Live data from Hacker News

Twilio confirms data breach after hackers leak 33M Authy user phone numbers

securityweek.com

221–230 of 408 posts

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#221

Earlier quoted context omitted.

I recently had to help my father organize his medical visits. Dealing with his healthcare providers was a bit of a pain, but it was way worse because he has stopped answering calls, primarily because of the call spam rate. I think because he owns his own business, he never fails to hand out his contact info when he is shopping, and he owns his own business (so his contact info is published by the city). His phone pro…

I haven't answered my phone for anyone not in my VIP list in a year or two. I can see when someone is calling and in realtime see them leaving a voicemail via speech-to-text and pick up the call if I want but 99.999% of the time it's spam.

Th topic of this subthread is exactly that one cannot rely on the contact list method because doctors may call from any unknown number. Maybe you haven’t had to deal with that (yet), but once you do you’ll realize that your method doesn’t work for that.

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#223

While this sucks, my phone is in so many data breaches at this point it doesn’t matter. The spam-to-ham ratio on my phone number is now far worse than any other channel for me. The traditional phone network is at risk of going the way of the fax machine if we don’t do something about the spam problem like we did with email. If I’m on a call, even with family, it’s now almost exclusively on FaceTime/zoom/meet/etc. I c…

> If I’m on a call, even with family, it’s now almost exclusively on FaceTime/zoom/meet/etc. I really don't get that. I don't get these, on neither of my phones (I've got two numbers). When it rings, it's virtually always friends or family. Sometimes the bank/insurance/doctor. Very exceptionally do I get a commercial or scam call. I think it's not an argument good enough to excuse to excuse Authy here: "my phone alre…

I have 5+ spam calls every day. Looking at my call history it’s been that way as far back as it lets me scroll. Blocking doesn’t make a ton of difference, as it’s almost always a different number.

I don’t understand what they are calling for either. I’ve answered a few and most of the time it’s a dead line when I answer. Just silence.

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#224

Earlier quoted context omitted.

Getting a new, out of state number can sometimes help. My phone is out of state due to my previous address, and 95% of spam i get is spoofed to that old town or the surrounding area. No doctors office/etc calls me from that area. It works pretty nice

> Getting a new, out of state number The problem with that idea is that when you make local calls, people think that you are the spammer. I too have an out-of-state number after having moved, and I can definitely confirm that when I make a local call, some people will not pick up after seeing the unusual area code on their caller ID. They told me so. There's another problem too: Even when I leave voicemail for a loca…

> Even though my area code is XYZ, I'm in the same city as you

The area code wouldn’t be a red flag for me, but this absolutely would.

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#225
post #150

> Twilio has detected that threat actors were able to identify data associated with Authy accounts, including phone numbers, due to an unauthenticated endpoint. We have taken action to secure this endpoint and no longer allow unauthenticated requests How do I avoid such problems in my own app? Force authentication for all requests with row-level security? Rate limiting? Any testing frameworks that would catch this? S…

Holy shit why is this even a question?? You. Write. Tests. You build into your testing framework/library a mechanism that will craft sessions across your range of authentication-levels - unauthenticated (no-session), authenticated but unauthorized, etc. You mandate new endpoints must have permissions test in code review. Simple, straight forward, and absolutely the bare minimum of competency for any endpoint returnin…

And then someone forgets to test that one thing for that one endpoint and no one notices ("mandate in code review" is not going to be fool-proof), or lines get crossed and they test the wrong thing.

This kind of arrogance is exactly how these mistakes get made.

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#226
post #196

While this sucks, my phone is in so many data breaches at this point it doesn’t matter. The spam-to-ham ratio on my phone number is now far worse than any other channel for me. The traditional phone network is at risk of going the way of the fax machine if we don’t do something about the spam problem like we did with email. If I’m on a call, even with family, it’s now almost exclusively on FaceTime/zoom/meet/etc. I c…

> I can’t remember the last time I talked on the traditional phone network or received a legitimate call Doctors, dentists, moving companies, home improvement contractors, recruiters, etc. These are some of the most important phone calls I've received in recent memory. I don't know what world you live in, but I religiously block phone numbers after just one spam call. And I usually don't give out my phone number. (I'…

Agreed. Phone calls are quite common in my circle. Spam calls have definitely risen in the last 10 years, but the ratio is nothing like the GP.

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#227

Earlier quoted context omitted.

I recently had to help my father organize his medical visits. Dealing with his healthcare providers was a bit of a pain, but it was way worse because he has stopped answering calls, primarily because of the call spam rate. I think because he owns his own business, he never fails to hand out his contact info when he is shopping, and he owns his own business (so his contact info is published by the city). His phone pro…

Why not get a second sim? Most phones can have 2 sims active, and a phone / text only plan is dirt cheap (3-6$/m). Offer the second number with much greater discretion.

I do basically this with a subscription to MySudo. I always get funny looks when giving out a number, living in a small town people are surprised when it isn't one of the two or three area codes around here.

It works like a charm though. I have three tiers of numbers - one that I'll keep and goes to only friends and family, one that I will likely keep for a couple years until it starts getting too much spam, and a third tier that I cycle regularly and use for one off things like online orders.

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#228
post #132

While this sucks, my phone is in so many data breaches at this point it doesn’t matter. The spam-to-ham ratio on my phone number is now far worse than any other channel for me. The traditional phone network is at risk of going the way of the fax machine if we don’t do something about the spam problem like we did with email. If I’m on a call, even with family, it’s now almost exclusively on FaceTime/zoom/meet/etc. I c…

How convenient for the data collecting companies that so generously sponsor the new & free services, that our democratically controlled communication infrastructure looses in value.

Is our communication infrastructure democratically controlled? At least in the US, we may have federal regulators but isn't the infrastructure still owned by a few massive telecoms corporations?

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#229

Earlier quoted context omitted.

Advertising is a cancer on modern society. It will metastasize to any new communications medium, public or private, and destroy it from within. People will switch to new medium that offer less spam, but advertisers quickly follow to strip-mine the new channel. A cycle of life, so to speak.

It’s also so annoying circular. We spend money to get more clients but this stops being effective at a certain point so now you’re just spending money to advertise for the sake of it or the status, and could even be losing money by doing so.

In my experience, the fear of missing out is a big driver for companies to continue to throw good money after bad in marketing. Maybe Facebook ads aren't driving as much traffic to your company as it used to, but if you give it up and all your competitors still use it it's pretty understandable to worry about falling behind the market.

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#230
post #132

Earlier quoted context omitted.

How convenient for the data collecting companies that so generously sponsor the new & free services, that our democratically controlled communication infrastructure looses in value.

"Our democratically controlled communication infrastructure" honestly deserves to be deprecated and replaced with some kind of federated voice system that comes out of the IETF instead of the telcos. What kind of antediluvian nonsense doesn't use end-to-end encryption in 2024?

AT&T has a long history with three letter agencies. If they ever did implement e2e encryption it would certainly come with backdoors that make it e2e only by name.
Post reply on HN