Live data from Hacker News

Twilio confirms data breach after hackers leak 33M Authy user phone numbers

securityweek.com

201–210 of 408 posts

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#201

Earlier quoted context omitted.

Advertising is a cancer on modern society. It will metastasize to any new communications medium, public or private, and destroy it from within. People will switch to new medium that offer less spam, but advertisers quickly follow to strip-mine the new channel. A cycle of life, so to speak.

I don’t have a problem with advertising generally, as long as I know upfront that’s what funds a tool I’m using, and isn’t disguised like a non-ad (eg. Unlike what Google does, which is outright deception). Advertising and spam are two separate things in my book. However, my real problem is with what I call “The Google Strategy.” Basically, they take publicly funded infrastructure like HTTP and SMTP, capture the netw…

> I don’t have a problem with advertising generally

You should, honestly.

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#202

Twilio requires Authy for 2fa for sendgrid and maybe even twilio itself instead of supporting more standardized 2fa that’d allow 1pass to be used. This is all the more frustrating because I was forced to use Authy to protect an account instead of my regular tooling and they still managed to screw it up. Twilio, take a hint and stop forcing people to use your custom thing https://www.twilio.com/docs/sendgrid/ui/accoun…

Ugh. I hate that some apps require use of specific auth apps. This should not be a thing, we have great generic systems for this already.

I just hate that some apps/services require 2FA. My 32 random characters which are unique to each service are secure enough. Adding another service on top just increases risk (as shown here; Authy was never going to do anything to protect me, but it has now leaked info about me.)

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#203

If you've got anything in Authy that isn't using the authy custom authentication scheme (ie. just regular TOTP) now is the time to get it out. Exporting the raw totp tokens can only be done from the desktop version that is currently deprecated and scheduled to be nuked from existence later this year. It requires getting the tokens loaded into the desktop app, then downgrading to an older version so you can use the ch…

> Exporting the raw totp tokens can only be done from the desktop version that is currently deprecated and scheduled to be nuked from existence later this year

Oh. Fucking great. So I'm locked in to using Authy forever now I guess.

I hate 2FA. It literally does exactly nothing for security, it's just another tool for these big companies like Google and Twilio to put themselves between me and the services I need access to, all while locking me in to their services and siphoning out information they can sell to advertisers. I hate it. I hate the "security" people who are pushing this garbage. I hate everyone involved in this space. I hate that I now can't log in to anything without going to fetch my phone. I hate these people.

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#204

Earlier quoted context omitted.

> I can’t remember the last time I talked on the traditional phone network or received a legitimate call Doctors and dentists. Most of the calls I get are spam, but then the MOST important calls I get are from doctors, labs, and dentists. I do as much as possible online of course, but not all of these professionals have good online systems and phone calls are often required. Sometimes you know what number they're goi…

Getting a new, out of state number can sometimes help. My phone is out of state due to my previous address, and 95% of spam i get is spoofed to that old town or the surrounding area. No doctors office/etc calls me from that area. It works pretty nice

> Getting a new, out of state number

The problem with that idea is that when you make local calls, people think that you are the spammer.

I too have an out-of-state number after having moved, and I can definitely confirm that when I make a local call, some people will not pick up after seeing the unusual area code on their caller ID. They told me so.

There's another problem too: Even when I leave voicemail for a local business (plumber, dentist, replying to a "for sale" ad), some people will be thinking, Why does this guy need a plumber or want to buy my kayak if they live 1500 miles away?

I've resorted to leaving an explanation saying "Even though my area code is XYZ, I'm in the same city as you".

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#206

Authy is basically unsupported. Not surprised. I switched my accounts to 1Password when they announced the end of life of the macOS app.

I chose Authy back in the day because that's what everyone was suggesting. I hate it. I hate the whole cyber"security" community.

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#207
post #126

Earlier quoted context omitted.

Has anyone found a single open-source app that supports both mobile and desktop though? That was the attraction of Authy before they killed their desktop apps.

The desktop version somewhat contradicts the purpose of 2FA.

Good thing that 2fa is entirely unnecessary.

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#209
post #121

Earlier quoted context omitted.

What did you end up moving to?

Storing 2FA in Bitwarden (my password manager) and Aegis as a fallback. Also making offline backups of each periodically.

Doesn't Bitwarden require you to be on the paid subscription plan to use 2FA? That's what I concluded anyway from trying to research this garbage when Microsoft was threatening to lock me out of my Github account. It's why I ended up on Authy.

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#210

I have removed all SMS based 2FA from every account that allows it and you should too.

and we should do product liability lawsuits on every service that only allows SMS based one time passwords, if they don't allow a client side only option

Why? 2fa doesn't meaningfully add security if you're using decent passwords, and SMS-based 2fa is no less secure than no 2fa
Post reply on HN