4 ms·
It seems likely to me that they do, they use Authy, and the employees that fell for the attack just supplied the codes they needed. Each time you get in, you ca
by Operyl 4y ago
It seems likely to me that they do, they use Authy, and the employees that fell for the attack just supplied the codes they needed. Each time you get in, you can muddle around and figure out what is needed for the next time you send out an attack until you get where you need to.
The real story is that Twilio, likely due to one of their largest products being Authy, still refuses to move away from SMS 2FA. They need to finally join the rest of the industry and move on to webauthn, internally and externally for their customers.
- deleted 4y ago[deleted]