I loved Twilio many years ago, but they've become the new Google/SendGrid/Shopify/Stripe/Uber/(soon to add CloudFlare). They retain the right to any/all the upside of any risk/scale, and you retain the obligation in any downside. No questions. It's despicable.
Confused, I don't see what's in common with all of the companies in your list. I work with Twilio a lot and kind of agree with your last sentence but what do you mean? Are these normal business practices?
Twilio’s toll fraud problem
41–50 of 221 posts
Re: Twilio’s toll fraud problem
#42Earlier quoted context omitted.
Solving this is squarely Twilio's business! They know how much to bill the customer, so they must know how much it costs to send to a number.
> They know how much to bill the customer I don't mean to do Twilio's work of defending them, but in my experience it's possible they actually don't know how much to bill the customer. What they may know is the generalized per-minute or per-session rate they've agreed with another operator alongside a general "premium rate numbers will be settled at a later date" kind of clause. My employer got bit by this several ye…
Re: Twilio’s toll fraud problem
#43Your only power to encourage them to fix this is to do the thing they're begging you not to: dispute the charges . If a threshold of Twilio customers dispute charges, Twilio loses the ability to process credit cards at a lower risk rate, then with all but high risk processors, then may lose the ability to process them at all. If enough of their customers are getting burned, and enough dispute, Twilio would no longer…
Re: Twilio’s toll fraud problem
#44Your only power to encourage them to fix this is to do the thing they're begging you not to: dispute the charges . If a threshold of Twilio customers dispute charges, Twilio loses the ability to process credit cards at a lower risk rate, then with all but high risk processors, then may lose the ability to process them at all. If enough of their customers are getting burned, and enough dispute, Twilio would no longer…
Couldn't Twilio also close and cease providing service to any accounts that initiate chargebacks?
I strongly encourage Twilio customers to pursue this route if Twilio is charging them for fraudulent charges.
Re: Twilio’s toll fraud problem
#45Earlier quoted context omitted.
> There are 200+ jurisdictions in the phone network and everybody has their own conventions on what a "premium" number is. They know how to charge you for these numbers so apparently they do have that data, no?
Depends what you mean by "premium rate." Every number costs money to call in Twilio. Some numbers cost more, in lots of these frauds numbers in ordinary ranges are used (Is a rural number in Chile that costs $0.20/minute to call premium rate/fraud? Because that's what it looks like a lot of the time. How about $0.05 a minute in Austria?). IRSF, the industry term for this kind of fraud causes billions in losses a year…
Re: Twilio’s toll fraud problem
#46Earlier quoted context omitted.
Couldn't Twilio also close and cease providing service to any accounts that initiate chargebacks?
They could, but customers could then file complaints with the FTC and their state’s attorney general for the fraud Twilio is enabling. I strongly encourage Twilio customers to pursue this route if Twilio is charging them for fraudulent charges.
Re: Twilio’s toll fraud problem
#47Re: Twilio’s toll fraud problem
#48How it works:
1. Attacker leases 1 or more premium rate numbers in an international country.
- Attacker can lease a premium rate number for as little as $10/month
- Typically, the attacker gets to keep 70% of the money generated by the premium rate number.
2. Attacker then finds companies with OTP (One-Time Passcodes) or 2FA (Two-Factor Authentication) endpoints that require no validation and writes a script to automate the webpage or call the API endpoint
- Attacker will typically obtain a new IP address per API call using a VPN or a rented botnet from the dark web.
3. If the premium rate number costs 10 cents, then each successful text message they can send to the number generates 7 cents for them.
4. The attacker then just needs to send 150 SMS to the premium rate number to break-even on their $10 investment, not counting the cost of the VPN or rented botnet.
There is a lot of money to be made here by an attacker unfortunately. :(Re: Twilio’s toll fraud problem
#49We tried to mitigate as cleanly as possible for our users, adding one-time nounces to signup requests, adding rate-limiting rules, locking down regions, but we still faced an onslaught of tens of thousands of fraudulent signups per day. On our tier we don't have the ability to set block rules ourselves - it requires a support request that takes 2-3 days to get a response on. Our choices are to eat thousands of dollars per day in toll fraud, or disable sign-ups until we can add more fraud prevention on top of what Twilio enables. The problem is the fraudsters are using real browsers across thousands of IPs located in dozens of different countries.
Similar to the OP, Twilio tries to say this is our fault and leaves it up to us to both pay for the issue and to try and fix it.
Re: Twilio’s toll fraud problem
#50Your only power to encourage them to fix this is to do the thing they're begging you not to: dispute the charges . If a threshold of Twilio customers dispute charges, Twilio loses the ability to process credit cards at a lower risk rate, then with all but high risk processors, then may lose the ability to process them at all. If enough of their customers are getting burned, and enough dispute, Twilio would no longer…
I'd check their TOS to see if they offer some kind of arbitration option. As noted in other threads, triggering that process can be a surprisingly effective way to make someone from the company actually engage with the issue. Disputing the charges is always a nuclear option. They may never do business with you after that.