Live data from Hacker News

Twilio confirms data breach after hackers leak 33M Authy user phone numbers

securityweek.com

21–30 of 408 posts

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#21
post #2

Good motivation to stop using Authy.

What is a good alternative?

Besides all the other advice of using the password manager as a 2FA store as well, on the stand-alone side there is Aegis. I have good experience with it, and allows better interoperability than Authy as well.

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#22
post #3

My goodness, for the 100,000th time, just stop using phone numbers for 2FA. (I know you won't anyway) There are no more excuses other than asking for your phone to be sim-swapped and your bank accounts or your wallets to be drained by call centers. If this breach doesn't scare you from using phone number for 2FA, then maybe nothing ever will and AI and deep fakes will make this even worse.

If you use Authy, turn off "allow multi-device" and SIM-swapping isn't an issue. This should be on regardless of the leak.

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#23
I use Authy’s iOS app to generate 2FA tokens for a few accounts. I cannot remember ever entering my phone number into it, or establishing an Authy account of any kind. Is there some other way they would have acquired my phone number?

I’m trying see if the issue is some unanticipated issue with the iOS client app itself, or if it is only affecting people who created online accounts with Authy to sync their 2FA credentials across devices.

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#24
post #2

Good motivation to stop using Authy.

What is a good alternative?

On iOS, I’ve been using “OTP Auth”.

While it’s nice that password managers can handle this as others have mentioned, the whole point of a 2nd factor is to ensure an attacker can’t get in if they somehow get your password. Storing the second factor along with the 1st factor doesn’t make much sense to me.

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#25
post #11
post #4

Earlier quoted context omitted.

Authy doesn't implement SMS 2FA (how could it). A phone number is part of your user profile for registered mobile devices hosting the app.

That is brilliant news for SIM swappers and criminals now that they can gain access to your codes directly with your phone number! A terrific reason to avoid anything Twilio / Authy

In fairness, you cannot. It requires a backup password.

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#27
post #14

Earlier quoted context omitted.

What is a good alternative?

Most likely whatever password app you use supports these now. I know for myself, I started using Authy long long ago when there were not really many options. In my case, 1 Password can do this now. I believe the same is true for Bitwarden and Apple passwords.

Also KeePassXC -- if you don't like the idea of 2FA codes being in the same db as passwords, it's straightforward to use a separate db for 2FA only.

Manage your own sync between devices with syncthing, dropbox or whatever you prefer.

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#29
post #14

Earlier quoted context omitted.

What is a good alternative?

Most likely whatever password app you use supports these now. I know for myself, I started using Authy long long ago when there were not really many options. In my case, 1 Password can do this now. I believe the same is true for Bitwarden and Apple passwords.

Personally I dislike the idea of putting the other factor(TOTP) alongside the main two ones (email/password). Kind of ruins most of the purpose of TOTP and MFA in general.
Post reply on HN