Live data from Hacker News

Twilio confirms data breach after hackers leak 33M Authy user phone numbers

securityweek.com

301–310 of 408 posts

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#301
post #282
post #206

Earlier quoted context omitted.

I chose Authy back in the day because that's what everyone was suggesting. I hate it. I hate the whole cyber"security" community.

> I hate the whole cyber"security" community. Why do you hate the whole community?

Because it's them who have pushed so hard for this 2fa mess.

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#302
post #269

Earlier quoted context omitted.

It's high time someone disrupted the damn desk phone network of these hospitals. It's definitely not a technical hurdle in 2024. All calls go on the data network. You route your calls out of the main router and any call that gets routed in such manner will have the ID of the router. Tag the router id to the hospital or hotel and be done with. Is it not this simple ? With dual SIMs any phone can serve 2 lines so emplo…

It's an american problem. Spam calls aren't a big issue in Germany. Complain to your government.

It’s a huge problem in India. 10 times worse than US.

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#303
post #186
post #179

Earlier quoted context omitted.

Is this like an American thing? I'm in the Netherlands and i get like 1 spam call per two months (business internet/electricity salesperson usually)

America doesn’t have privacy laws that prevent robot spam. Repercussions for violating the SPAM Act are not prosecuted very often. Personally, the only “spam” I get is flagged by the cellular provider and 99% of the time the calls are silenced. Not really an issue for me. The only people that “call” me are in my contacts list anyways. Everyone else can leave a VM or text message.

It's also far, far cheaper to make calls to US mobiles than mobiles in any other developed country. Like call termination to an EU mobile is 10x+ than a US mobile.

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#304

Earlier quoted context omitted.

I'm an European and I get zero spam calls. I used to get a couple of cold calls per year for surveys, but I got unlisted via GDPR requests and now its down to zero. Companies do try collecting your phone number, but then I answer NO to the obligatory "do you want the latest offers" question (in the EU, this is opt-in not opt-out). And it doesn't matter if my phone number leaks. This is similar to my email address use…

>And I find it odd when people call me on WhatsApp. Given that you're European, do you not have any friends/family outside your country, in neighboring EU countries? Wouldn't they have to pay high per-minute rates to call you?

https://mobile.free.fr/fiche-forfait-free

Example from one provider: nope with 100 countries. Including the US, Canada, China etc.

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#305
post #304

Earlier quoted context omitted.

>And I find it odd when people call me on WhatsApp. Given that you're European, do you not have any friends/family outside your country, in neighboring EU countries? Wouldn't they have to pay high per-minute rates to call you?

https://mobile.free.fr/fiche-forfait-free Example from one provider: nope with 100 countries. Including the US, Canada, China etc.

Looks expensive. What about the regular phone plans? For instance, the plan I use currently in Japan has high per-minute or per-SMS charges for international numbers. The trade-off, of course, is that it's dirt cheap as long as you don't call international numbers, and basically just use it for mobile data. In a place where everyone uses LINE for communication, this works well.

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#306

Earlier quoted context omitted.

Even worse.. 2FA is mandatory on Twilio products, so either install authy or don't use Twilio - no exceptions.

Yeah, no. You don't need to use Authy.

Last time I checked, they did. In fact their 2FA system is so messed up that it thinks my mobile number is an authenticator app, and so I can't even request a code to delete the 2FA method, let alone add a new one:

https://i.imgur.com/PoZ2ssc.png https://i.imgur.com/heiJer6.png

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#307
post #203

Earlier quoted context omitted.

> Exporting the raw totp tokens can only be done from the desktop version that is currently deprecated and scheduled to be nuked from existence later this year Oh. Fucking great. So I'm locked in to using Authy forever now I guess. I hate 2FA. It literally does exactly nothing for security, it's just another tool for these big companies like Google and Twilio to put themselves between me and the services I need acces…

Haha, I see you manically rage posting in this topic. I empathise, it's fucking shit when "smart" people foist something unwanted on you because they think it's better for you. FWIW, I'm feeling pretty liberated to have moved my OTP codes out of authy and into multiple locations - my data, as much as I'd prefer not to use it, is now under my control. You can get the old desktop version from chocolatey/choco - https:/…

Thank you for the time you took to write this out. I'm sure it'll help people. It would probably work if I used Windows, but I don't.

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#308
post #304

Earlier quoted context omitted.

>And I find it odd when people call me on WhatsApp. Given that you're European, do you not have any friends/family outside your country, in neighboring EU countries? Wouldn't they have to pay high per-minute rates to call you?

https://mobile.free.fr/fiche-forfait-free Example from one provider: nope with 100 countries. Including the US, Canada, China etc.

In Finland I see the opposite problem. Traditional calling is dead, so there is absolutely no competition on international calls.

National calls and calls to nordic and Baltic countries are typically included in the subscription. But once you have to call to let's say central Europe per minute rates are exorbitant compared to today's data volume pricing.

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#309

Earlier quoted context omitted.

> I can’t remember the last time I talked on the traditional phone network or received a legitimate call Doctors and dentists. Most of the calls I get are spam, but then the MOST important calls I get are from doctors, labs, and dentists. I do as much as possible online of course, but not all of these professionals have good online systems and phone calls are often required. Sometimes you know what number they're goi…

I recently had to help my father organize his medical visits. Dealing with his healthcare providers was a bit of a pain, but it was way worse because he has stopped answering calls, primarily because of the call spam rate. I think because he owns his own business, he never fails to hand out his contact info when he is shopping, and he owns his own business (so his contact info is published by the city). His phone pro…

Depending on his age the business may be a red herring.

Shady outbound call based operations purchase, trade, and mine data all day long. You can have Equifax directly sell you reams of demographic specific contact information. God help anyone who ordered from a catalog.

My grandparents received easily 30 scam/spam calls a day. Mostly from Medicare scammers and sketchy organizations that operate right at the edge of illegality. Not even counting the outright fraudulent “Microsoft Support” scams.

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#310

Took a while, but this commenter is finally correct: > Why does Authy require I provide my cell phone number and email address? Why do I have to have a user account? This is completely ridiculous. I do not need nor want cloud syncing or backup. You are making Authy a potential target for attacks by associating a user to cloud stored 2FA information. > This is not in the spirit of 2FA. https://news.ycombinator.com/ite…

I use Authy _because_ it provides cloud sync. At the time, Google Authenticator didn't have it, and when I had to change phones it was a real hassle. Imagine if the phone had been stolen, no way to access the account normally to get a new QR, you'd have to "recover" every account.
Post reply on HN