Live data from Hacker News

Twilio confirms data breach after hackers leak 33M Authy user phone numbers

securityweek.com

211–220 of 408 posts

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#211

While this sucks, my phone is in so many data breaches at this point it doesn’t matter. The spam-to-ham ratio on my phone number is now far worse than any other channel for me. The traditional phone network is at risk of going the way of the fax machine if we don’t do something about the spam problem like we did with email. If I’m on a call, even with family, it’s now almost exclusively on FaceTime/zoom/meet/etc. I c…

The solution to phone spam is voicemail transcription. Every call goes to voicemail, I get the transcription in a minute or two, and can call back if I want to.

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#212

While this sucks, my phone is in so many data breaches at this point it doesn’t matter. The spam-to-ham ratio on my phone number is now far worse than any other channel for me. The traditional phone network is at risk of going the way of the fax machine if we don’t do something about the spam problem like we did with email. If I’m on a call, even with family, it’s now almost exclusively on FaceTime/zoom/meet/etc. I c…

The telephone companies make money based on minutes of usage. There is a very large financial incentive for the really big telcos to allow spam calls.

Spam callers are likely the most lucrative customer of the telephone network for the telephone companies.

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#213
post #180

Earlier quoted context omitted.

Why not get a second sim? Most phones can have 2 sims active, and a phone / text only plan is dirt cheap (3-6$/m). Offer the second number with much greater discretion.

I don't know about most phones supporting that, probably depends on the market. But best I can tell, 80% of my spam calls are just war dialing; a new number would get war dialed just as much. Probably wouldn't get collections calls for my deadbeat cousin though.

Physical dual-SIM support is very market based (Popular in Asia).

I believe most reasonably modern phones should support at least one active eSIM in addition to the physical SIM now.

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#214

Earlier quoted context omitted.

Almost no-one is pro-spam, it’s pretty much universally hated, and in many cases it’s already illegal so it’s more of a matter of enforcement. It is also trivial to detect. Sure there probably is some regulatory capture but if anything at all can be regulated it’s spam calls / messages. If the government can’t regulate spam then what could it be expected to regulate. The general population is increasing worried about…

> Almost no-one is pro-spam In fact there are really only two groups that are pro-spam: spammers, obviously, and the entities that provide them services from which they may spam. Oh sure basically any provider of any service be it phone, web hosting, email, etc. will say they don't want spammers, and the email providers may actually mean it what with them not wanting their server's scores trashed and be unable to get…

Not quite. For example politicians benefit from being able to solicit donations over mass text.

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#215
post #126

Earlier quoted context omitted.

Has anyone found a single open-source app that supports both mobile and desktop though? That was the attraction of Authy before they killed their desktop apps.

The desktop version somewhat contradicts the purpose of 2FA.

In this case what if you use 2FA while browsing with your phone. Wouldn't that also contradict the purpose?

The main purpose is that people won't get phished as easily or if they reuse passwords it can't be abused. Or if password was to leak for any reason.

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#216

While this sucks, my phone is in so many data breaches at this point it doesn’t matter. The spam-to-ham ratio on my phone number is now far worse than any other channel for me. The traditional phone network is at risk of going the way of the fax machine if we don’t do something about the spam problem like we did with email. If I’m on a call, even with family, it’s now almost exclusively on FaceTime/zoom/meet/etc. I c…

> I can’t remember the last time I talked on the traditional phone network or received a legitimate call Doctors and dentists. Most of the calls I get are spam, but then the MOST important calls I get are from doctors, labs, and dentists. I do as much as possible online of course, but not all of these professionals have good online systems and phone calls are often required. Sometimes you know what number they're goi…

> I can’t remember the last time I talked on the traditional phone network or received a legitimate call

I think a whole lot more people still make regular phone calls than the ones who don't. Anyone who runs a business for example is usually on the phone ALL the time.

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#217
post #212

While this sucks, my phone is in so many data breaches at this point it doesn’t matter. The spam-to-ham ratio on my phone number is now far worse than any other channel for me. The traditional phone network is at risk of going the way of the fax machine if we don’t do something about the spam problem like we did with email. If I’m on a call, even with family, it’s now almost exclusively on FaceTime/zoom/meet/etc. I c…

The telephone companies make money based on minutes of usage. There is a very large financial incentive for the really big telcos to allow spam calls. Spam callers are likely the most lucrative customer of the telephone network for the telephone companies.

> The telephone companies make money based on minutes of usage.

I don't see how that could be correct. Once you pay your monthly fee, the fewer minutes you tie up the company's resources the better for them. That's true too for pay-ahead plans.

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#218

While this sucks, my phone is in so many data breaches at this point it doesn’t matter. The spam-to-ham ratio on my phone number is now far worse than any other channel for me. The traditional phone network is at risk of going the way of the fax machine if we don’t do something about the spam problem like we did with email. If I’m on a call, even with family, it’s now almost exclusively on FaceTime/zoom/meet/etc. I c…

IMO The problem with data breaches is not the phone number being exposed, it's the other data around it that one can combine with other breaches to make full profiles of a person's comings and goings, their location/purchase history, their associations and preferences, etc.

This is very valuable data to have, not only for advertisers, but also criminals and other bad actors.

Also, the fact that nobody ever questions the authenticity of leaked data should be VERY alarming. Imagine what power someone can hold over someone with manipulated leak data.

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#219

While this sucks, my phone is in so many data breaches at this point it doesn’t matter. The spam-to-ham ratio on my phone number is now far worse than any other channel for me. The traditional phone network is at risk of going the way of the fax machine if we don’t do something about the spam problem like we did with email. If I’m on a call, even with family, it’s now almost exclusively on FaceTime/zoom/meet/etc. I c…

Yet another reason the digital world is marching towards a closed-by-default model.

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#220
post #202

Earlier quoted context omitted.

Ugh. I hate that some apps require use of specific auth apps. This should not be a thing, we have great generic systems for this already.

I just hate that some apps/services require 2FA. My 32 random characters which are unique to each service are secure enough. Adding another service on top just increases risk (as shown here; Authy was never going to do anything to protect me, but it has now leaked info about me.)

No. TOTP MFA’s mechanics make it a significant security improvement regardless of how impressively large (???) your password is. It doesn’t inherently implicate “another service”. That’s the beauty of it. This issue is SPECIFICALLY due to forced use of Authy. Forced MFA for high-value accounts is a good thing. “A long password will protect me” is 2006 thinking.
Post reply on HN