Live data from Hacker News

Twilio confirms data breach after hackers leak 33M Authy user phone numbers

securityweek.com

241–250 of 408 posts

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#241

Earlier quoted context omitted.

Why not get a second sim? Most phones can have 2 sims active, and a phone / text only plan is dirt cheap (3-6$/m). Offer the second number with much greater discretion.

I do basically this with a subscription to MySudo. I always get funny looks when giving out a number, living in a small town people are surprised when it isn't one of the two or three area codes around here. It works like a charm though. I have three tiers of numbers - one that I'll keep and goes to only friends and family, one that I will likely keep for a couple years until it starts getting too much spam, and a th…

Distant area code SIMs do wonders.

I was still living in Vancouver, Canada when I learned maybe six or so years ago AT&T has removed all roaming restrictions in North America. So a few of us banded together, one of us crossed over to New York picked up a group subscription of sorts and we had very cheap subscriptions. Only the last 1-2 years did Canadian providers caught up, somewhat.

But the real advantage was if anyone called from a "local" number, local to my SIM at least, I immediately knew it was spam. I do not know anyone in Buffalo, I do not do business in Buffalo, there's no authority which has anything to do with me there, nothing. It's spam.

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#242

Took a while, but this commenter is finally correct: > Why does Authy require I provide my cell phone number and email address? Why do I have to have a user account? This is completely ridiculous. I do not need nor want cloud syncing or backup. You are making Authy a potential target for attacks by associating a user to cloud stored 2FA information. > This is not in the spirit of 2FA. https://news.ycombinator.com/ite…

[deleted]

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#243
post #209

Earlier quoted context omitted.

Storing 2FA in Bitwarden (my password manager) and Aegis as a fallback. Also making offline backups of each periodically.

Doesn't Bitwarden require you to be on the paid subscription plan to use 2FA? That's what I concluded anyway from trying to research this garbage when Microsoft was threatening to lock me out of my Github account. It's why I ended up on Authy.

> Doesn't Bitwarden require you to be on the paid subscription plan to use 2FA?

I believe they do, yes. Been on the $10/year plan and have forgotten the details on their tiers, though.

> It's why I ended up on Authy.

All 2FA really boils down to is a "otpauth://totp" URL that clients use to generate time based tokens. Once you have those exported somewhere, you can move to any TOTP app you want (desktop or mobile)

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#244
post #203

If you've got anything in Authy that isn't using the authy custom authentication scheme (ie. just regular TOTP) now is the time to get it out. Exporting the raw totp tokens can only be done from the desktop version that is currently deprecated and scheduled to be nuked from existence later this year. It requires getting the tokens loaded into the desktop app, then downgrading to an older version so you can use the ch…

> Exporting the raw totp tokens can only be done from the desktop version that is currently deprecated and scheduled to be nuked from existence later this year Oh. Fucking great. So I'm locked in to using Authy forever now I guess. I hate 2FA. It literally does exactly nothing for security, it's just another tool for these big companies like Google and Twilio to put themselves between me and the services I need acces…

Haha, I see you manically rage posting in this topic. I empathise, it's fucking shit when "smart" people foist something unwanted on you because they think it's better for you. FWIW, I'm feeling pretty liberated to have moved my OTP codes out of authy and into multiple locations - my data, as much as I'd prefer not to use it, is now under my control.

You can get the old desktop version from chocolatey/choco - https://community.chocolatey.org/packages/authy-desktop/

If anyone wants to try this themselves, this is the recipe that worked for me;

- Enable multi device for authy on my phone

- Install the 3.0 desktop authy client from chocolatey

- Get logged in and set up on the desktop client so that you can see the current OTP codes (not the lock symbol)

- Uninstall the 3.0.0 desktop authy client

- Install the 2.2.3 desktop authy client from chocolatey (https://community.chocolatey.org/packages/authy-desktop/2.2.... or choco install authy-desktop --version=2.2.3)

- DISCONNECT FROM THE INTERNET AFTER OPENING 2.2.3 AND BEFORE IT POPS THE UPDATE DIALOG

- The update dialog will block the program and you can't use the chrome remote debugger in the later steps

- Start from step 2 of https://gist.github.com/gboudreau/94bb0c11a6209c82418d01a59d...

