Live data from Hacker News

Twilio confirms data breach after hackers leak 33M Authy user phone numbers

securityweek.com

261–270 of 408 posts

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#261
post #259

I have resisted moving off Authy as I liked the idea of cross-platform cloud sync. That'll teach me. Any other suitable alternatives? Aegis is android only. I do run vaultwarden, but it means I need another 2FA to login to it, before I can use it as a 2FA for other sites.

Bitwarden released a standalone authenticator app recently. You can give it a try.

https://bitwarden.com/blog/bitwarden-just-launched-a-new-aut...

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#262
post #203

Earlier quoted context omitted.

> Exporting the raw totp tokens can only be done from the desktop version that is currently deprecated and scheduled to be nuked from existence later this year Oh. Fucking great. So I'm locked in to using Authy forever now I guess. I hate 2FA. It literally does exactly nothing for security, it's just another tool for these big companies like Google and Twilio to put themselves between me and the services I need acces…

Haha, I see you manically rage posting in this topic. I empathise, it's fucking shit when "smart" people foist something unwanted on you because they think it's better for you. FWIW, I'm feeling pretty liberated to have moved my OTP codes out of authy and into multiple locations - my data, as much as I'd prefer not to use it, is now under my control. You can get the old desktop version from chocolatey/choco - https:/…

Great comment. Authy seems to be taking a user hostile stance by taking hostage peoples OTP's this way.

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#263

Twilio requires Authy for 2fa for sendgrid and maybe even twilio itself instead of supporting more standardized 2fa that’d allow 1pass to be used. This is all the more frustrating because I was forced to use Authy to protect an account instead of my regular tooling and they still managed to screw it up. Twilio, take a hint and stop forcing people to use your custom thing https://www.twilio.com/docs/sendgrid/ui/accoun…

Even worse.. 2FA is mandatory on Twilio products, so either install authy or don't use Twilio - no exceptions.

I use a normal authenticator app which is not Authy.

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#264

Took a while, but this commenter is finally correct: > Why does Authy require I provide my cell phone number and email address? Why do I have to have a user account? This is completely ridiculous. I do not need nor want cloud syncing or backup. You are making Authy a potential target for attacks by associating a user to cloud stored 2FA information. > This is not in the spirit of 2FA. https://news.ycombinator.com/ite…

You can't pick and choose "Not a real scotsman" since 99% of users will be on bigcorp 2FA that does it in most ass-backwards way possible. 2FA as mobile apps locked to hardware is not going to go away without 2FA being replaced by something else.

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#265

While this sucks, my phone is in so many data breaches at this point it doesn’t matter. The spam-to-ham ratio on my phone number is now far worse than any other channel for me. The traditional phone network is at risk of going the way of the fax machine if we don’t do something about the spam problem like we did with email. If I’m on a call, even with family, it’s now almost exclusively on FaceTime/zoom/meet/etc. I c…

IMO The problem with data breaches is not the phone number being exposed, it's the other data around it that one can combine with other breaches to make full profiles of a person's comings and goings, their location/purchase history, their associations and preferences, etc. This is very valuable data to have, not only for advertisers, but also criminals and other bad actors. Also, the fact that nobody ever questions…

Doesn’t even have to be manipulated just incorrect. I share a rather uncommon name with at least two others within five years of my age. I get emails intended for either of them almost daily. One holds political views completely opposite my own. The other is rebuilding his life after a couple years in prison.

I would rather not have my own life intertwined with either of them but undoubtedly it already is to some degree.

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#266

Took a while, but this commenter is finally correct: > Why does Authy require I provide my cell phone number and email address? Why do I have to have a user account? This is completely ridiculous. I do not need nor want cloud syncing or backup. You are making Authy a potential target for attacks by associating a user to cloud stored 2FA information. > This is not in the spirit of 2FA. https://news.ycombinator.com/ite…

The entire use case for Authy is the cloud backup and syncing across devices. If you don’t want that, use any of the other free and more open 2FA apps.

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#267
One major problem I see with this hack is that the phone numbers exposed in the leak is the single factor of authentication needed to get access to an Authy account, including all the MFA tokens that the account has saved.

If there are any high-profile victims in this list SIM Swapping those phone numbers should be a very attractive approach.

I think security cautious companies should consider turning off multi-device support and start planning for a migration. This leak feels way riskier to me than what media reports it to be.

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#268
post #259

I have resisted moving off Authy as I liked the idea of cross-platform cloud sync. That'll teach me. Any other suitable alternatives? Aegis is android only. I do run vaultwarden, but it means I need another 2FA to login to it, before I can use it as a 2FA for other sites.

KeePassXC (and the associated apps) can store TOTP, and you can sync it with SyncThing on any device. Add an always-on NAS with SyncThing and you'll always have an up-to-date vault, even when your other devices are offline.

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#269

Earlier quoted context omitted.

> I can’t remember the last time I talked on the traditional phone network or received a legitimate call Doctors and dentists. Most of the calls I get are spam, but then the MOST important calls I get are from doctors, labs, and dentists. I do as much as possible online of course, but not all of these professionals have good online systems and phone calls are often required. Sometimes you know what number they're goi…

It's high time someone disrupted the damn desk phone network of these hospitals. It's definitely not a technical hurdle in 2024. All calls go on the data network. You route your calls out of the main router and any call that gets routed in such manner will have the ID of the router. Tag the router id to the hospital or hotel and be done with. Is it not this simple ? With dual SIMs any phone can serve 2 lines so emplo…

It's an american problem. Spam calls aren't a big issue in Germany.

Complain to your government.

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#270

While this sucks, my phone is in so many data breaches at this point it doesn’t matter. The spam-to-ham ratio on my phone number is now far worse than any other channel for me. The traditional phone network is at risk of going the way of the fax machine if we don’t do something about the spam problem like we did with email. If I’m on a call, even with family, it’s now almost exclusively on FaceTime/zoom/meet/etc. I c…

I'm an European and I get zero spam calls.

I used to get a couple of cold calls per year for surveys, but I got unlisted via GDPR requests and now its down to zero.

Companies do try collecting your phone number, but then I answer NO to the obligatory "do you want the latest offers" question (in the EU, this is opt-in not opt-out). And it doesn't matter if my phone number leaks.

This is similar to my email address use. I used to get emails from recruiters, but after a couple of replies informing them that whatever profile they have is illegal, with my email address not being public, asking them to delete it, the emails stopped. I still get spam, but it's mostly fraud and US companies. Fastmail's spam filters are good enough, BTW.

My phone number works just fine, and the phone network is valuable given the better signal 2G can have, or the fact that not everyone is on the app du jour. And I find it odd when people call me on WhatsApp.

I frequently see US folks criticising GDPR, so I'm guessing this is one of those "the US mind can't comprehend" moments.

Post reply on HN