Live data from Hacker News

Twilio confirms data breach after hackers leak 33M Authy user phone numbers

securityweek.com

171–180 of 408 posts

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#171
post #132

Earlier quoted context omitted.

How convenient for the data collecting companies that so generously sponsor the new & free services, that our democratically controlled communication infrastructure looses in value.

Advertising is a cancer on modern society. It will metastasize to any new communications medium, public or private, and destroy it from within. People will switch to new medium that offer less spam, but advertisers quickly follow to strip-mine the new channel. A cycle of life, so to speak.

I don’t have a problem with advertising generally, as long as I know upfront that’s what funds a tool I’m using, and isn’t disguised like a non-ad (eg. Unlike what Google does, which is outright deception). Advertising and spam are two separate things in my book.

However, my real problem is with what I call “The Google Strategy.” Basically, they take publicly funded infrastructure like HTTP and SMTP, capture the network by dumping “free” products on the market (with basically no advertising), kill off competitors, then monetize their market capture by removing the "free" part, packing these products with ads, making them worse and worse over time in the process. And everyone is trapped, since they captured the network of this public infrastructure. This is the story of Google Search, Gmail, YouTube, etc.

It’s anti-competitive, anti-markets, and quite frankly should have been regulated away as a strategy a long time ago.

Google basically ran Microsoft's classic anti-competitive B2B strategy to capture the consumer internet, and got away with it!

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#172
post #135
post #119

This doesn’t surprise me. I found an information exposure vuln on the user registration endpoint a while ago (given a phone number of an authy user who had previously registered via another customer, retrieve all other numbers/devices/timestamps, email addresses and other info for that user). It took them two years to fix it.

> Twilio has detected that threat actors were able to identify data associated with Authy accounts, including phone numbers, due to an unauthenticated endpoint Isn’t it what you are describing?

Based on the reports that I’ve read so far, this vuln was different to the one I found, which was on an authenticated endpoint.

Definitely some similarities though, I’d love to see some concrete technical information on it.

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#173

Does anyone have a recommendation for an Open Source 2FA OTP app? That's the only thing I use Authy for, to scan the QR Codes into the App and generate the 2FA tokens, but in a way that allows me to migrate to another phone without having to re-set all the 2FA tokens on the vendor side.

https://2fas.com/

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#174

Authy is basically unsupported. Not surprised. I switched my accounts to 1Password when they announced the end of life of the macOS app.

Authy is terrible. I recently tried to delete my account, because I've (finally) moved everything to Keepass, and they make it as difficult as possible. Then they make you wait 30 days before they actually delete it, making sure to email you constantly in the mean time, to ask you to please reconsider. My 30 days expired a few days ago, so if they had actually deleted my account when I told them to, my info maybe wouldn't have been leaked.

Dog shit company. Avoid.

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#175

Earlier quoted context omitted.

I recently had to help my father organize his medical visits. Dealing with his healthcare providers was a bit of a pain, but it was way worse because he has stopped answering calls, primarily because of the call spam rate. I think because he owns his own business, he never fails to hand out his contact info when he is shopping, and he owns his own business (so his contact info is published by the city). His phone pro…

Why not get a second sim? Most phones can have 2 sims active, and a phone / text only plan is dirt cheap (3-6$/m). Offer the second number with much greater discretion.

From experience it seems to be semi-random.

I've never had a single spam call on my main phone number, but friends who have got a new number get maybe 20 spam calls per day, with only having given their number to their closest friends and family.

I think one factor that weighs in heavily is if your contacts download thousands of spam apps onto their phones and click YES to every permission. Then your phone number is harvested from your contact's phone and sold. TikTok, for instance, will beg me multiple times on a frequent basis to see my contacts. I don't think you can even install WhatsApp without giving it your entire phone book, can you?

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#177

Twilio requires Authy for 2fa for sendgrid and maybe even twilio itself instead of supporting more standardized 2fa that’d allow 1pass to be used. This is all the more frustrating because I was forced to use Authy to protect an account instead of my regular tooling and they still managed to screw it up. Twilio, take a hint and stop forcing people to use your custom thing https://www.twilio.com/docs/sendgrid/ui/accoun…

Ugh. I hate that some apps require use of specific auth apps. This should not be a thing, we have great generic systems for this already.

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#178
post #132

While this sucks, my phone is in so many data breaches at this point it doesn’t matter. The spam-to-ham ratio on my phone number is now far worse than any other channel for me. The traditional phone network is at risk of going the way of the fax machine if we don’t do something about the spam problem like we did with email. If I’m on a call, even with family, it’s now almost exclusively on FaceTime/zoom/meet/etc. I c…

How convenient for the data collecting companies that so generously sponsor the new & free services, that our democratically controlled communication infrastructure looses in value.

"Our democratically controlled communication infrastructure" honestly deserves to be deprecated and replaced with some kind of federated voice system that comes out of the IETF instead of the telcos. What kind of antediluvian nonsense doesn't use end-to-end encryption in 2024?

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#179

While this sucks, my phone is in so many data breaches at this point it doesn’t matter. The spam-to-ham ratio on my phone number is now far worse than any other channel for me. The traditional phone network is at risk of going the way of the fax machine if we don’t do something about the spam problem like we did with email. If I’m on a call, even with family, it’s now almost exclusively on FaceTime/zoom/meet/etc. I c…

Is this like an American thing? I'm in the Netherlands and i get like 1 spam call per two months (business internet/electricity salesperson usually)

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#180

Earlier quoted context omitted.

I recently had to help my father organize his medical visits. Dealing with his healthcare providers was a bit of a pain, but it was way worse because he has stopped answering calls, primarily because of the call spam rate. I think because he owns his own business, he never fails to hand out his contact info when he is shopping, and he owns his own business (so his contact info is published by the city). His phone pro…

Why not get a second sim? Most phones can have 2 sims active, and a phone / text only plan is dirt cheap (3-6$/m). Offer the second number with much greater discretion.

I don't know about most phones supporting that, probably depends on the market.

But best I can tell, 80% of my spam calls are just war dialing; a new number would get war dialed just as much. Probably wouldn't get collections calls for my deadbeat cousin though.

Post reply on HN