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#247

Earlier quoted context omitted.

Getting a new, out of state number can sometimes help. My phone is out of state due to my previous address, and 95% of spam i get is spoofed to that old town or the surrounding area. No doctors office/etc calls me from that area. It works pretty nice

> Getting a new, out of state number The problem with that idea is that when you make local calls, people think that you are the spammer. I too have an out-of-state number after having moved, and I can definitely confirm that when I make a local call, some people will not pick up after seeing the unusual area code on their caller ID. They told me so. There's another problem too: Even when I leave voicemail for a loca…

I moved from British Columbia (250 area code) to the Montreal suburbs (450 area code). The one digit difference was a huge issue: the number of times businesses and government agencies would helpfully "correct" my phone number when I gave it to them or when they tried to call it meant I missed a substantial number of important phone calls. I get it, my French isn't the greatest and I have a thick Anglo accent, but "deux cinq zéro" sounds very different from "quatre cinq zéro." Eventually I just gave up and got a local number (I ported my old one to VOIP.ms and forwarded it so I wouldn't miss calls).

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#248

Earlier quoted context omitted.

> I can’t remember the last time I talked on the traditional phone network or received a legitimate call Doctors and dentists. Most of the calls I get are spam, but then the MOST important calls I get are from doctors, labs, and dentists. I do as much as possible online of course, but not all of these professionals have good online systems and phone calls are often required. Sometimes you know what number they're goi…

I recently had to help my father organize his medical visits. Dealing with his healthcare providers was a bit of a pain, but it was way worse because he has stopped answering calls, primarily because of the call spam rate. I think because he owns his own business, he never fails to hand out his contact info when he is shopping, and he owns his own business (so his contact info is published by the city). His phone pro…

I have a business with a published phone number and I probably get 20 spam calls a day, at least half of which leave “voicemails,” some of which are just really loud high pitched noises for whatever reason.

It’s absolutely ridiculous. I wish I would have used a different number than my personal one back when I had started.

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#249

Earlier quoted context omitted.

No. TOTP MFA’s mechanics make it a significant security improvement regardless of how impressively large (???) your password is. It doesn’t inherently implicate “another service”. That’s the beauty of it. This issue is SPECIFICALLY due to forced use of Authy. Forced MFA for high-value accounts is a good thing. “A long password will protect me” is 2006 thinking.

What happens when you lose your phone then? Do you have recovery code printed out? Do you carry them with you? If you do then what's the difference between this and a password?

Not the parent, but I write recovery codes down and store in a safe at my home.

The difference compared to a password is that these recovery codes are single use, used only in exceptional cases and physically airgapped. On the other hand my password is multi use, is used daily by me and in the event of a breach will be exposed to the attacker.

I will know if someone steals my recovery codes. I'll have no idea if someone gains knowledge of my password though.

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#250

Earlier quoted context omitted.

Getting a new, out of state number can sometimes help. My phone is out of state due to my previous address, and 95% of spam i get is spoofed to that old town or the surrounding area. No doctors office/etc calls me from that area. It works pretty nice

> Getting a new, out of state number The problem with that idea is that when you make local calls, people think that you are the spammer. I too have an out-of-state number after having moved, and I can definitely confirm that when I make a local call, some people will not pick up after seeing the unusual area code on their caller ID. They told me so. There's another problem too: Even when I leave voicemail for a loca…

Almost all of the spam calls I receive have the same area code as my phone, which is in a different state from where I currently live.

These people who don't pick up for an unusual area code: don't they know that spammers are more likely to call from a "usual" area code? Am I mistaken?

Post reply on HN