Live data from Hacker News

Twilio confirms data breach after hackers leak 33M Authy user phone numbers

securityweek.com

321–330 of 408 posts

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#321

Took a while, but this commenter is finally correct: > Why does Authy require I provide my cell phone number and email address? Why do I have to have a user account? This is completely ridiculous. I do not need nor want cloud syncing or backup. You are making Authy a potential target for attacks by associating a user to cloud stored 2FA information. > This is not in the spirit of 2FA. https://news.ycombinator.com/ite…

I use Authy _because_ it provides cloud sync. At the time, Google Authenticator didn't have it, and when I had to change phones it was a real hassle. Imagine if the phone had been stolen, no way to access the account normally to get a new QR, you'd have to "recover" every account.

Good for you. Still doesn't answer gp's question. Why do we have to create a central account?

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#322

Earlier quoted context omitted.

Wow. I was wondering why people were fussing about the odd spam call! The most I have had is 2 in a day and my number is in websites, social media, whatever. Almost all spam is instantly recognisable. Mostly visa and parcel delivery scams. In do not block unknown numbers because lots of organisations use them here (UK) This includes people I really do want to be able to contact me if they want to such as the police.

> here (UK) I think it's mostly just an issue in the US/North America

I’m in Canada and get maybe a couple scam calls a month

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#323

Took a while, but this commenter is finally correct: > Why does Authy require I provide my cell phone number and email address? Why do I have to have a user account? This is completely ridiculous. I do not need nor want cloud syncing or backup. You are making Authy a potential target for attacks by associating a user to cloud stored 2FA information. > This is not in the spirit of 2FA. https://news.ycombinator.com/ite…

[deleted]

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#324

While this sucks, my phone is in so many data breaches at this point it doesn’t matter. The spam-to-ham ratio on my phone number is now far worse than any other channel for me. The traditional phone network is at risk of going the way of the fax machine if we don’t do something about the spam problem like we did with email. If I’m on a call, even with family, it’s now almost exclusively on FaceTime/zoom/meet/etc. I c…

I have never shared my phone number with any online service aside from my bank and I don't get any spam on my phone.

I still don't recommend to do that and just toss those that demand your phone number away. Get a business phone if your work demands it.

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#325

Earlier quoted context omitted.

I use Authy _because_ it provides cloud sync. At the time, Google Authenticator didn't have it, and when I had to change phones it was a real hassle. Imagine if the phone had been stolen, no way to access the account normally to get a new QR, you'd have to "recover" every account.

Good for you. Still doesn't answer gp's question. Why do we have to create a central account?

Yes it did. Authy provided cloud sync via phone number authentication. If you didn't want that, you stuck with Google Authenticator.

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#326

Twilio requires Authy for 2fa for sendgrid and maybe even twilio itself instead of supporting more standardized 2fa that’d allow 1pass to be used. This is all the more frustrating because I was forced to use Authy to protect an account instead of my regular tooling and they still managed to screw it up. Twilio, take a hint and stop forcing people to use your custom thing https://www.twilio.com/docs/sendgrid/ui/accoun…

Authy uses a standardized QR code to seed your TOTP. This isn't true.

Not true. Look at the documentation, authy or sms.

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#327

While this sucks, my phone is in so many data breaches at this point it doesn’t matter. The spam-to-ham ratio on my phone number is now far worse than any other channel for me. The traditional phone network is at risk of going the way of the fax machine if we don’t do something about the spam problem like we did with email. If I’m on a call, even with family, it’s now almost exclusively on FaceTime/zoom/meet/etc. I c…

Easy trick: Every time you get a spam call, answer it. Talk to them until _they_ hang up. String them along. Put them on speakerphone and keep working. Feed them fake credit card numbers (there are generators out there that create numbers that checksum correctly, so they type them into whatever they're using to bill numbers. Hopefully this helps flag them as a bad actor to the processors, idk).

It sounds like a lot of work, but when I started doing this about two years ago it took about two weeks for the calls to just... stop. Now I get a spam call maybe once a month. It's glorious.

My theory is this is the only route to get put on the _real_ do-not-call lists - the ones that spam companies in India have labelled "unprofitable numbers.txt". Seems like once you're on those, you're good.

Every minute they're listening to you use them for rubber-duck debugging is a minute they're not scamming Granny out of her 401k. Be prepared to get called bad names in foreign languages. Bonus points if you learn some phrases in their language to really get under their skin.

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#328

Earlier quoted context omitted.

> If I’m on a call, even with family, it’s now almost exclusively on FaceTime/zoom/meet/etc. I really don't get that. I don't get these, on neither of my phones (I've got two numbers). When it rings, it's virtually always friends or family. Sometimes the bank/insurance/doctor. Very exceptionally do I get a commercial or scam call. I think it's not an argument good enough to excuse to excuse Authy here: "my phone alre…

I have 5+ spam calls every day. Looking at my call history it’s been that way as far back as it lets me scroll. Blocking doesn’t make a ton of difference, as it’s almost always a different number. I don’t understand what they are calling for either. I’ve answered a few and most of the time it’s a dead line when I answer. Just silence.

> I don’t understand what they are calling for either. I’ve answered a few and most of the time it’s a dead line when I answer. Just silence.

The primary operating goal of a predictive dialing system is minimizing agent downtime. Ideally, when an agent transitions into being ready to talk, they want as little time as possible before they're connected to a live lead.

In above-board telemarketing, where there's a finite list of leads instead of 000-000-0000 through 999-999-9999, the administrator will adjust dialing aggressiveness to minimize the chance that a lead picks up the phone but no agent is available to take the call. Because when that happens, the answering party experiences nothing but dead air, followed by a timeout, and a hangup.

The one nice consequence from this, though, is that if you do answer a spam call and get connected to a live person, chances are very high that several other potential marks got dead air instead. Maybe you saved grandma for another day.

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#329

Earlier quoted context omitted.

I have 5+ spam calls every day. Looking at my call history it’s been that way as far back as it lets me scroll. Blocking doesn’t make a ton of difference, as it’s almost always a different number. I don’t understand what they are calling for either. I’ve answered a few and most of the time it’s a dead line when I answer. Just silence.

Those are usually robo dialers looking for active numbers to resell to spammers/scammers. You answering puts you on their good list. These are also the calls that never leave any type of voicemail. I’m not sure what list VM gets you on.

This sounds intuitive, but isn't true in my experience. It's a natural consequence of aggressive dialing with a limited pool of agents. See my sibling comment: https://news.ycombinator.com/item?id=40882163

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#330

Took a while, but this commenter is finally correct: > Why does Authy require I provide my cell phone number and email address? Why do I have to have a user account? This is completely ridiculous. I do not need nor want cloud syncing or backup. You are making Authy a potential target for attacks by associating a user to cloud stored 2FA information. > This is not in the spirit of 2FA. https://news.ycombinator.com/ite…

I use Authy _because_ it provides cloud sync. At the time, Google Authenticator didn't have it, and when I had to change phones it was a real hassle. Imagine if the phone had been stolen, no way to access the account normally to get a new QR, you'd have to "recover" every account.

I have been transferring Google Authenticator from phone to phone for years though? Going back to at least 2016, and that was 8 years ago. In 2020 I copied it from Android to iOS even by doing an export I had no idea was there.
Post reply on HN