Live data from Hacker News

Twilio confirms data breach after hackers leak 33M Authy user phone numbers

securityweek.com

401–408 of 408 posts

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#401
post #174

Authy is basically unsupported. Not surprised. I switched my accounts to 1Password when they announced the end of life of the macOS app.

Authy is terrible. I recently tried to delete my account, because I've (finally) moved everything to Keepass, and they make it as difficult as possible. Then they make you wait 30 days before they actually delete it, making sure to email you constantly in the mean time, to ask you to please reconsider. My 30 days expired a few days ago, so if they had actually deleted my account when I told them to, my info maybe wou…

After I transferred everything I only had dead sites no longer around like FTX in the app. I feel like it needs to be left around as a kind of Time Machine…

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#402

Earlier quoted context omitted.

Why not get a second sim? Most phones can have 2 sims active, and a phone / text only plan is dirt cheap (3-6$/m). Offer the second number with much greater discretion.

From experience it seems to be semi-random. I've never had a single spam call on my main phone number, but friends who have got a new number get maybe 20 spam calls per day, with only having given their number to their closest friends and family. I think one factor that weighs in heavily is if your contacts download thousands of spam apps onto their phones and click YES to every permission. Then your phone number is…

> I don't think you can even install WhatsApp without giving it your entire phone book, can you?

You can. It will cry and beg and nag every chance it gets (same as when you don’t allow notifications) but it will still function without these permissions (for now).

Tested with WA business on a “landline” voip number because I don’t want people to contact me via WA (and they would if I used my cell number for WA)

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#403

Earlier quoted context omitted.

Inside the EU / EES we usually have minutes included. Right now my plan, with Orange, costs 7.5 EUR / month with unlimited 5G (for real), 16 GB of data when roaming, unlimited minutes when roaming in EU/EES, and 600 international minutes in EU/EES. We do have great deals here, BTW, I'm sure it's more expensive in other EU countries. I'd have to upgrade for another 100 minutes with US / Canada, however, I have another…

> Inside the EU / EES we usually have minutes included. Nowadays... but not so long ago it wasn't like that and the prices were abysmal. And considering that EU is somewhat smaller and there is higher chance of having international contacts make the IMs so popular (especially whatsapp)...

You're right about prices being higher not long ago.

> EU is somewhat smaller

By area? The EU's population is larger than that of the US.

WhatsApp is indeed very popular for IM, and nowadays, SMS is basically just for 2FA (I hoped RCS would change that, but it's too little too late unfortunately).

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#404

Earlier quoted context omitted.

> Inside the EU / EES we usually have minutes included. Nowadays... but not so long ago it wasn't like that and the prices were abysmal. And considering that EU is somewhat smaller and there is higher chance of having international contacts make the IMs so popular (especially whatsapp)...

You're right about prices being higher not long ago. > EU is somewhat smaller By area? The EU's population is larger than that of the US. WhatsApp is indeed very popular for IM, and nowadays, SMS is basically just for 2FA (I hoped RCS would change that, but it's too little too late unfortunately).

> By area? The EU's population is larger than that of the US.

Yes, by area, which second part of the sentence implied when I mentioned it's easier to end-up in different country without driving miles on end :)

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#405
post #203

Earlier quoted context omitted.

> Exporting the raw totp tokens can only be done from the desktop version that is currently deprecated and scheduled to be nuked from existence later this year Oh. Fucking great. So I'm locked in to using Authy forever now I guess. I hate 2FA. It literally does exactly nothing for security, it's just another tool for these big companies like Google and Twilio to put themselves between me and the services I need acces…

Haha, I see you manically rage posting in this topic. I empathise, it's fucking shit when "smart" people foist something unwanted on you because they think it's better for you. FWIW, I'm feeling pretty liberated to have moved my OTP codes out of authy and into multiple locations - my data, as much as I'd prefer not to use it, is now under my control. You can get the old desktop version from chocolatey/choco - https:/…

It is not worked now. If I tried to log in, the message popped up, "The device does not meet the minimum integrity requirements".

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#407
post #342
post #126

Earlier quoted context omitted.

Has anyone found a single open-source app that supports both mobile and desktop though? That was the attraction of Authy before they killed their desktop apps.

Why do you need it to be a single app?

Because I don't want to manually sync between desktop and mobile?

Re: Twilio confirms data breach after hackers leak 33M Authy user phone numbers

#408
post #399

Earlier quoted context omitted.

They address that here: https://strongboxsafe.com/support/#reamaze#0#/kb/security-an... Is Keepassium audited?

We are undergoing the same CASA audit (required to access Google Drive API). And we do have people forking and building the project from source, so one can hope they read what they compile. Strongbox' source code is half-closed (see #784 in their repo) so source-level independent audit is impossible. Otherwise, no. A third-party audit costs like a year of part-time developer, and at this stage the developer is more u…

Wise words! Most of the people think, that Strongboxsafe is an Open Source App, which is definitely not the case!

Overall a good app, but if you want true Open Source KeePassium is the app to choose.

Post reply on HN