Live data from Hacker News

Twilio confirms data breach after hackers leak 33M Authy user phone numbers

securityweek.com

381–390 of 408 posts

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#381

Earlier quoted context omitted.

>If the government can’t regulate spam then what could it be expected to regulate. The (US) government does an excellent job of regulating many things, such as commercial airplane design and construction. Oh wait...

> The (US) government does an excellent job of regulating many things, such as commercial airplane design and construction If the US government wanted a healthy industry, they would have bought one or otherwise directed actual competition. Instead we only have Boeing, which taxpayers also subsidized, which seems incompetent and unwilling to acknowledge fault, which seems to be generally a gargantuan waste of taxpayer…

I have no idea what you are trying to say, but you appear not to know that the McDonnell Douglas merger was forced upon Boeing by the US government as a ‘cheap’ way to save McDonalds Douglass. Boeing didn’t really have a choice in the matter.

It would be highly improbable that the people making those kinds of decisions could successfully regulate an airline industry, or even the much easier task of spam.

The US government has also gone to great lengths to protect Boeing from competition by boxing out concord, canadian aircraft, and embraer . I think such companies like Boeing should be considered for-profit arms of the government instead of independent corporations.

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#382
post #179

Earlier quoted context omitted.

Is this like an American thing? I'm in the Netherlands and i get like 1 spam call per two months (business internet/electricity salesperson usually)

In Spain I get at least 4 or 5 calls a week from different providers. Luckily at the moment, there's still a delay after you answer the call as (I assume) you're being connected to a human. How long will this last....? Currently, when I don't hear a voice within 1s or so, I hang up. A legitimate caller will (hopefully) call back pretty quick.

Hmm... interesting. Spain should be covered by GDPR so you should be able to say "I reject right to process my personal data" and it should stop...

I had issue with Vodafone here - they were pestering me with calls/messages... even after I switched to Digi they were calling me for a week to try to convince me to stay (it just confirmed my decission to switch ;) )

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#383

Earlier quoted context omitted.

>And I find it odd when people call me on WhatsApp. Given that you're European, do you not have any friends/family outside your country, in neighboring EU countries? Wouldn't they have to pay high per-minute rates to call you?

Inside the EU / EES we usually have minutes included. Right now my plan, with Orange, costs 7.5 EUR / month with unlimited 5G (for real), 16 GB of data when roaming, unlimited minutes when roaming in EU/EES, and 600 international minutes in EU/EES. We do have great deals here, BTW, I'm sure it's more expensive in other EU countries. I'd have to upgrade for another 100 minutes with US / Canada, however, I have another…

> Inside the EU / EES we usually have minutes included.

Nowadays... but not so long ago it wasn't like that and the prices were abysmal. And considering that EU is somewhat smaller and there is higher chance of having international contacts make the IMs so popular (especially whatsapp)...

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#384
post #179

While this sucks, my phone is in so many data breaches at this point it doesn’t matter. The spam-to-ham ratio on my phone number is now far worse than any other channel for me. The traditional phone network is at risk of going the way of the fax machine if we don’t do something about the spam problem like we did with email. If I’m on a call, even with family, it’s now almost exclusively on FaceTime/zoom/meet/etc. I c…

Is this like an American thing? I'm in the Netherlands and i get like 1 spam call per two months (business internet/electricity salesperson usually)

Presumably because there aren't very many fluent Dutch speakers in India/Phillipines/Carribean countries where the spam call centers are.

They target the US, and to some extent the UK, Gulf countries like UAE where English is the de facto language.

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#385

While this sucks, my phone is in so many data breaches at this point it doesn’t matter. The spam-to-ham ratio on my phone number is now far worse than any other channel for me. The traditional phone network is at risk of going the way of the fax machine if we don’t do something about the spam problem like we did with email. If I’m on a call, even with family, it’s now almost exclusively on FaceTime/zoom/meet/etc. I c…

The solution to phone spam is voicemail transcription. Every call goes to voicemail, I get the transcription in a minute or two, and can call back if I want to.

This is what you get on iPhone with the "Silence Unknown Callers" setting.

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#386
post #343
post #319

Earlier quoted context omitted.

I'm really sorry for the situation you find yourself in and agree that it sucks. I'm replying because I want to mention that it is possible to use 2FA without any form of vendor lock-in (although I realize this doesn't help you retrospectively fix your existing issue). I'm not trying to be a wise ass, I just want to share some pointers for folks who are interested in avoiding or remedying this problem (which is a bit…

TLDR: use a password manager to store your secrets. An OTP secret key is just a secret.

That is not the TLDR I intended. If you store your OTP secrets in the same password store that also stores your regular passwords, you've just completely undermined the second factor of security.

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#387
post #210

Earlier quoted context omitted.

Why? 2fa doesn't meaningfully add security if you're using decent passwords, and SMS-based 2fa is no less secure than no 2fa

just because SMS is vulnerable to SS7 attacks

So you're saying no 2fa is more secure than SMS 2fa?

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#388
post #386
post #343

Earlier quoted context omitted.

TLDR: use a password manager to store your secrets. An OTP secret key is just a secret.

That is not the TLDR I intended. If you store your OTP secrets in the same password store that also stores your regular passwords, you've just completely undermined the second factor of security.

> If you store your OTP secrets in the same password store that also stores your regular passwords, you've just completely undermined the second factor of security.

Which, to be clear, is perfectly fine. 2fa is completely unnecessary: the increased risk of getting locked out from my accounts and the risk of using services from companies like Twilio and Google is greater than the risk of someone guessing long randomly generated passwords.

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#389
post #202

Earlier quoted context omitted.

I just hate that some apps/services require 2FA. My 32 random characters which are unique to each service are secure enough. Adding another service on top just increases risk (as shown here; Authy was never going to do anything to protect me, but it has now leaked info about me.)

No. TOTP MFA’s mechanics make it a significant security improvement regardless of how impressively large (???) your password is. It doesn’t inherently implicate “another service”. That’s the beauty of it. This issue is SPECIFICALLY due to forced use of Authy. Forced MFA for high-value accounts is a good thing. “A long password will protect me” is 2006 thinking.

You need to explain the threat model which 2fa protects against. Because I'm not seeing it.

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#390
post #209

Earlier quoted context omitted.

Doesn't Bitwarden require you to be on the paid subscription plan to use 2FA? That's what I concluded anyway from trying to research this garbage when Microsoft was threatening to lock me out of my Github account. It's why I ended up on Authy.

> Doesn't Bitwarden require you to be on the paid subscription plan to use 2FA? I believe they do, yes. Been on the $10/year plan and have forgotten the details on their tiers, though. > It's why I ended up on Authy. All 2FA really boils down to is a "otpauth://totp" URL that clients use to generate time based tokens. Once you have those exported somewhere, you can move to any TOTP app you want (desktop or mobile)

> All 2FA really boils down to is a "otpauth://totp" URL that clients use to generate time based tokens. Once you have those exported somewhere, you can move to any TOTP app you want (desktop or mobile)

And how do I do that in Authy

Post reply on HN