3 ms·
tl;dr: Social Engineering that sent SMS with links to Twilio employees and a few fell for it. Time for more security training to employees ? Weird that this hap
by codegeek 4y ago
tl;dr: Social Engineering that sent SMS with links to Twilio employees and a few fell for it. Time for more security training to employees ? Weird that this happened to a company like Twilio which sells SMS API.
- geofft 4y agoI don't think "more security training" will get us anywhere - we've been trying it for a long while. This is a technical problem and admits technical solutions. The most obvious, simple, and straightforward solution here is logins with security keys (WebAuthn/FIDO), which cannot be phished. Perhaps Twilio fell for this precisely because they don't want to admit to themselves that the SMS verification product they sell (https://www.twilio.com/verify https://www.twilio.com/verify) is an obsolete joke compared to security keys. If you don't want to use that, for some reason, or if you want additional protection, other solutions include using dedicated machines (not personal cell phones and certainly not whatever devices the attacker was using) ideally with hardware-locked keys (TPMs etc.) to access the corporate network or at least to access sensitive systems like customer data, or giving people separate privileged accounts that they don't use for day-to-day access, or establishing a two-person rule for logging into sensitive systems (so two people with the same access need to get successfully phished at the same time), or setting up some real-time auditing of changes (e.g., a Slack channel gets notified when people manually log into prod).