Live data from Hacker News

Twilio confirms data breach after hackers leak 33M Authy user phone numbers

securityweek.com

1–10 of 408 posts

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#3
My goodness, for the 100,000th time, just stop using phone numbers for 2FA. (I know you won't anyway)

There are no more excuses other than asking for your phone to be sim-swapped and your bank accounts or your wallets to be drained by call centers.

If this breach doesn't scare you from using phone number for 2FA, then maybe nothing ever will and AI and deep fakes will make this even worse.

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#4
post #3

My goodness, for the 100,000th time, just stop using phone numbers for 2FA. (I know you won't anyway) There are no more excuses other than asking for your phone to be sim-swapped and your bank accounts or your wallets to be drained by call centers. If this breach doesn't scare you from using phone number for 2FA, then maybe nothing ever will and AI and deep fakes will make this even worse.

Authy doesn't implement SMS 2FA (how could it). A phone number is part of your user profile for registered mobile devices hosting the app.

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#5
post #3

My goodness, for the 100,000th time, just stop using phone numbers for 2FA. (I know you won't anyway) There are no more excuses other than asking for your phone to be sim-swapped and your bank accounts or your wallets to be drained by call centers. If this breach doesn't scare you from using phone number for 2FA, then maybe nothing ever will and AI and deep fakes will make this even worse.

[deleted]

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#6
post #4
post #3

My goodness, for the 100,000th time, just stop using phone numbers for 2FA. (I know you won't anyway) There are no more excuses other than asking for your phone to be sim-swapped and your bank accounts or your wallets to be drained by call centers. If this breach doesn't scare you from using phone number for 2FA, then maybe nothing ever will and AI and deep fakes will make this even worse.

Authy doesn't implement SMS 2FA (how could it). A phone number is part of your user profile for registered mobile devices hosting the app.

Even worse... Sounds like phone number is irrelevant, yet they collect it.

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#8
post #6
post #4

Earlier quoted context omitted.

Authy doesn't implement SMS 2FA (how could it). A phone number is part of your user profile for registered mobile devices hosting the app.

Even worse... Sounds like phone number is irrelevant, yet they collect it.

How else are they going to track people with a hard-to-change identifier?

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#9
post #6
post #4

Earlier quoted context omitted.

Authy doesn't implement SMS 2FA (how could it). A phone number is part of your user profile for registered mobile devices hosting the app.

Even worse... Sounds like phone number is irrelevant, yet they collect it.

It's used to store and retrieve your 2fa secrets in case you lose your device

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#10
post #6

Earlier quoted context omitted.

Even worse... Sounds like phone number is irrelevant, yet they collect it.

How else are they going to track people with a hard-to-change identifier?

> How else are they going to track people with a hard-to-change identifier?

Using the device advertisee ID that the user is entitled to change.

// Sorry, for a moment I thought you were serious.

Post reply on HN