Signal put out a notice today that I've now read three times, mostly because I have that app open more hours of the day than I'd like to admit. Short version: Twilio, the company that handles SMS verification for a huge chunk of the internet (Signal included), got phished earlier this month. Some employee credentials got taken, attackers poked around, and Signal says the phone numbers of about 1,900 users got exposed. For a small subset of those, whoever did this could've seen the actual SMS verification code come through, meaning in theory they could've tried to register someone else's number on a new device.
Signal's being pretty upfront about it, which I appreciate, and they're telling anyone affected to re-register and turn on a registration PIN if they haven't already. I did mine this morning before coffee, which tells you something about where my priorities sit these days.
Here's the thing that's been nagging at me all day though, and its not really about Signal specifically. Its about how much of our security still boils down to "prove you have this phone number" as the load-bearing wall. Signal is the app privacy people recommend to their less-technical relatives specifically because it doesn't need your contacts or your real name, just a number — and that number is also, it turns out, the thing an attacker can go after by breaching some third-party vendor you've never heard of and never agreed to trust. Twilio isn't consumer-facing. Most Signal users have no idea it exists. Doesn't matter. It's in the chain.
I run a Fastmail address with 2FA everywhere I can manage it, and I still get funneled into SMS verification more than I'd like on things that really should offer an authenticator app option and just don't. Banks are the worst offenders honestly, closely followed by anything from an airline. My opinion, not up for debate: SMS-as-2FA should be treated as better-than-nothing, not as a real second factor, and any service still leaning on it as the only option in 2022 is being lazy about it.
This all lands during the same stretch as Black Hat and DEF CON out in Vegas, which wrapped up this past weekend, so my feeds have been extra security-brained lately anyway. Every August it's the same rhythm: a couple weeks of "here's a horrifying thing we found" talks, then a slow trickle of actual disclosures like this one over the following days as companies scramble to notify people before some researcher live-tweets it for them.
Unrelated tangent, but I also want to note that Samsung's Unpacked event from last week is still sitting in my browser tabs unread, three tabs deep, because I genuinely cannot get myself excited about another folding phone announcement. The Z Fold 4 and Flip 4 look fine! Nice hardware, I'm sure. I just have fold fatigue at this point; every year it's a slightly thinner hinge and a slightly better cover screen and everyone acts like its a whole new category again. I'll probably end up reading the reviews in October anyway, because I'm a hypocrite about these things.
Back to the actual point. If you use Signal, and honestly even if you don't, this is a decent nudge to go check what's tied to SMS verification in your life. I went through my 1Password entries tonight and found four services where SMS was still my only 2FA method despite the option to switch to TOTP sitting right there in settings, ignored for probably a year. Fixed two of them before I got bored and went to make dinner. The other two are still sitting there. I'll get to them.
The bigger, uglier problem, that phone numbers were never designed to be identity anchors and we've backed the entire internet's security model into them anyway because it was convenient in like 2011, isn't something Signal fixed by rotating a PIN, and it isn't something I'm going to solve by writing a blog post about it either. But it's worth being annoyed about publicly, so, here I am, annoyed about it publicly.