Their Signal account went dormant after not being used for a year. After that someone was able to claim the username for the account.
There isn’t much information about the breach or how it was discovered, but the article says this.
Signal user IDs associated with accounts that are left dormant are eventually recycled and made available to new users.
If you own a Signal account that you leave dormant from time to time, beware of this.
The Signal team need to fix this. I don’t claim to propose the best solution, but letting other users take over usernames of a dormant account is a mistake, and perhaps users who connect with someone using a potentially hijacked username ought to be alerted to verify the contact.
You do not own a Signal account if access can be automatically revoked by a third-party due to inactivity.
SimpleX would be a good option but Signal is popular with Journalists.
I assume the account itself wasn’t taken over but the associated username was deregistered and subsequently taken over by the third party.
When it comes to trust, the technical details do not really matter if people continue to assume that the hijacked account handle remains in possession of The Intercept.
I agree. Unsuspecting people will trust the third party as if they own the account that is actually owned by The Intercept.
Is this behaviour clearly indicated? It would be—to me—the responsibility of the outlets to promptly inform that the Signal tip line is no longer active.
On ownership, it seems a bit ridiculous to me that you would feel “ownership” (in the property sense, as in, “this is mine forever”) over an account (or in this case, just a username) that exists in someone else’s database. Even email services eventually turn over their inactive addresses.
This highlights a great life rule.
Never trust reporters.
When I said “ownership” I meant control over the account, not ownership in the property sense.
It would be good to examine Signal’s ToS wrt inactive accounts. If it states nothing about inactive accounts/usernames, users may expect to maintain ownership (control) over them indefinitely. If the ToS states inactive accounts/usernames are deactivated, a balance between security and recycling accounts/usernames would be prudent. AFAIK some email services are smart enough to freeze used email addresses after they have been deactivated.
The ephemeral nature of Signal usernames has always been rather transparent. This is not unlike phone numbers which are cycled person to person.
One should not assume the identity at the other end. This is why the safety number feature exists. The safety number can be confirmed out of band.
In my opinion, anyone posting their Signal username publicly long-term should consider also posting the per-account segment of their safety number. In the app, this will be either the first 30 characters or last 30 characters, depending. If there are privacy implications of this, perhaps others could chime in.
However, there are some more advanced use cases which per-conversation safety numbers might not provide for (such as Charlie verifying Alice’s fingerprint by checking with Bob), so we designed the safety number format to be a sorted concatenation of two 30-digit individual numeric fingerprints. Advanced users that would like to use fingerprints for more complex use cases can separate the two fingerprints from the safety number if necessary.
More reading on Safety numbers:
It doesn’t seem like Signal usernames were meant to be ephemeral. This support page about phone number privacy and usernames says this.
A username is not the profile name that’s displayed in chats, it’s not a permanent handle, and not visible to the people you are chatting with in Signal.
I interpret this as usernames are not locked in once created, not usernames are ephemeral.
Usernames are designed to be flexible. You can keep the same one for as long as you like, or change it as often as you wish.
Back to The Intercept, the support page says this about freezing usernames, though this in the context of changed usernames and not dormant accounts.
If you change your username, no one else will be able to claim your old username for about a week after you make the change. Following that, they will be able to claim it.
Privacy implications need consideration (chime in people) but may be worth considering ![]()
You should interpret it as it reads. Which is that it is not a permanent handle. Usernames on Signal are recycled fairly quickly after control is relinquished. Once you change your username, anyone can claim it soon.
Usernames are locked in once created so long as the account stays active and I’ve seen nothing nor does my personal experience indicate they are not. Nothing reported indicates otherwise.
I think account inactivity could be more clearly documented in the support pages, but for what it’s worth this appears to be an authoritative source on reddit. “u/jon-signal”
FWIW, the current numbers are:
120 days inactivity to remove account
45 days inactivity to unlink linked device
46 day time-to-live for messages awaiting delivery
The way The Intercept handled the situation is unacceptable. I would not trust them at this point. Look at what happened to Reality Winner and other whistleblowers who trusted them.
Archived link: https://archive.fo/mWWti
CONTEXT:
Winner was just 25 years old when she printed a single classified document — one that described Russian military efforts to spear-phish dozens of local election officials ahead of the 2016 election — smuggled it out of the NSA facility where she worked and mailed it to The Intercept.
(For comparison, Edward Snowden provided at least 10,000 documents to, among others, Glenn Greenwald and Laura Poitras, who later went on to co-found The Intercept. The NSA has claimed he took more than 1.7 million files.) Winner was ultimately sentenced to sixty-three months in prison for the leak, the longest prison term ever imposed for an unauthorized release of government information to the media.
HOW THE INTERCEPT FAILED A WHISTLEBLOWER:
The Intercept was widely criticized for its handling of the document Winner leaked—in particular, the decision to show the leaked document to the U.S. government. While attempting to verify its authenticity with the NSA, an Intercept reporter inadvertently revealed its provenance. According to an FBI affidavit, the document had a telltale crease in it, indicating it had been printed and folded.
An FBI agent assigned to the case would later testify that a total of six people had printed the document. The pool of potential leakers was further narrowed to one — Winner — when investigators discovered she’d emailed The Intercept from her work computer.
The Intercept would go on to conduct an internal review, which found that, in Winner’s case, its “practices fell short of the standards to which we hold ourselves” when it came to protecting sources
After her arrest, First Look Media, which owns The Intercept, pledged to support Winner’s legal defense, but Winner says that support stopped shortly after her sentencing in August 2018.
THE INTERCEPT FAILED OTHER WHISTLEBLOWERS:
“I wasn’t the first source that they burned and I definitely wasn’t the last — two other people have done prison time [due to] them being extremely sloppy,” Winner says, referring to Daniel Hale, sentenced to 45 months in prison earlier this year after he pled guilty to leaking documents about the U.S. military’s drone program, and Terry Albury, sentenced in 2018 to four years in prison after leaking documents concerning the bureau’s use of informants. “Every time one of their sources goes to prison, that’s another headline for them. That’s how they stay relevant — by burning sources, instead of the journalism that they once believed in.”
