright side, Signal's reputation as the most secure messaging app is intact thanks to its service being 100 percent end-to-end encrypted. Without access to a Signal user's physical device, a bad actor could not access that user's messaging history. So, any sensitive information that was shared within messages on Signal have not been compromised. Profile data, contact list, and other data also was not compromised, again, thanks to Signal's design.

Mashable Light SpeedWant more out-of-this world tech, space and science stories?Sign up for Mashable's weekly Light Speed newsletter.By signing up you agree to our Terms of Use and Privacy Policy.Thanks for signing up!

However, Signal warns that there were issues that arose for the users affected by the breach:

"For about 1,900 users, an attacker could have attempted to re-register their number to another device or learned that their number was registered to Signal. This attack has since been shut down by Twilio." 

SEE ALSO:Apple delayed Telegram's iOS app update due to unauthorized use of its emoji

According to Signal, one of those 1,900 users reported that their account was re-registered on another device without their authorization. Also, as Signal notes, most of its users were not affected at all by the security breach.

That there's been fairly little fallout from this security breach is a testament to Signal's security. But the breach is also a reminder of Signal's one glaring flaw: the requirement that a user registers their phone number to use the messaging service. Signal has previously hinted that it will soon allow people to use usernames instead of their phone number, but there is currently no scheduled roll out for that feature.

TopicsCybersecurity

1.本站遵循行业规范,任何转载的稿件都会明确标注作者和来源;2.本站的原创文章,请转载时务必注明文章作者和来源,不尊重原创的行为我们将追究责任;3.作者投稿可能会经我们编辑修改或补充。

相关文章
  • Man stumbles upon his phone background in real life

    Man stumbles upon his phone background in real life

    2025-02-28 23:53

  • 賈秀全
:目前隊員精神狀態不錯 對陣巴西已準備好

    賈秀全 :目前隊員精神狀態不錯 對陣巴西已準備好

    2025-02-28 23:42

  • 海港攻防效率與武漢持平 2外援缺陣影響逐漸顯現

    海港攻防效率與武漢持平 2外援缺陣影響逐漸顯現

    2025-02-28 23:31

  • 塞浦路斯球隊官方宣布青島外援加盟 雙方簽約兩年

    塞浦路斯球隊官方宣布青島外援加盟 雙方簽約兩年

    2025-02-28 22:29

网友点评