Live data from Hacker News

Twilio’s toll fraud problem

billychasen.medium.com

111–120 of 221 posts

Re: Twilio’s toll fraud problem

#113
Could this stop every random company from asking for my phone number to send me SMS? I hope so.

Email works fine, is more reliable, latency is fine, and it works across devices and on desktops.

Deduplicate your accounts some other way. Owning a bunch of phone numbers is (clearly, from the article) not a hurdle for attackers.

Re: Twilio’s toll fraud problem

#114
post #107

We've been hit by this at work as well. We had to add CAPTCHA and a several other techniques to defend against this. How it works: 1. Attacker leases 1 or more premium rate numbers in an international country. - Attacker can lease a premium rate number for as little as $10/month - Typically, the attacker gets to keep 70% of the money generated by the premium rate number. 2. Attacker then finds companies with OTP (One…

Which seems like a super easy fix for Twilio to implement. Don't allow SMS to premium rate numbers. If they can identify the premium numbers for billing, they should be able to identify them for blocking.

I would imagine there are rules/regulations about a SMS provider blocking communications before fraudulent behavior is determined? Not saying it shouldn't/couldn't be done, but probably one of those things with a simple tech fix but a complicating social/business aspect.

Re: Twilio’s toll fraud problem

#115

We've been hit by this exact issue, especially over the last month. We tried to mitigate as cleanly as possible for our users, adding one-time nounces to signup requests, adding rate-limiting rules, locking down regions, but we still faced an onslaught of tens of thousands of fraudulent signups per day. On our tier we don't have the ability to set block rules ourselves - it requires a support request that takes 2-3 d…

If you told Twilio to text a number and they text it, I don't see how Twilio is at fault. It would be valuable if they let you avoid texting premium numbers, but that's just a feature on top of the service they provide.

They should be better equipped to detect and prevent the abuse. It's an order of magnitude higher request volume for phone #s located in remote regions of the world. Twilio knows full-well where those numbers go, and can see them being abused simultaneously across many customers. I don't possess the same ability to know this... unless I use Twilio to run a reverse-lookup, which would of course still incur a cost.

Re: Twilio’s toll fraud problem

#117
post #72
post #50

Earlier quoted context omitted.

>Your only power to encourage them to fix this is to do the thing they're begging you not to: dispute the charges. I'd check their TOS to see if they offer some kind of arbitration option. As noted in other threads, triggering that process can be a surprisingly effective way to make someone from the company actually engage with the issue. Disputing the charges is always a nuclear option. They may never do business wi…

> Disputing the charges is always a nuclear option. They may never do business with you after that. This is something that I think needs to be regulated. I'm not saying that this should be the case for a company the size of Twilio, but I definitely think that a company the size of Apple/Google/Samsung should not be able to ruin your life because you had temerity to stand up to them and dispute a charge.

Also twilio … they’re the industry standard for enterprise communications

Re: Twilio’s toll fraud problem

#118
post #107

We've been hit by this at work as well. We had to add CAPTCHA and a several other techniques to defend against this. How it works: 1. Attacker leases 1 or more premium rate numbers in an international country. - Attacker can lease a premium rate number for as little as $10/month - Typically, the attacker gets to keep 70% of the money generated by the premium rate number. 2. Attacker then finds companies with OTP (One…

Which seems like a super easy fix for Twilio to implement. Don't allow SMS to premium rate numbers. If they can identify the premium numbers for billing, they should be able to identify them for blocking.

Down thread someone pointed out that their API allows you to set a max price:

https://www.twilio.com/blog/2015/08/introducing-max-price.ht...

Apparently a lot of people could really use that info.

Re: Twilio’s toll fraud problem

#119
post #25
post #18

Earlier quoted context omitted.

As a programmatic telephone company, they're a possible (but not really probable) base for fraudulent spam calls. With KYC, and the fact that Twilio requires you call from a number you control, fraudulent calls would be easy to trace back to a person who could be charged for the calls. Much better than status quo, where it's very difficult to get to the originating phone account, and if you could, it's probably not r…

Why should Twilio do this when nobody else does?

Keeping their traffic clean makes it easier to interconnect, and in an ideal world, they want to interconnect with everyone

Re: Twilio’s toll fraud problem

#120
This is the first I'm hearing of this, so I might be missing some information, bit I don't understand how this is Twilio's fault or responsibility.

Your service got hit with a ddos-style attack that translated into you using twilio to send lots of texts. This cost you a lot of money.

I don't see how this is categorically different than your kid "accidentally" buying movies on Amazon prime or something like that. No way a credit card company would accept a chargeback in that scenario.

Ultimately, you used their product in the intended way. Of course you're on the hook for the bill.

Post reply on HN