Live data from Hacker News

Twilio confirms data breach after hackers leak 33M Authy user phone numbers

securityweek.com

181–190 of 408 posts

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#181
post #148

consider* putting endpoints on a private overlay network in which network access is cryptography-gated (e.g. x.509 cert based). then, a misconfigured endpoint (or a zero day etc.) can't be exploited by any_actor_on_the_internet - actors need to first complete the provisioning process you choose to enforce to be authorized to use the private overlay. *not one size fits all, e.g. bad option if endpoints need to accept…

> many endpoints only need to accept requests from known (identified, authenticated, authorized) endpoints

Do you mean clients for the last part? I'm not a networking expert but I don't see how layering on certs here is going to help?

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#182
post #179

While this sucks, my phone is in so many data breaches at this point it doesn’t matter. The spam-to-ham ratio on my phone number is now far worse than any other channel for me. The traditional phone network is at risk of going the way of the fax machine if we don’t do something about the spam problem like we did with email. If I’m on a call, even with family, it’s now almost exclusively on FaceTime/zoom/meet/etc. I c…

Is this like an American thing? I'm in the Netherlands and i get like 1 spam call per two months (business internet/electricity salesperson usually)

[deleted]

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#183

Earlier quoted context omitted.

> I can’t remember the last time I talked on the traditional phone network or received a legitimate call Doctors and dentists. Most of the calls I get are spam, but then the MOST important calls I get are from doctors, labs, and dentists. I do as much as possible online of course, but not all of these professionals have good online systems and phone calls are often required. Sometimes you know what number they're goi…

I recently had to help my father organize his medical visits. Dealing with his healthcare providers was a bit of a pain, but it was way worse because he has stopped answering calls, primarily because of the call spam rate. I think because he owns his own business, he never fails to hand out his contact info when he is shopping, and he owns his own business (so his contact info is published by the city). His phone pro…

I haven't answered my phone for anyone not in my VIP list in a year or two.

I can see when someone is calling and in realtime see them leaving a voicemail via speech-to-text and pick up the call if I want but 99.999% of the time it's spam.

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#184

I use Authy’s iOS app to generate 2FA tokens for a few accounts. I cannot remember ever entering my phone number into it, or establishing an Authy account of any kind. Is there some other way they would have acquired my phone number? I’m trying see if the issue is some unanticipated issue with the iOS client app itself, or if it is only affecting people who created online accounts with Authy to sync their 2FA credent…

Authy is both a SaaS and a consumer-facing authenticator app. When companies integrate Authy into their system, they can use it for SMS OTP (also deliverable by phone call + TTS iirc) as well as regular TOTP, Authy's proprietary TOTP, and others. Your phone number would only be at risk if you used a service which used Authy for SMS 2FA

What's Authy's proprietary TOTP protocol? Is it just in fact HOTP, like Duo?

https://news.ycombinator.com/item?id=20936222

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#185

While this sucks, my phone is in so many data breaches at this point it doesn’t matter. The spam-to-ham ratio on my phone number is now far worse than any other channel for me. The traditional phone network is at risk of going the way of the fax machine if we don’t do something about the spam problem like we did with email. If I’m on a call, even with family, it’s now almost exclusively on FaceTime/zoom/meet/etc. I c…

> Gmail did to monetize the lock-in on your inbox

This is why I have my own mail server and domain. Full control over mail, and access to features that you pay for (ie, unlimited e-mail aliases, control over mailbox size). No more worrying about “google decided to shut your free account down for whatever reason. Bye bye decades of emails and loss to services that use email based OTP or magic link login.

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#186
post #179

While this sucks, my phone is in so many data breaches at this point it doesn’t matter. The spam-to-ham ratio on my phone number is now far worse than any other channel for me. The traditional phone network is at risk of going the way of the fax machine if we don’t do something about the spam problem like we did with email. If I’m on a call, even with family, it’s now almost exclusively on FaceTime/zoom/meet/etc. I c…

Is this like an American thing? I'm in the Netherlands and i get like 1 spam call per two months (business internet/electricity salesperson usually)

America doesn’t have privacy laws that prevent robot spam. Repercussions for violating the SPAM Act are not prosecuted very often.

Personally, the only “spam” I get is flagged by the cellular provider and 99% of the time the calls are silenced. Not really an issue for me. The only people that “call” me are in my contacts list anyways. Everyone else can leave a VM or text message.

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#188
Took a while, but this commenter is finally correct:

> Why does Authy require I provide my cell phone number and email address? Why do I have to have a user account? This is completely ridiculous. I do not need nor want cloud syncing or backup. You are making Authy a potential target for attacks by associating a user to cloud stored 2FA information.

> This is not in the spirit of 2FA.

https://news.ycombinator.com/item?id=9100560

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#189

Earlier quoted context omitted.

> I can’t remember the last time I talked on the traditional phone network or received a legitimate call Doctors and dentists. Most of the calls I get are spam, but then the MOST important calls I get are from doctors, labs, and dentists. I do as much as possible online of course, but not all of these professionals have good online systems and phone calls are often required. Sometimes you know what number they're goi…

I recently had to help my father organize his medical visits. Dealing with his healthcare providers was a bit of a pain, but it was way worse because he has stopped answering calls, primarily because of the call spam rate. I think because he owns his own business, he never fails to hand out his contact info when he is shopping, and he owns his own business (so his contact info is published by the city). His phone pro…

Which app did you use ( I seem to have similar issue with my other parent )?

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#190

While this sucks, my phone is in so many data breaches at this point it doesn’t matter. The spam-to-ham ratio on my phone number is now far worse than any other channel for me. The traditional phone network is at risk of going the way of the fax machine if we don’t do something about the spam problem like we did with email. If I’m on a call, even with family, it’s now almost exclusively on FaceTime/zoom/meet/etc. I c…

> If I’m on a call, even with family, it’s now almost exclusively on FaceTime/zoom/meet/etc.

I really don't get that. I don't get these, on neither of my phones (I've got two numbers). When it rings, it's virtually always friends or family. Sometimes the bank/insurance/doctor. Very exceptionally do I get a commercial or scam call.

I think it's not an argument good enough to excuse to excuse Authy here: "my phone already leaked, so what's one more leak!?".

> Which isn’t great because those aforementioned platforms are all proprietary walled gardens with terrible incentives

Oh I fully agree. I'm using Telegram for chat but zero FaceTime/meet/WhatsApp here. People want to call me, they usually phone me. Once in a rare while Telegram.

Post reply on HN