Live data from Hacker News

Twilio confirms data breach after hackers leak 33M Authy user phone numbers

securityweek.com

251–260 of 408 posts

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#251
post #202

Earlier quoted context omitted.

I just hate that some apps/services require 2FA. My 32 random characters which are unique to each service are secure enough. Adding another service on top just increases risk (as shown here; Authy was never going to do anything to protect me, but it has now leaked info about me.)

No. TOTP MFA’s mechanics make it a significant security improvement regardless of how impressively large (???) your password is. It doesn’t inherently implicate “another service”. That’s the beauty of it. This issue is SPECIFICALLY due to forced use of Authy. Forced MFA for high-value accounts is a good thing. “A long password will protect me” is 2006 thinking.

Well, phishing attacks are still prevelent and it's still at the top for compromising credentials. And phishing attacks have evolved. Most of them will hijack your session, which will make TOTP useless (FIDO will protect you tho)

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#252

Earlier quoted context omitted.

> I can’t remember the last time I talked on the traditional phone network or received a legitimate call Doctors and dentists. Most of the calls I get are spam, but then the MOST important calls I get are from doctors, labs, and dentists. I do as much as possible online of course, but not all of these professionals have good online systems and phone calls are often required. Sometimes you know what number they're goi…

It's high time someone disrupted the damn desk phone network of these hospitals. It's definitely not a technical hurdle in 2024. All calls go on the data network. You route your calls out of the main router and any call that gets routed in such manner will have the ID of the router. Tag the router id to the hospital or hotel and be done with. Is it not this simple ? With dual SIMs any phone can serve 2 lines so emplo…

Or maybe telecommunications in general need disruption. Instead of having a number that anyone in the world can call, I should provide an abstract identity to a contact. When I approve that entity to contact me, and they get a unique identifier that only their identity can use to contact me, I decide how important their calls are to me:

1. Phone rings no matter what (doctors and other high profile contacts that I do not want to miss a call from)

2. Phone rings unless sleep mode active (family/friends). A second call within 3 minutes rings through in case of emergency.

3. Call goes straight to pre-recorded message (generic or unique to that identity) that tells them to text me their message/request (or when AI gets good enough, and it doesn't seem like it there yet for all accents, it transcribes their voicemail message).

4. Caller can leave a message but it is completely ignored by me and I don't know they left a message unless I go and check my spam folder.

I can change the call handling of any identity at any time, and there should also be an email and text message layer on top of this system so the same rules apply and I choose who can contact me with those methods as well.

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#253

Earlier quoted context omitted.

No. TOTP MFA’s mechanics make it a significant security improvement regardless of how impressively large (???) your password is. It doesn’t inherently implicate “another service”. That’s the beauty of it. This issue is SPECIFICALLY due to forced use of Authy. Forced MFA for high-value accounts is a good thing. “A long password will protect me” is 2006 thinking.

Well, phishing attacks are still prevelent and it's still at the top for compromising credentials. And phishing attacks have evolved. Most of them will hijack your session, which will make TOTP useless (FIDO will protect you tho)

I just don’t buy the argument that because most sophisticated attacks exist, then 2FA isn’t useful.

2FA protects you from someone getting access to a leaked password. They still can’t connect even with user and password, without doing a very elaborate hack. That’s a huge benefit.

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#254

While this sucks, my phone is in so many data breaches at this point it doesn’t matter. The spam-to-ham ratio on my phone number is now far worse than any other channel for me. The traditional phone network is at risk of going the way of the fax machine if we don’t do something about the spam problem like we did with email. If I’m on a call, even with family, it’s now almost exclusively on FaceTime/zoom/meet/etc. I c…

The phone network we once knew is useless in terms of answering or bothering with any calls or text from those not in your contacts. If you do .. you do so at your own risk!

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#255

When I tried SendGrid it was super annoying that I had to install yet another Authenticator app on my phone. Now it’s become a point of data loss. It’s bizarre to me that Twilio decided to get into the Authenticator business at all, especially while SendGrid had plenty enough problems to keep them busy.

What are some of the SendGrid problems you're thinking about?

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#256
post #241

Earlier quoted context omitted.

I do basically this with a subscription to MySudo. I always get funny looks when giving out a number, living in a small town people are surprised when it isn't one of the two or three area codes around here. It works like a charm though. I have three tiers of numbers - one that I'll keep and goes to only friends and family, one that I will likely keep for a couple years until it starts getting too much spam, and a th…

Distant area code SIMs do wonders. I was still living in Vancouver, Canada when I learned maybe six or so years ago AT&T has removed all roaming restrictions in North America. So a few of us banded together, one of us crossed over to New York picked up a group subscription of sorts and we had very cheap subscriptions. Only the last 1-2 years did Canadian providers caught up, somewhat. But the real advantage was if an…

Reminds me of my parents... they live close enough to the US border that they just have a US cell phone plan. The plan is $50/mo/line USD and includes unlimited data/calling/text in Canada/US/Mexico. But because they live so close they're not actually roaming most of the time, and they're snow birds so they're in the US half the year anyway. They found the same thing as you... any calls from the same area code as their phone numbers was definitely not for them since it was somewhere very far away and they don't have any business there.

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#257

Earlier quoted context omitted.

> Getting a new, out of state number The problem with that idea is that when you make local calls, people think that you are the spammer. I too have an out-of-state number after having moved, and I can definitely confirm that when I make a local call, some people will not pick up after seeing the unusual area code on their caller ID. They told me so. There's another problem too: Even when I leave voicemail for a loca…

Almost all of the spam calls I receive have the same area code as my phone, which is in a different state from where I currently live. These people who don't pick up for an unusual area code: don't they know that spammers are more likely to call from a "usual" area code? Am I mistaken?

Exactly, and not just the same area code, the spammers often have the same prefix as my phone number too... so it looks like someone "just around the corner".

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#258

Earlier quoted context omitted.

I recently had to help my father organize his medical visits. Dealing with his healthcare providers was a bit of a pain, but it was way worse because he has stopped answering calls, primarily because of the call spam rate. I think because he owns his own business, he never fails to hand out his contact info when he is shopping, and he owns his own business (so his contact info is published by the city). His phone pro…

I have a business with a published phone number and I probably get 20 spam calls a day, at least half of which leave “voicemails,” some of which are just really loud high pitched noises for whatever reason. It’s absolutely ridiculous. I wish I would have used a different number than my personal one back when I had started.

If our government can’t protect us from spam calls, how can they can protect us from anything else?

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#259
I have resisted moving off Authy as I liked the idea of cross-platform cloud sync. That'll teach me. Any other suitable alternatives? Aegis is android only. I do run vaultwarden, but it means I need another 2FA to login to it, before I can use it as a 2FA for other sites.

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#260
post #202

Earlier quoted context omitted.

I just hate that some apps/services require 2FA. My 32 random characters which are unique to each service are secure enough. Adding another service on top just increases risk (as shown here; Authy was never going to do anything to protect me, but it has now leaked info about me.)

No. TOTP MFA’s mechanics make it a significant security improvement regardless of how impressively large (???) your password is. It doesn’t inherently implicate “another service”. That’s the beauty of it. This issue is SPECIFICALLY due to forced use of Authy. Forced MFA for high-value accounts is a good thing. “A long password will protect me” is 2006 thinking.

> Forced MFA for high-value accounts is a good thing.

No. I agree the MFA is big improvement and I use it for many of my accounts, but I still don't want you forcing me to do something "for my own good".

Make it the default or show me scary warnings, but still give me the option to make my own decision in the end. Sometimes, it's okay for convenience to take precedence over security, and the user is the only one who should make that determination.

Post reply on HN