17 ms·
Twilio’s toll fraud problem
- woofcat 4y agohttps://nitter.kylrth.com/benjaminnetter/status/1530852928885608449#m https://nitter.kylrth.com/benjaminnetter/status/153085292888... If you want to read the tweet on how it works.
- yjftsjthsd-h 4y agoI'm surprised/confused: Why is it hard to detect premium rate numbers, or at least set a flag to not allow sending to them? Like, I can't think of a time when twillo should ever be sending to a premium rate number; why is this even possible?
- rippercushions 4y agoThere are 200+ jurisdictions in the phone network and everybody has their own conventions on what a "premium" number is. For comparison, imagine if each domain in the world could set its own rates for much doing a DNS query would cost you, and governments regulated this only by designating a few second level domains as "premium". That's pretty much the scale of the problem. Edit: To be clear, this is a very well known problem and Twilio should be doing much better at it. But it's by no means an easy problem, and all the other side needs is one (1) number to exploit.
- globalreset 4y ago> There are 200+ jurisdictions in the phone network and everybody has their own conventions on what a "premium" number is. They know how to charge you for these numbers so apparently they do have that data, no?
- from 4y agoDepends what you mean by "premium rate." Every number costs money to call in Twilio. Some numbers cost more, in lots of these frauds numbers in ordinary ranges are used (Is a rural number in Chile that costs $0.20/minute to call premium rate/fraud? Because that's what it looks like a lot of the time. How about $0.05 a minute in Austria?). IRSF, the industry term for this kind of fraud causes billions in losses a year and there is no easy answer but Twilio should probably have more infrastructure in place to reduce massive surprise bills.
- globalreset 4y agoBlock any number that costs more than 25th percentile would be a start and so on... I can come up with plenty of heuristics that would be better than nothing.
- bee_rider 4y agoThat seems like it ought to be a knob provided to the user…
- rippercushions 4y agoTelco billing is postpaid, so they actually won't find out for at least a month.
- yjftsjthsd-h 4y agoThat's inconsistent with the OP getting 40 emails a day about charges, though?
- nfm 4y agoSolving this is squarely Twilio's business! They know how much to bill the customer, so they must know how much it costs to send to a number.
- techsupporter 4y ago> They know how much to bill the customer I don't mean to do Twilio's work of defending them, but in my experience it's possible they actually don't know how much to bill the customer. What they may know is the generalized per-minute or per-session rate they've agreed with another operator alongside a general "premium rate numbers will be settled at a later date" kind of clause. My employer got bit by this several years ago, purely on calls within the +1 country code. Before this practice was largely banned, some small carriers were allowed to designate certain rate centers as higher cost. So our VoIP carrier would say that a call to a given area code was $0.003/minute but the calls would later settle out at $0.25/minute because of a 1,000s block of numbers being (unknowing to us our our carrier) as higher cost and being settlement billed back at the higher rate. Twilio could agree to carry some or all of this risk for its customers as part of their value-add and fees. That way, Twilio has the incentive to make the proper changes for its customers and would have the experience of looking at all of the return billed rates for all of the calls or messages across its entire customer base to help prevent toll fraud.
- bombcar 4y agoThis is the case, the telephone billing system is perhaps the most complicated pile of softwareshit you have ever seen in your LIFE - and some of it is insane. There have been people who got printed bills from their cell phone provider for every single kilobyte of data, each individually indexed and billed: https://en.wikipedia.org/wiki/300-page_iPhone_bill https://en.wikipedia.org/wiki/300-page_iPhone_bill
- Scoundreller 4y agoMy favourite was getting charged for an sms my iPhone sent which was a phone home to an Apple headquarters short code for iMessage. iOS hides these from the user. Most providers don’t charge for this, but some do. Really sucks when you carefully load 10 EUR of credit to buy a 10 EUR prepaid plan for the month and see 0,05 deducted despite being incredibly careful to not do anything that would incur a charge before buying the plan.
- askvictor 4y agoTwilio works with phone companies across the globe; this is not something that would be that difficult for a company of their size to implement (even if it means one employee whose job it is to keep this up to date). Consider that the timezone database (a similar problem) is administered by one person (a volunteer no less)
- purpleblue 4y agoThis is NOT hard. Not at all. Twilio knows which numbers will charge customers, THEY HAVE THE DATA. They can make a list of numbers that charge customers, and then have a flag that disallows SMSes to those numbers. They also have relationships with phone providers in every market that they are in, and those providers can provide that same information and then allow a blacklist to those numbers or whatever format the premium numbers occur in. It's not hard at all. It's a nice value-add feature and I'm sure if a competitor like MessageBird implemented something like this, it would be an easy differentiator if Twilio doesn't want to provide this.
- bdcravens 4y agoWrapping abstractions around hard problems is pretty much Twilio's value prop.
- toast0 4y agoTwilio should help their customers with this (and it looks like they do have something, but maybe not enough)... but it's also something you can do a first pass through libphonenumber metadata[1], which was pretty reasonable at my last job. [1] https://github.com/google/libphonenumber/tree/master/metadata https://github.com/google/libphonenumber/tree/master/metadat...
