Live data from Hacker News

Twilio confirms data breach after hackers leak 33M Authy user phone numbers

securityweek.com

41–50 of 408 posts

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#41
post #33

Earlier quoted context omitted.

Authy is both a SaaS and a consumer-facing authenticator app. When companies integrate Authy into their system, they can use it for SMS OTP (also deliverable by phone call + TTS iirc) as well as regular TOTP, Authy's proprietary TOTP, and others. Your phone number would only be at risk if you used a service which used Authy for SMS 2FA

The consumer app also wants your phone number... It prompts you to "backup" your codes, so that they're not gone if you reinstall the app or switch devices you probably gave them your phone number at some point if youve got authy on multiple devices. /Edit: just checked on a clean install. It prompts for a phone number instantly and won't let you scan codes without creating an account. Not sure when that happened, as…

Figures. I stand corrected then.

We used Authy for 2FA at my last company and migrated off it to use a complete auth platform. The amount of user (consumer and business) hostile shit we found in the process was astounding.

Twilio was nice to work with way back when it was the only decent API-driven POTS connection service out there. They've steadily gotten worse over the years and acquisitions though. Wouldn't recommend them to my worst enemy these days.

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#42

Authy makes it hard to migrate away. Anyone know how to get the seed of the 2FA codes? Is there really no export option?

Some months ago, I used https://github.com/alexzorin/authy to export them. It basically creates a dummy-device to access the tokens, and then exports them to some format. But I have not figured out how to import them now into another app.

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#43
post #4
post #3

My goodness, for the 100,000th time, just stop using phone numbers for 2FA. (I know you won't anyway) There are no more excuses other than asking for your phone to be sim-swapped and your bank accounts or your wallets to be drained by call centers. If this breach doesn't scare you from using phone number for 2FA, then maybe nothing ever will and AI and deep fakes will make this even worse.

Authy doesn't implement SMS 2FA (how could it). A phone number is part of your user profile for registered mobile devices hosting the app.

> Authy doesn't implement SMS 2FA (how could it).

https://www.authy.com/integrations/ssh/

"Someone in your organization doesn't have a smartphone? We got you covered. Authy SSH can send them the token via SMS or a phone call."

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#44

Does anyone have a recommendation for an Open Source 2FA OTP app? That's the only thing I use Authy for, to scan the QR Codes into the App and generate the 2FA tokens, but in a way that allows me to migrate to another phone without having to re-set all the 2FA tokens on the vendor side.

I‘m using Raivo. It hasn’t let me down, yet

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#45

Does anyone have a recommendation for an Open Source 2FA OTP app? That's the only thing I use Authy for, to scan the QR Codes into the App and generate the 2FA tokens, but in a way that allows me to migrate to another phone without having to re-set all the 2FA tokens on the vendor side.

I use a YubiKey with their Authenticator app.

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#46
There really has to be steep repercussions for companies that fail to protect user data like this. At this point I can't help but feel that there is wilful neglect with the aim of exfiltrating data with unknowable aim.

Our digital data must be recognized as human rights but lately the world has been vocal about it but silent when it comes to action and enforcement.

More and more reason why people no longer trust cloud hosted solutions. Offline-first, local-first with optional data sync is the only path forward to combat violation of our rights to our own digital data.

Case in point, feeding haveibeenpwned with a bunch of HN user handles reveal a good chunk of you aren't even aware your data has been leaked, especially ironic since I see comments from those handles are very anti-regulation when it comes to user data ownership.

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#47

Does anyone have a recommendation for an Open Source 2FA OTP app? That's the only thing I use Authy for, to scan the QR Codes into the App and generate the 2FA tokens, but in a way that allows me to migrate to another phone without having to re-set all the 2FA tokens on the vendor side.

I've implanted my 2FA token in my arm and just hope it never breaks :D

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#48

Does anyone have a recommendation for an Open Source 2FA OTP app? That's the only thing I use Authy for, to scan the QR Codes into the App and generate the 2FA tokens, but in a way that allows me to migrate to another phone without having to re-set all the 2FA tokens on the vendor side.

I used Aegis for a while and really liked it, switched to Bitwarden now but the UX was better

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#49

Does anyone have a recommendation for an Open Source 2FA OTP app? That's the only thing I use Authy for, to scan the QR Codes into the App and generate the 2FA tokens, but in a way that allows me to migrate to another phone without having to re-set all the 2FA tokens on the vendor side.

I‘m using Raivo. It hasn’t let me down, yet

Raivo was bought by a shady developer last year and is no longer open source. If that wasn’t enough, a few weeks ago they released an update which deleted all your codes - failing at literally the one job a 2FA app has!

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#50

Does anyone have a recommendation for an Open Source 2FA OTP app? That's the only thing I use Authy for, to scan the QR Codes into the App and generate the 2FA tokens, but in a way that allows me to migrate to another phone without having to re-set all the 2FA tokens on the vendor side.

I‘m using Raivo. It hasn’t let me down, yet

The same Raivo that was sold to some shady dev who proceeded to delete all of the OTPs that I had in the app?

https://www.reddit.com/r/privacy/comments/1d3zqvv/raivo_auth...

Post reply on HN