Live data from Hacker News

Twilio confirms data breach after hackers leak 33M Authy user phone numbers

securityweek.com

371–380 of 408 posts

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#371

While this sucks, my phone is in so many data breaches at this point it doesn’t matter. The spam-to-ham ratio on my phone number is now far worse than any other channel for me. The traditional phone network is at risk of going the way of the fax machine if we don’t do something about the spam problem like we did with email. If I’m on a call, even with family, it’s now almost exclusively on FaceTime/zoom/meet/etc. I c…

The solution to phone spam is voicemail transcription. Every call goes to voicemail, I get the transcription in a minute or two, and can call back if I want to.

With the caveat that this now adds a third-party transcriber that logs the content of every single voicemail you get.

Which will definitely end up in some data breach at some point.

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#372

While this sucks, my phone is in so many data breaches at this point it doesn’t matter. The spam-to-ham ratio on my phone number is now far worse than any other channel for me. The traditional phone network is at risk of going the way of the fax machine if we don’t do something about the spam problem like we did with email. If I’m on a call, even with family, it’s now almost exclusively on FaceTime/zoom/meet/etc. I c…

Easy trick: Every time you get a spam call, answer it. Talk to them until _they_ hang up. String them along. Put them on speakerphone and keep working. Feed them fake credit card numbers (there are generators out there that create numbers that checksum correctly, so they type them into whatever they're using to bill numbers. Hopefully this helps flag them as a bad actor to the processors, idk). It sounds like a lot o…

Incredible post. Starting this today!

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#373

Earlier quoted context omitted.

I think we just don't have very much competition in telecommunications so things never get fixed. Why bother? It's easier to extract rent off largely the same offerings as the rest of your market (difficult to understand pricing tiers that function as a congestion tax more than a transaction, often region-specific monopolies or duopolies, indistinguishable quality of service) and bring home large profits, market effi…

Almost no-one is pro-spam, it’s pretty much universally hated, and in many cases it’s already illegal so it’s more of a matter of enforcement. It is also trivial to detect. Sure there probably is some regulatory capture but if anything at all can be regulated it’s spam calls / messages. If the government can’t regulate spam then what could it be expected to regulate. The general population is increasing worried about…

> Almost no-one is pro-spam

They are if you point out ads are just spam by another name

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#374

Earlier quoted context omitted.

Almost no-one is pro-spam, it’s pretty much universally hated, and in many cases it’s already illegal so it’s more of a matter of enforcement. It is also trivial to detect. Sure there probably is some regulatory capture but if anything at all can be regulated it’s spam calls / messages. If the government can’t regulate spam then what could it be expected to regulate. The general population is increasing worried about…

>If the government can’t regulate spam then what could it be expected to regulate. The (US) government does an excellent job of regulating many things, such as commercial airplane design and construction. Oh wait...

> The (US) government does an excellent job of regulating many things, such as commercial airplane design and construction

If the US government wanted a healthy industry, they would have bought one or otherwise directed actual competition. Instead we only have Boeing, which taxpayers also subsidized, which seems incompetent and unwilling to acknowledge fault, which seems to be generally a gargantuan waste of taxpayer dollars compared to a properly efficient and reliable no-profit outfit.

I don't understand what this has to do with spam.

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#375

Earlier quoted context omitted.

Almost no-one is pro-spam, it’s pretty much universally hated, and in many cases it’s already illegal so it’s more of a matter of enforcement. It is also trivial to detect. Sure there probably is some regulatory capture but if anything at all can be regulated it’s spam calls / messages. If the government can’t regulate spam then what could it be expected to regulate. The general population is increasing worried about…

> Almost no-one is pro-spam In fact there are really only two groups that are pro-spam: spammers, obviously, and the entities that provide them services from which they may spam. Oh sure basically any provider of any service be it phone, web hosting, email, etc. will say they don't want spammers, and the email providers may actually mean it what with them not wanting their server's scores trashed and be unable to get…

> In fact there are really only two groups that are pro-spam

you forgot the entire marketing industry

> everyone is incentivized to enter walled garden services that actually do the barest minimum of enforcement for spam activity

These walled gardens actively spam you—that's how they make money. They only act against competing advertisers.