- Spooky23 4y agoHonestly, I can’t think of a legitimate use case for toll SMS.
- jameshart 4y agoPaying for things?
- wizwit999 4y agoWhat's in it for the fraudster here?
- woofcat 4y agoThey own the premium number that the victim is texting... and thus earning the charged money.
- rib3ye 4y agoAh, it's like a 900 number, but for sms.
- Scoundreller 4y agoHas been going on against voip companies since the beginning. Here’s a story from 2005: https://www.forbes.com/forbes/2005/0919/058.html?sh=5531184c6f10 https://www.forbes.com/forbes/2005/0919/058.html?sh=5531184c...
- deleted 4y ago[deleted]
- ipython 4y agoNow if only I could sign one of those premium rate numbers to get robocalled …
- from 4y agoGoogle "international premium rate number" and you can get one in any country for free. Up to $0.7 a minute on some satellite and Albanian numbers if you opt for net 30/45 day payment in some places! This stuff happens everyday - I'm surprised no one has talked about it here till now. It is a very difficult problem to address if you want to accept international users and limit false positives.
- ridgered4 4y agoI remember reading an article where a guy in the UK set one of these up with a bot like Lenny to make money off the scam calls. It was kind of shocking to me you could just setup any number like that, not just 900 numbers.
- lotsofpulp 4y agoThe idea that you can contact a phone number without any idea how much it will cost in 2023 is crazy. At the least, there should be a list of phone numbers known to not result in surprise charges so you can block all others.
- Natsu 4y agoYou'd think they'd have an option simply not to let you connect to those toll numbers at all.
- dima_vm 4y agoThey do: https://www.twilio.com/blog/2015/08/introducing-max-price.html https://www.twilio.com/blog/2015/08/introducing-max-price.ht...
- dhritzkiv 4y agoThank you. I can't believe I missed this API parameter when I was looking to solve our toll fraud issue a few years ago.
- AdrianEGraphene 4y agoWow, ok. I've been hit with this issues twice and both times, the Twilio reps failed to let me know about this. I had previously resorted to just turning off any counties. Looks like mu international app users might get functionality back.... if this feature is still live.
- francislavoie 4y agoDo you happen to know which MaxPrice number would make sense for simple SMS? Figuring it out a reasonable value to use from Twilio's pricing pages is proving quite tricky, because of the amount of dimensions to their pricing.
- dima_vm 4y agoNo, sorry. Wondering that myself.
- alberth 4y agoWhen you want to grow revenue at all costs, reducing/preventing fraud isn't a priority. E.g. why don't they have KYC controls during account opening? Because it would reduce the # of people who open an account.
- bbbbb5 4y agoWhy on earth should Twilio have KYC controls during account opening?
- toast0 4y agoAs a programmatic telephone company, they're a possible (but not really probable) base for fraudulent spam calls. With KYC, and the fact that Twilio requires you call from a number you control, fraudulent calls would be easy to trace back to a person who could be charged for the calls. Much better than status quo, where it's very difficult to get to the originating phone account, and if you could, it's probably not really connected to a person.
- gggggg5 4y agoWhy should Twilio do this when nobody else does?
- toast0 4y agoKeeping their traffic clean makes it easier to interconnect, and in an ideal world, they want to interconnect with everyone
- gggggg5 4y agoSurely the overheads of any useful KYC are way too high for this to work? And basically nobody in this industry does KYC, so how do you propose that would meaningfully affect their interconnects?
- from 4y ago
- jameshart 4y agoThere’s no way to set up an account such that it isn’t permitted to text premium numbers? Throttling to prevent the same number being messaged more than a certain number of times in a given window? Or throttling to prevent charges accumulating faster than a set rate?
- tobinfekkes 4y agoI loved Twilio many years ago, but they've become the new Google/SendGrid/Shopify/Stripe/Uber/(soon to add CloudFlare). They retain the right to any/all the upside of any risk/scale, and you retain the obligation in any downside. No questions. It's despicable.
- mxuribe 4y agoSame here! So, i wonder then, who would be a viable alternative to Twilio?
- tobinfekkes 4y agoUnfortunately, I haven't found any. There are some hacky solutions that I've bookmarked over the years, but nothing reliable enough for a production service(s). At least that I've found. Most "alternative" SMS services a simply a façade built on top of Twilio, with the markup to prove it.
- STELLANOVA 4y agoThere are some alternatives for example: https://wavecell.com/sms/ https://wavecell.com/sms/ While they are mostly known in Asia but they offer service in Europe/North America as well.
- tobinfekkes 4y agoThank you for sharing. Haven't heard of this before.
