Live data from Hacker News

Twilio confirms data breach after hackers leak 33M Authy user phone numbers

securityweek.com

231–240 of 408 posts

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#231

Earlier quoted context omitted.

> If I’m on a call, even with family, it’s now almost exclusively on FaceTime/zoom/meet/etc. I really don't get that. I don't get these, on neither of my phones (I've got two numbers). When it rings, it's virtually always friends or family. Sometimes the bank/insurance/doctor. Very exceptionally do I get a commercial or scam call. I think it's not an argument good enough to excuse to excuse Authy here: "my phone alre…

i'm jealous of you. I recently had a day where I got 25 phone calls. 23 were spam. Turning on iOS "ignore unrecognize phone numbers" has been amazing (i assume android has the same feature)

Occasionally I'll get spam from numbers in my contacts. I got a virtual kidnapping call from my wife's number the other day, which would have been terrifying if she wasn't sitting right next to me.

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#232
post #180

Earlier quoted context omitted.

Why not get a second sim? Most phones can have 2 sims active, and a phone / text only plan is dirt cheap (3-6$/m). Offer the second number with much greater discretion.

I don't know about most phones supporting that, probably depends on the market. But best I can tell, 80% of my spam calls are just war dialing; a new number would get war dialed just as much. Probably wouldn't get collections calls for my deadbeat cousin though.

That's the worst! I had a collection agency keep calling consistently for a particular family member.

I got fed up, told the caller that I hadn't seen her in years and she could be dead in a ditch for all I knew, then asked if he could call me if he got a hold of her.

They never called again.

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#233

Earlier quoted context omitted.

"Our democratically controlled communication infrastructure" honestly deserves to be deprecated and replaced with some kind of federated voice system that comes out of the IETF instead of the telcos. What kind of antediluvian nonsense doesn't use end-to-end encryption in 2024?

AT&T has a long history with three letter agencies. If they ever did implement e2e encryption it would certainly come with backdoors that make it e2e only by name.

All the more reason to have the IETF do it and leave AT&T out of it.

Any modern system is going to use IP as a transport. Even the traditional phone network is VoIP under the hood in modern networks. The replacement system should be kept as far from the influence of the last mile providers as possible.

The thing that definitely shouldn't happen is that you get your phone number from them. Let it be "user@host" like email or otherwise assigned via DNS.

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#234
post #221

Earlier quoted context omitted.

I haven't answered my phone for anyone not in my VIP list in a year or two. I can see when someone is calling and in realtime see them leaving a voicemail via speech-to-text and pick up the call if I want but 99.999% of the time it's spam.

Th topic of this subthread is exactly that one cannot rely on the contact list method because doctors may call from any unknown number. Maybe you haven’t had to deal with that (yet), but once you do you’ll realize that your method doesn’t work for that.

Same with home repair contractors. The person coming over to do the work is unlikely to call from the same number the business hands out that rings an office manager or the owner. Same goes for the person calling me back with an estimate I requested.

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#235

Earlier quoted context omitted.

I recently had to help my father organize his medical visits. Dealing with his healthcare providers was a bit of a pain, but it was way worse because he has stopped answering calls, primarily because of the call spam rate. I think because he owns his own business, he never fails to hand out his contact info when he is shopping, and he owns his own business (so his contact info is published by the city). His phone pro…

Why not get a second sim? Most phones can have 2 sims active, and a phone / text only plan is dirt cheap (3-6$/m). Offer the second number with much greater discretion.

That doesn't always work. A lot of phone numbers out there are "dirty": they are on various marketing lists and will get spam calls and texts.

Some carriers do try to keep excessively dirty numbers inactive for a while after a customer cancels a plan and returns the number, in the hopes that the spam will fall off after to many "this number is disconnected" responses.

But sometimes they don't bother, and sometimes it just doesn't help all that much, because spammers are just running through the phone number space.

This is a long way of saying that even getting a new number doesn't always work. The number you end up with might already be inundated with spam.

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#236
post #132

Earlier quoted context omitted.

How convenient for the data collecting companies that so generously sponsor the new & free services, that our democratically controlled communication infrastructure looses in value.

Advertising is a cancer on modern society. It will metastasize to any new communications medium, public or private, and destroy it from within. People will switch to new medium that offer less spam, but advertisers quickly follow to strip-mine the new channel. A cycle of life, so to speak.

Agreed. Advertising is psychological manipulation. I would be happy if all forms of it were just outlawed.

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#237

Earlier quoted context omitted.

> If I’m on a call, even with family, it’s now almost exclusively on FaceTime/zoom/meet/etc. I really don't get that. I don't get these, on neither of my phones (I've got two numbers). When it rings, it's virtually always friends or family. Sometimes the bank/insurance/doctor. Very exceptionally do I get a commercial or scam call. I think it's not an argument good enough to excuse to excuse Authy here: "my phone alre…

I have 5+ spam calls every day. Looking at my call history it’s been that way as far back as it lets me scroll. Blocking doesn’t make a ton of difference, as it’s almost always a different number. I don’t understand what they are calling for either. I’ve answered a few and most of the time it’s a dead line when I answer. Just silence.

Those are usually robo dialers looking for active numbers to resell to spammers/scammers. You answering puts you on their good list. These are also the calls that never leave any type of voicemail. I’m not sure what list VM gets you on.

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#238

While this sucks, my phone is in so many data breaches at this point it doesn’t matter. The spam-to-ham ratio on my phone number is now far worse than any other channel for me. The traditional phone network is at risk of going the way of the fax machine if we don’t do something about the spam problem like we did with email. If I’m on a call, even with family, it’s now almost exclusively on FaceTime/zoom/meet/etc. I c…

> I can’t remember the last time I talked on the traditional phone network or received a legitimate call Doctors and dentists. Most of the calls I get are spam, but then the MOST important calls I get are from doctors, labs, and dentists. I do as much as possible online of course, but not all of these professionals have good online systems and phone calls are often required. Sometimes you know what number they're goi…

It's high time someone disrupted the damn desk phone network of these hospitals. It's definitely not a technical hurdle in 2024. All calls go on the data network. You route your calls out of the main router and any call that gets routed in such manner will have the ID of the router. Tag the router id to the hospital or hotel and be done with.

Is it not this simple ? With dual SIMs any phone can serve 2 lines so employees officially switch to the hospital e-sim within the hospital premises.

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#239

Jesus fucking Christ. Can these companies learn how to write software? Quality is dropping like dogs. Twilio used to be a good company and now they are utter shite. Such a shame. Leetcode and bad hiring practices have done this to our industry.

Agile practices and the elimination of proper QA are also part of the problem.

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#240
post #202

Earlier quoted context omitted.

I just hate that some apps/services require 2FA. My 32 random characters which are unique to each service are secure enough. Adding another service on top just increases risk (as shown here; Authy was never going to do anything to protect me, but it has now leaked info about me.)

No. TOTP MFA’s mechanics make it a significant security improvement regardless of how impressively large (???) your password is. It doesn’t inherently implicate “another service”. That’s the beauty of it. This issue is SPECIFICALLY due to forced use of Authy. Forced MFA for high-value accounts is a good thing. “A long password will protect me” is 2006 thinking.

What happens when you lose your phone then?

Do you have recovery code printed out? Do you carry them with you? If you do then what's the difference between this and a password?

Post reply on HN