Live data from Hacker News

Twilio confirms data breach after hackers leak 33M Authy user phone numbers

securityweek.com

331–340 of 408 posts

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#331

While this sucks, my phone is in so many data breaches at this point it doesn’t matter. The spam-to-ham ratio on my phone number is now far worse than any other channel for me. The traditional phone network is at risk of going the way of the fax machine if we don’t do something about the spam problem like we did with email. If I’m on a call, even with family, it’s now almost exclusively on FaceTime/zoom/meet/etc. I c…

Easy trick: Every time you get a spam call, answer it. Talk to them until _they_ hang up. String them along. Put them on speakerphone and keep working. Feed them fake credit card numbers (there are generators out there that create numbers that checksum correctly, so they type them into whatever they're using to bill numbers. Hopefully this helps flag them as a bad actor to the processors, idk). It sounds like a lot o…

This works.

I started doing this as well.

I mimic the Jolly Roger call service and they usually hang up in less than a minute.

Ex…

- Act like you can’t hear them

- Ask them to restart what they were saying

- Start a conversation with a fictional person in the background

It’s fun and makes getting spam calls enjoyable.

https://jollyrogertelephone.com/

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#332

Took a while, but this commenter is finally correct: > Why does Authy require I provide my cell phone number and email address? Why do I have to have a user account? This is completely ridiculous. I do not need nor want cloud syncing or backup. You are making Authy a potential target for attacks by associating a user to cloud stored 2FA information. > This is not in the spirit of 2FA. https://news.ycombinator.com/ite…

Not to go too off-topic, but that post from 2015 has a response from 2019, how is that even possible? I thought HN auto locked posts after x number of days / years.

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#333

Twilio requires Authy for 2fa for sendgrid and maybe even twilio itself instead of supporting more standardized 2fa that’d allow 1pass to be used. This is all the more frustrating because I was forced to use Authy to protect an account instead of my regular tooling and they still managed to screw it up. Twilio, take a hint and stop forcing people to use your custom thing https://www.twilio.com/docs/sendgrid/ui/accoun…

They should be held fully liable for damages for this kind of nonsense when indeed it goes wrong.

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#334

Earlier quoted context omitted.

I don’t have a problem with advertising generally, as long as I know upfront that’s what funds a tool I’m using, and isn’t disguised like a non-ad (eg. Unlike what Google does, which is outright deception). Advertising and spam are two separate things in my book. However, my real problem is with what I call “The Google Strategy.” Basically, they take publicly funded infrastructure like HTTP and SMTP, capture the netw…

This process has a descriptive name, enshittification ( https://en.wikipedia.org/wiki/Enshittification ), and it seems to apply to most internet services.

That might be the trendy term for it now, but the strategy is as old as time.

In old school economic terms its called "dumping." When international trade started becoming a major thing, aspiring monopolists would flood foreign markets with goods sold below-cost to push out local competitors, then ratchet up prices and reduce quality once they'd captured the market (basically the Google strategy).

Just like crypto people had to learn that financial regulation was in place for a reason, internet people have had to learn that industrial age anti-trust rules were also put in place for a reason. Now we just need to enforce them.

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#335

Earlier quoted context omitted.

Maybe? https://gist.github.com/gboudreau/94bb0c11a6209c82418d01a59d...

Authy desktop is no longer available and you need a specific version.

https://community.chocolatey.org/packages/authy-desktop/2.2....

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#336

While this sucks, my phone is in so many data breaches at this point it doesn’t matter. The spam-to-ham ratio on my phone number is now far worse than any other channel for me. The traditional phone network is at risk of going the way of the fax machine if we don’t do something about the spam problem like we did with email. If I’m on a call, even with family, it’s now almost exclusively on FaceTime/zoom/meet/etc. I c…

Very similar here... same for my primary gmail address... the most annoying thing is the "credit monitoring" that comes with a few of my credit cards is all but worthless... I get constant notices that my "email is compromised" but absolutely no detail on how/where/what exactly is compromised, with is like saying, your email is public.

While I do get a few regular phone calls a week, they're all in my contacts and I don't answer if the number isn't... at least 2/3 the time if I decide to answer as I'm expecting an out of band call, it's spam. On the flip side, I am wanting to setup for "your code is XXXXXX" as a verification on a personal website I'm working on to allow for public users. I know it doesn't add too much, but it's enough to reduce the noise. I'm not even sure what more hoops I need to jump through with Twilio to get to send said messages. I'm not a company, and not sending any kind of marketing campaign.

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#337
post #221

Earlier quoted context omitted.

Th topic of this subthread is exactly that one cannot rely on the contact list method because doctors may call from any unknown number. Maybe you haven’t had to deal with that (yet), but once you do you’ll realize that your method doesn’t work for that.

Same with home repair contractors. The person coming over to do the work is unlikely to call from the same number the business hands out that rings an office manager or the owner. Same goes for the person calling me back with an estimate I requested.

For contractors, this is where SMS tends to come in a lot as they'll usually text if they cannot get a voice call through, which helps.

For doctors offices, it's a whole different bag and a true pain... you'll get voicemails with half a message that has none of the important details.

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#338

While this sucks, my phone is in so many data breaches at this point it doesn’t matter. The spam-to-ham ratio on my phone number is now far worse than any other channel for me. The traditional phone network is at risk of going the way of the fax machine if we don’t do something about the spam problem like we did with email. If I’m on a call, even with family, it’s now almost exclusively on FaceTime/zoom/meet/etc. I c…

Really? I get nearly zero spam text maybe 1-2 per year, even voice calls now. I get maybe 1 per month now. I'm with US carrier TMobile and on iOS.

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#339

While this sucks, my phone is in so many data breaches at this point it doesn’t matter. The spam-to-ham ratio on my phone number is now far worse than any other channel for me. The traditional phone network is at risk of going the way of the fax machine if we don’t do something about the spam problem like we did with email. If I’m on a call, even with family, it’s now almost exclusively on FaceTime/zoom/meet/etc. I c…

> I can’t remember the last time I talked on the traditional phone network or received a legitimate call Doctors and dentists. Most of the calls I get are spam, but then the MOST important calls I get are from doctors, labs, and dentists. I do as much as possible online of course, but not all of these professionals have good online systems and phone calls are often required. Sometimes you know what number they're goi…

Doctors and dentists are shifting to apps with integrated VoIP calls and dropping PSTN.

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#340

Earlier quoted context omitted.

> I can’t remember the last time I talked on the traditional phone network or received a legitimate call Doctors and dentists. Most of the calls I get are spam, but then the MOST important calls I get are from doctors, labs, and dentists. I do as much as possible online of course, but not all of these professionals have good online systems and phone calls are often required. Sometimes you know what number they're goi…

Doctors and dentists are shifting to apps with integrated VoIP calls and dropping PSTN.

And I really like that. Instead of having to use some social network product just to receive my lab results.

Or we may end up in a world when doctors send us important Tiktoks.

Post reply on HN