Live data from Hacker News

Twilio confirms data breach after hackers leak 33M Authy user phone numbers

securityweek.com

11–20 of 408 posts

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#11
post #4
post #3

My goodness, for the 100,000th time, just stop using phone numbers for 2FA. (I know you won't anyway) There are no more excuses other than asking for your phone to be sim-swapped and your bank accounts or your wallets to be drained by call centers. If this breach doesn't scare you from using phone number for 2FA, then maybe nothing ever will and AI and deep fakes will make this even worse.

Authy doesn't implement SMS 2FA (how could it). A phone number is part of your user profile for registered mobile devices hosting the app.

That is brilliant news for SIM swappers and criminals now that they can gain access to your codes directly with your phone number!

A terrific reason to avoid anything Twilio / Authy

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#12
post #6

Earlier quoted context omitted.

Even worse... Sounds like phone number is irrelevant, yet they collect it.

It's used to store and retrieve your 2fa secrets in case you lose your device

> > Even worse... Sounds like phone number is irrelevant, yet they collect it.

> It's used to store and retrieve your 2fa secrets in case you lose your device

The phone number doesn't store anything?

But if somehow knowing that phone number is a key to getting your 2FA secrets, you'd have a bigger problem.

Except it often is, and that's the problem.

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#14
post #2

Good motivation to stop using Authy.

What is a good alternative?

Most likely whatever password app you use supports these now. I know for myself, I started using Authy long long ago when there were not really many options.

In my case, 1 Password can do this now. I believe the same is true for Bitwarden and Apple passwords.

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#15
post #11
post #4

Earlier quoted context omitted.

Authy doesn't implement SMS 2FA (how could it). A phone number is part of your user profile for registered mobile devices hosting the app.

That is brilliant news for SIM swappers and criminals now that they can gain access to your codes directly with your phone number! A terrific reason to avoid anything Twilio / Authy

[deleted]

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#16
post #14

Earlier quoted context omitted.

What is a good alternative?

Most likely whatever password app you use supports these now. I know for myself, I started using Authy long long ago when there were not really many options. In my case, 1 Password can do this now. I believe the same is true for Bitwarden and Apple passwords.

I hesitate to use the same app for both authentication factors.

The reason why I started using Authy a long time ago is that it supports multiple devices and isn't linked to any other account (such as Google or Microsoft).

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#17

Earlier quoted context omitted.

How else are they going to track people with a hard-to-change identifier?

> How else are they going to track people with a hard-to-change identifier? Using the device advertisee ID that the user is entitled to change. // Sorry, for a moment I thought you were serious.

I just did some quick research on these IDs. Correct me if I'm wrong, but it seems like each user account would be tied to one device. It also seems like the user, at least on Apple devices, has to opt into advertising tracking in order for your app to even get access to this.

Ignoring the security pitfalls of phone numbers, it really doesn't seem like these advertising IDs are a drop in replacement for using phone numbers.

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#20

Earlier quoted context omitted.

It's used to store and retrieve your 2fa secrets in case you lose your device

> > Even worse... Sounds like phone number is irrelevant, yet they collect it. > It's used to store and retrieve your 2fa secrets in case you lose your device The phone number doesn't store anything? But if somehow knowing that phone number is a key to getting your 2FA secrets, you'd have a bigger problem. Except it often is, and that's the problem.

Do what I do and turn off "allow multi-device." Problem solved -- even if your phone number is stolen, they can't recover your 2FA because it's locked to the device too.
Post reply on HN