Live data from Hacker News

Twilio confirms data breach after hackers leak 33M Authy user phone numbers

securityweek.com

271–280 of 408 posts

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#271

While this sucks, my phone is in so many data breaches at this point it doesn’t matter. The spam-to-ham ratio on my phone number is now far worse than any other channel for me. The traditional phone network is at risk of going the way of the fax machine if we don’t do something about the spam problem like we did with email. If I’m on a call, even with family, it’s now almost exclusively on FaceTime/zoom/meet/etc. I c…

> While this sucks, my phone is in so many data breaches at this point it doesn’t matter.

Yes, and this is the slope that we keep sliding down with these data breaches not being taken seriously. First it was your name and email. Now phone numbers. What's the next bit of our private info that we'll normalize leaking?

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#273

While this sucks, my phone is in so many data breaches at this point it doesn’t matter. The spam-to-ham ratio on my phone number is now far worse than any other channel for me. The traditional phone network is at risk of going the way of the fax machine if we don’t do something about the spam problem like we did with email. If I’m on a call, even with family, it’s now almost exclusively on FaceTime/zoom/meet/etc. I c…

> I can’t remember the last time I talked on the traditional phone network or received a legitimate call Doctors and dentists. Most of the calls I get are spam, but then the MOST important calls I get are from doctors, labs, and dentists. I do as much as possible online of course, but not all of these professionals have good online systems and phone calls are often required. Sometimes you know what number they're goi…

I have a dedicated phone I use solely for healthcare.

The number in my main phone changes every 90 days.

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#274
post #259

I have resisted moving off Authy as I liked the idea of cross-platform cloud sync. That'll teach me. Any other suitable alternatives? Aegis is android only. I do run vaultwarden, but it means I need another 2FA to login to it, before I can use it as a 2FA for other sites.

2FAS - https://github.com/twofas and I did replaced Authy with it some year ago; I'm using it mainly on iPhone while having a backup file on desktop and second app installed on Samsung phone

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#275
post #267

One major problem I see with this hack is that the phone numbers exposed in the leak is the single factor of authentication needed to get access to an Authy account, including all the MFA tokens that the account has saved. If there are any high-profile victims in this list SIM Swapping those phone numbers should be a very attractive approach. I think security cautious companies should consider turning off multi-devic…

But it's not the single factor?

> There are account recovery options outside of multi-device, but those require the attacker to compromise your primary email. These also take a minimum of 24 hours, during which you would receive email notifications, and could request a cancellation

https://help.twilio.com/articles/19753631468059

And for multi device you can require current device to approve new ones

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#276

And they wonder in random organizations and businesses that I am not willing to give all my personal details right away on first contact despite their 'utmost importance' of handling my data very securely, all this just to be informed about their product. And they seems to be offended with a "but we did it so for many years now" on my refusal and saying goodbye if they try to insist this "company policy". Unluckily s…

British Gas has taken to removing their bank account details from their invoices so that you have to set up an online account with them and then set up a Direct Debit (permission to take arbitrary amounts of money from your UK bank account).

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#277
post #259

I have resisted moving off Authy as I liked the idea of cross-platform cloud sync. That'll teach me. Any other suitable alternatives? Aegis is android only. I do run vaultwarden, but it means I need another 2FA to login to it, before I can use it as a 2FA for other sites.

Could try that FOSS ente app

And there is a FOSS app I forgot the name of to allow exporting Authy tokens from cli

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#278
post #261
post #259

I have resisted moving off Authy as I liked the idea of cross-platform cloud sync. That'll teach me. Any other suitable alternatives? Aegis is android only. I do run vaultwarden, but it means I need another 2FA to login to it, before I can use it as a 2FA for other sites.

Bitwarden released a standalone authenticator app recently. You can give it a try. https://bitwarden.com/blog/bitwarden-just-launched-a-new-aut...

This doesn't sync across devices/os, does it?

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#279

I just migrated off of Authy last week but I was probably caught in this breach, ugh. Never liked it but they make it extremely difficult to export your data. I used this project for exporting: https://github.com/alexzorin/authy EDIT: it appears this project was actually using the unauthenticated endpoint (used in breach, too) to facilitate exporting, lol. Good luck to anyone trying to get off of Authy, Twilio really…

I also just recently left for Aegis and have been very happy. I feel much better knowing that my 2FA is completely offline

Do they offer a device-to-device sync with the desktop? Or is it all gone if you lose your phone?

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#280

Took a while, but this commenter is finally correct: > Why does Authy require I provide my cell phone number and email address? Why do I have to have a user account? This is completely ridiculous. I do not need nor want cloud syncing or backup. You are making Authy a potential target for attacks by associating a user to cloud stored 2FA information. > This is not in the spirit of 2FA. https://news.ycombinator.com/ite…

The entire use case for Authy is the cloud backup and syncing across devices. If you don’t want that, use any of the other free and more open 2FA apps.

[deleted]
Post reply on HN