For there to be an incentive to avoid spam, we would need a social network not funded by it. To my knowledge this is essentially ActivityPub. In order for ActivityPub to be useful, we need an incentive to drag celebrities away from private paychecks that benefit from manipulation of other social networks (twitter, ig, tt). I don't believe there is any such entity or incentivization right now.

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#376

Earlier quoted context omitted.

Not to go too off-topic, but that post from 2015 has a response from 2019, how is that even possible? I thought HN auto locked posts after x number of days / years.

I don't want to go through the trouble of creating a throwaway to test it, but having worked in webdev long enough makes me believe it's possible that restriction is only on the frontend and some well placed curl may sidestep it

Facebook regularly shows me "posted 2 hrs ago" posts with comments from 22hrs ago. Lemmy changes the "posted X ago" timestamp when somebody edits their own post. Everyone seems to do something annoying with timestamp.

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#377
post #261
post #259

I have resisted moving off Authy as I liked the idea of cross-platform cloud sync. That'll teach me. Any other suitable alternatives? Aegis is android only. I do run vaultwarden, but it means I need another 2FA to login to it, before I can use it as a 2FA for other sites.

Bitwarden released a standalone authenticator app recently. You can give it a try. https://bitwarden.com/blog/bitwarden-just-launched-a-new-aut...

Does this mean you can export the backup and run a separate authenticator, yet both are sync'd?

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#378

Earlier quoted context omitted.

Easy trick: Every time you get a spam call, answer it. Talk to them until _they_ hang up. String them along. Put them on speakerphone and keep working. Feed them fake credit card numbers (there are generators out there that create numbers that checksum correctly, so they type them into whatever they're using to bill numbers. Hopefully this helps flag them as a bad actor to the processors, idk). It sounds like a lot o…

This works. I started doing this as well. I mimic the Jolly Roger call service and they usually hang up in less than a minute. Ex… - Act like you can’t hear them - Ask them to restart what they were saying - Start a conversation with a fictional person in the background It’s fun and makes getting spam calls enjoyable. https://jollyrogertelephone.com/

Reminds me of Lenny: https://en.m.wikipedia.org/wiki/Lenny_(bot) That one was just a recording of an old person saying weird incomprehensible things and asking for clarification at random intervals. No AI.

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#379

Earlier quoted context omitted.

I think we just don't have very much competition in telecommunications so things never get fixed. Why bother? It's easier to extract rent off largely the same offerings as the rest of your market (difficult to understand pricing tiers that function as a congestion tax more than a transaction, often region-specific monopolies or duopolies, indistinguishable quality of service) and bring home large profits, market effi…

Email is easier to mitigate spam with. The whole body of the message is given upfront.

> Email is easier to mitigate spam with

Absolutely disagree, email is the spam king. Just the fact that you can contact someone without consent breaks the entire system.

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#380
post #169

Earlier quoted context omitted.

Email is easier to mitigate spam with. The whole body of the message is given upfront.

It's easy now. It was an unsolved problem two decades ago. And it's not like there's no technical means for the phones either. Just enforcing caller ID would go a long way to curtail spam. Like in our great Red Tape Europe, even with uptick in recent years we have a tiny fraction of spam calls compared to the United States.

> It's easy now.

If this were true we wouldn't have spam

> And it's not like there's no technical means for the phones either. Just enforcing caller ID would go a long way to curtail spam.

A) this is insanely naïve given the international treaties that make up telecommunication agreements. B) "Just enforcing caller ID would go a long way to curtail spam." telecoms don't have any clue who is calling, see above comments about treaties.

Post reply on HN