I recently setup a focus profile on my iPhone that only lets calls ring through from knowns contacts. There is going to be an adjustment period as I discover people and companies (such as doctors/hospitals) that I want to allow calls from and add them to the whitelist. But otherwise, it has been really nice to cut down on all of the interruptions.
You can flip on the option in the settings to silence unknown callers. It does a decent job, and prevents a lot of the manual micro-managing. I will sometimes toggle it off if I’m expecting a call from an unknown number, but it will also pull numbers it sees in texts and email and known. I manually set this up several years ago, to only ring for contract in my address book. It was annoying, but worked. At the same ti…
Twilio confirms data breach after hackers leak 33M Authy user phone numbers
391–400 of 408 posts
Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers
#392Twilio requires Authy for 2fa for sendgrid and maybe even twilio itself instead of supporting more standardized 2fa that’d allow 1pass to be used. This is all the more frustrating because I was forced to use Authy to protect an account instead of my regular tooling and they still managed to screw it up. Twilio, take a hint and stop forcing people to use your custom thing https://www.twilio.com/docs/sendgrid/ui/accoun…
Even worse.. 2FA is mandatory on Twilio products, so either install authy or don't use Twilio - no exceptions.
Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers
#393Earlier quoted context omitted.
TLDR: use a password manager to store your secrets. An OTP secret key is just a secret.
That is not the TLDR I intended. If you store your OTP secrets in the same password store that also stores your regular passwords, you've just completely undermined the second factor of security.
Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers
#394Earlier quoted context omitted.
TLDR: use a password manager to store your secrets. An OTP secret key is just a secret.
That is not the TLDR I intended. If you store your OTP secrets in the same password store that also stores your regular passwords, you've just completely undermined the second factor of security.
That said, the significance of using two separate password stores isn't clear to me. Under what threat model is that supposed to be an improvement over a single password store? Basically, your idea is that passwords are less essential than OTP secrets, so you take less care keeping them safe. However I think it'd make more sense to just apply proper protection for all secrets.
Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers
#395Earlier quoted context omitted.
Getting a new, out of state number can sometimes help. My phone is out of state due to my previous address, and 95% of spam i get is spoofed to that old town or the surrounding area. No doctors office/etc calls me from that area. It works pretty nice
> Getting a new, out of state number The problem with that idea is that when you make local calls, people think that you are the spammer. I too have an out-of-state number after having moved, and I can definitely confirm that when I make a local call, some people will not pick up after seeing the unusual area code on their caller ID. They told me so. There's another problem too: Even when I leave voicemail for a loca…
Everyone i know has kept their phone number for years. You'd think businesses would be used to people who moved from out of town but kept their number.
I don't call places much aside from doctors/etc tho, so i guess i just haven't had that issue personally.
Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers
#396Earlier quoted context omitted.
I have been transferring Google Authenticator from phone to phone for years though? Going back to at least 2016, and that was 8 years ago. In 2020 I copied it from Android to iOS even by doing an export I had no idea was there.
It was a manual process requiring the phone to be working, which doesn't help when you have an accident that damages the phone.
Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers
#397Earlier quoted context omitted.
Not to go too off-topic, but that post from 2015 has a response from 2019, how is that even possible? I thought HN auto locked posts after x number of days / years.
I don't want to go through the trouble of creating a throwaway to test it, but having worked in webdev long enough makes me believe it's possible that restriction is only on the frontend and some well placed curl may sidestep it
Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers
#398Earlier quoted context omitted.
It's easy now. It was an unsolved problem two decades ago. And it's not like there's no technical means for the phones either. Just enforcing caller ID would go a long way to curtail spam. Like in our great Red Tape Europe, even with uptick in recent years we have a tiny fraction of spam calls compared to the United States.
> It's easy now. If this were true we wouldn't have spam > And it's not like there's no technical means for the phones either. Just enforcing caller ID would go a long way to curtail spam. A) this is insanely naïve given the international treaties that make up telecommunication agreements. B) "Just enforcing caller ID would go a long way to curtail spam." telecoms don't have any clue who is calling, see above comment…
I was replying to the comment asserting that dealing with email spam is easier, which it most resolutely wasn't until the advent of statistical filters.
> A) this is insanely naïve given the international treaties that make up telecommunication agreements.
Fun thing about treaties and agreements is they are not laws of nature and can be entered, abandoned and amended at will. A lot of regulation is getting constantly updated.
Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers
#399Earlier quoted context omitted.
I started with Keepassium but ended up with Strongbox which has been great.
Don‘t know if Strongbox is working well? Developed by a single programmer… and no Audits available.
Is Keepassium audited?
Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers
#400Earlier quoted context omitted.
Don‘t know if Strongbox is working well? Developed by a single programmer… and no Audits available.
They address that here: https://strongboxsafe.com/support/#reamaze#0#/kb/security-an... Is Keepassium audited?
Otherwise, no. A third-party audit costs like a year of part-time developer, and at this stage the developer is more useful.