Earlier quoted context omitted.
>Your only power to encourage them to fix this is to do the thing they're begging you not to: dispute the charges. I'd check their TOS to see if they offer some kind of arbitration option. As noted in other threads, triggering that process can be a surprisingly effective way to make someone from the company actually engage with the issue. Disputing the charges is always a nuclear option. They may never do business wi…
Is there anything in the arbitration clauses forbidding them from cancelling your account if you invoke arbitration (regardless of whether you prevail or fail?).
Twilio’s toll fraud problem
101–110 of 221 posts
Re: Twilio’s toll fraud problem
#102We've been hit by this exact issue, especially over the last month. We tried to mitigate as cleanly as possible for our users, adding one-time nounces to signup requests, adding rate-limiting rules, locking down regions, but we still faced an onslaught of tens of thousands of fraudulent signups per day. On our tier we don't have the ability to set block rules ourselves - it requires a support request that takes 2-3 d…
It would be valuable if they let you avoid texting premium numbers, but that's just a feature on top of the service they provide.
Re: Twilio’s toll fraud problem
#103Earlier quoted context omitted.
That Twillio doesn't protect you is bad. However, would a court agree you don't owe them the money? This recommendation seems like abuse of disputing a charge and will just get you banned from Twillio.
The court doesn't have to agree, only the card provider does. The customer has the right to dispute credit card charges thanks to the agreements between customer and card provider and between card provider and merchant. Twilio will get in trouble with Visa/Mastercard if customers say Twilio is dropping them for disputes the card provider finds in the customers' favor. This is why you always pay for sketchy merchants…
If you pay someone to mow your lawn, then they mow your lawn and charge you. You can't just chargeback after the fact to get that service for free.
Re: Twilio’s toll fraud problem
#1041. Rate limited SMS by number/ip: bypassed by large number of proxies/vpn.
2. Added captcha: bypassed by attacker manually signing up thousands of accounts (mechanical turks?) over months and then iterating over them for login OTP.
3. Identifying what carriers/operators are involved and blocking them asap (usually obscure ones).
4. Careful monitoring of SMS send rates and alerting of anomalies to investigate.
Re: Twilio’s toll fraud problem
#105Earlier quoted context omitted.
The court doesn't have to agree, only the card provider does. The customer has the right to dispute credit card charges thanks to the agreements between customer and card provider and between card provider and merchant. Twilio will get in trouble with Visa/Mastercard if customers say Twilio is dropping them for disputes the card provider finds in the customers' favor. This is why you always pay for sketchy merchants…
Why would the card providers be in the customer's favor. The customer paid for a text to be delivered to a phone number and Twilio did that and then charged the customer for it. If you pay someone to mow your lawn, then they mow your lawn and charge you. You can't just chargeback after the fact to get that service for free.
Re: Twilio’s toll fraud problem
#106Earlier quoted context omitted.
The court doesn't have to agree, only the card provider does. The customer has the right to dispute credit card charges thanks to the agreements between customer and card provider and between card provider and merchant. Twilio will get in trouble with Visa/Mastercard if customers say Twilio is dropping them for disputes the card provider finds in the customers' favor. This is why you always pay for sketchy merchants…
Why would the card providers be in the customer's favor. The customer paid for a text to be delivered to a phone number and Twilio did that and then charged the customer for it. If you pay someone to mow your lawn, then they mow your lawn and charge you. You can't just chargeback after the fact to get that service for free.
It might be in the terms and conditions, but it’s bad faith to not give any warnings or controls before the services are rendered.
Re: Twilio’s toll fraud problem
#107We've been hit by this at work as well. We had to add CAPTCHA and a several other techniques to defend against this. How it works: 1. Attacker leases 1 or more premium rate numbers in an international country. - Attacker can lease a premium rate number for as little as $10/month - Typically, the attacker gets to keep 70% of the money generated by the premium rate number. 2. Attacker then finds companies with OTP (One…
If they can identify the premium numbers for billing, they should be able to identify them for blocking.
Re: Twilio’s toll fraud problem
#108Earlier quoted context omitted.
Is there anything in the arbitration clauses forbidding them from cancelling your account if you invoke arbitration (regardless of whether you prevail or fail?).
Well they have to abide by the arbitration and any good arbitrator will put a good faith clause in the agreement.
Re: Twilio’s toll fraud problem
#109Spam phone calls... the global phone system is a network of relays. No telecom provider connects everyone on the planet together. To call our grandmother in Russia, we may have to go through Verizon, Deutsche Telecom, MTS, and ~five different smaller, regional telecom providers. The first telecom provider will request the second to complete the call, will trust they do this, and will accept the price they charge upon which they'll add their own costs. This occurs recursively until the phone call has been connected and completed. This implicit trust enables fraudulent actors to get into the circle of trust. Verizon may trust Deutsche, Deutsche may trust MTS, and MTS may trust a smaller telecom provider who in turn trusts a spam caller. This enables you to get spam calls. Telecom providers themselves don't know all the callers on the global telecom network and don't really know how much people will be charged. There is no global government to legislate across all telecoms.
Bots on the internet... the internet as a whole doesn't have a firm sense of identity. It's just a network protocol routing packets to ip addresses. In the past, these ip addresses were mostly human beings. In the current time, the majority of the participants on the internet are bots/computer programs. A website like "Big Tech Retailer" has >90% of all traffic from computer programs. Elon Musk was probably right that Twitter is full of bots, because the entire internet is swimming with bots. They can be incredibly difficult to detect because AI blurs humans with bots.
This toll fraud problem is that bots we struggle to detect place phone messages to phone numbers we struggle to identify. This ends up costing a huge and growing amount of money. You cannot truly solve the problem without solving the two underlying problems of bots on the internet and spam calls. Solutions to those problems may require rethinking and rebuilding the entire communication system we've built our lives around.
Nonetheless, we can greatly reduce the effect of this problem. At "Big Tech Retailer", myself and two others we were able to reduce the cost to a small percentage of what it was. After that point, the business sort of stopped caring because the fraud cost less than the staff. There were perhaps five techniques that were most helpful, all of which were contemporary fraud fighting/bot fighting/security techniques.
If you're a startup facing this problem, I can help give you some guidance. Twilio will probably see this post and start working on a solution, but that may take a long time. There are easy things you can do to mitigate the problem right now. You can contact me at manrajt@gmail.com.
Re: Twilio’s toll fraud problem
#110We've been hit by this exact issue, especially over the last month. We tried to mitigate as cleanly as possible for our users, adding one-time nounces to signup requests, adding rate-limiting rules, locking down regions, but we still faced an onslaught of tens of thousands of fraudulent signups per day. On our tier we don't have the ability to set block rules ourselves - it requires a support request that takes 2-3 d…
Just curious because you didn't mention it - have you considered putting a captcha in front of your OTP flow? Are the fraudsters also defeating that?