Live data from Hacker News

Twilio confirms data breach after hackers leak 33M Authy user phone numbers

securityweek.com

31–40 of 408 posts

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#31
post #2

Good motivation to stop using Authy.

What is a good alternative?

Aegis (Android), supports automatic backups. There is also Ente Auth (it's been mentioned on this site), but I haven't used it much.

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#32

I use Authy’s iOS app to generate 2FA tokens for a few accounts. I cannot remember ever entering my phone number into it, or establishing an Authy account of any kind. Is there some other way they would have acquired my phone number? I’m trying see if the issue is some unanticipated issue with the iOS client app itself, or if it is only affecting people who created online accounts with Authy to sync their 2FA credent…

Authy is both a SaaS and a consumer-facing authenticator app.

When companies integrate Authy into their system, they can use it for SMS OTP (also deliverable by phone call + TTS iirc) as well as regular TOTP, Authy's proprietary TOTP, and others.

Your phone number would only be at risk if you used a service which used Authy for SMS 2FA

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#33

I use Authy’s iOS app to generate 2FA tokens for a few accounts. I cannot remember ever entering my phone number into it, or establishing an Authy account of any kind. Is there some other way they would have acquired my phone number? I’m trying see if the issue is some unanticipated issue with the iOS client app itself, or if it is only affecting people who created online accounts with Authy to sync their 2FA credent…

Authy is both a SaaS and a consumer-facing authenticator app. When companies integrate Authy into their system, they can use it for SMS OTP (also deliverable by phone call + TTS iirc) as well as regular TOTP, Authy's proprietary TOTP, and others. Your phone number would only be at risk if you used a service which used Authy for SMS 2FA

The consumer app also wants your phone number... It prompts you to "backup" your codes, so that they're not gone if you reinstall the app or switch devices

you probably gave them your phone number at some point if youve got authy on multiple devices.

/Edit: just checked on a clean install. It prompts for a phone number instantly and won't let you scan codes without creating an account. Not sure when that happened, as I haven't really used it in years.

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#34

Authy makes it hard to migrate away. Anyone know how to get the seed of the 2FA codes? Is there really no export option?

I slowly migrated away from Authy when they decided to shut down their desktop authenticator. You can painfully export codes, though I generated new 2FA codes at every vendor.

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#35
post #22
post #3

My goodness, for the 100,000th time, just stop using phone numbers for 2FA. (I know you won't anyway) There are no more excuses other than asking for your phone to be sim-swapped and your bank accounts or your wallets to be drained by call centers. If this breach doesn't scare you from using phone number for 2FA, then maybe nothing ever will and AI and deep fakes will make this even worse.

If you use Authy, turn off "allow multi-device" and SIM-swapping isn't an issue. This should be on regardless of the leak.

But one of the selling points for me was to allow multiple devices so that if one broke I'd still have access.

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#36
post #22

Earlier quoted context omitted.

If you use Authy, turn off "allow multi-device" and SIM-swapping isn't an issue. This should be on regardless of the leak.

But one of the selling points for me was to allow multiple devices so that if one broke I'd still have access.

people with this use case would need to be comfortable taking on the extra risk.

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#37

I use Authy’s iOS app to generate 2FA tokens for a few accounts. I cannot remember ever entering my phone number into it, or establishing an Authy account of any kind. Is there some other way they would have acquired my phone number? I’m trying see if the issue is some unanticipated issue with the iOS client app itself, or if it is only affecting people who created online accounts with Authy to sync their 2FA credent…

Have you looked into the settings? On android you can see a cellphone-number and e-mail there. If they are missing, I guess it's not known to them.

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#39
post #30

Authy makes it hard to migrate away. Anyone know how to get the seed of the 2FA codes? Is there really no export option?

You'll have to reset them one by one.

I finished that process recently for 50+ accounts. It's something that I would definitely wish on my worst enemy.

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#40
Does anyone have a recommendation for an Open Source 2FA OTP app? That's the only thing I use Authy for, to scan the QR Codes into the App and generate the 2FA tokens, but in a way that allows me to migrate to another phone without having to re-set all the 2FA tokens on the vendor side.
Post reply on HN