- jpeg_hero 4y agoi've used these guys: Thinq and they are awesome for sms / messaging apis https://www.thinq.com/sms-mms-text-messaging/ https://www.thinq.com/sms-mms-text-messaging/
- startledmarmot 4y agoHey! I'd naturally recommend SignalWire (as one of the founders over there.) We have a full messaging + voice + video APIs, including a Twilio-compatible API just for people who need to switch. We're backed by companies like Deutsche Telekom, T-Mobile, and Samsung so we know how to make telecom infra! https://signalwire.com/products/cloud-messaging https://signalwire.com/products/cloud-messaging We're also the folks behind the open-source FreeSWITCH framework that powers companies like Bandwidth, Five9, Dialpad, Zoom Voice... maybe even your own company's PBX! https://freeswitch.com https://freeswitch.com
- olliej 4y agoThe fact the Twilio is allowing toll numbers at all is clearly their fault, not that of their customers. Turning around and claiming that customers should be paying for twilio’s bad choices is BS
- rcme 4y agoI'm surprised it's not possible for Twilio to detect premium rate numbers. How does Twilio negotiate the payment with the number holder?
- from 4y agoThese numbers are usually not premium in the 1-900 sense of the word. It's more like they are international numbers and there are various intermediaries who work with mobile/landline operators in a bunch of countries to set up these kind of numbers and split the revenue from incoming calls/texts if they can deliver lots of minutes to them. One way of doing so is by getting a bunch of 2fa texts sent.
- nebula8804 4y agoIsn't this something Elon Musk brought up a few weeks ago when Twitter SMS 2FA stopped working in some countries? (India? I think?). On a Twitter spaces he said they were losing millions to SMS fraud for years and found out that some Telecom companies were complicit so they just cut off all SMS traffic to those companies until they re-negotiated terms.
- ridgered4 4y agoLast time I tried to sign up for Twitter it demanded I verify my account with text messages. Actually, virtually all services do this now when creating an account. The worst (Microsoft for example) let you sign up and use the account for a bit (possibly purchasing some items tied to the account) and then extort the phone number out of you later to maintain access. It is sort of amusing that these companies hitched their wagon to the now scam laden telephone network to track users and ended up getting scammed themselves.
- mylidlpony 4y agoTBH I would consider this type of fraud of a more Robin Hood variety. Companies that still encourage weak security practices like sms 2fa (or even worse, just hoover your PII under the guise of it) should be defrauded of their money as much as possible.
- ectopod 4y agoThis is illegal under GDPR. After someone has signed up for a service you can't then demand additional personal information as a condition of continuing to supply the service.
- trulyhnh 4y agoYep, I remember getting pinged by a coworker asking why is our Twilio bill so high all of sudden. It turns out to be Toll Fraud through 2FA messages. Malicious actors sign up new accounts and setup 2FA number and just keep requesting 2FA through SMS to profit.
- downrightmike 4y agoInsane
- jspaetzel 4y agoTwilio managed to convince everyone that SMS based auth was a good idea but it's always been a bad idea. Drop twilio and go back to using passwords and use a different 2fa method.
- dima_vm 4y agoMost users forget/neglect keeping backup codes for proper 2fa, unfortunately.
- Krisjohn 4y agoWere falling through the computer literacy gap between SMS MFA and authenticator/Yubikey MFA at the moment. While an IT person can do password managers (with secure backups) authenticators, passkeys, and biometrics, all with half-decent opsec, the average user can barely do more than a couple of passwords for everything, and SMS MFA. It's absolutely critical that the companies we support vastly improve their security, but there's no way to get there from here with their staff, lack of any established processes, and zero training infrastructure.
- TheHappyOddish 4y agoLike Authy (owned by Twilio)? Or give them all to (totally not evil) Google?
- admn2 4y agoDoes this Fraud Guard they offer protect against this? https://www.twilio.com/docs/verify/preventing-toll-fraud/sms-fraud-guard https://www.twilio.com/docs/verify/preventing-toll-fraud/sms...
- jwcooper 4y agoAs far as I understand, you need to be using their "Verify" product in order to use the SMS Fraud Guard.
- mannykannot 4y agoThe author says this was added after they started using Twilio and implies they were not informed of the option when it became available.
- Terretta 4y agoYour only power to encourage them to fix this is to do the thing they're begging you not to: dispute the charges. If a threshold of Twilio customers dispute charges, Twilio loses the ability to process credit cards at a lower risk rate, then with all but high risk processors, then may lose the ability to process them at all. If enough of their customers are getting burned, and enough dispute, Twilio would no longer be able to accept credit cards. They are terrified of that, so begging you not to dispute charges for their lack of fraud prevention. You accepting anything less than full refund of all fraudulent use they're cascading back on you is a gift to them. You accepting less than a full refund, while not dinging them at all with a chargeback is also a gift to them. If they don't want to give you the full refund for misuse they should be preventing, dispute it, as is your right. The correct course for Twilio is for Twilio to refund these charges no questions asked while fixing the problem.
- tomesco 4y agoCouldn't Twilio also close and cease providing service to any accounts that initiate chargebacks?
- toomuchtodo 4y agoThey could, but customers could then file complaints with the FTC and their state’s attorney general for the fraud Twilio is enabling. I strongly encourage Twilio customers to pursue this route if Twilio is charging them for fraudulent charges.
- bredren 4y agoThese filings may add up to change at some later time, though are unlikely to provide any kind of near-term actionable remedy.
- toomuchtodo 4y agoSuch is America’s regulatory landscape ¯\_(ツ)_/¯
- tersers 4y agoNothing would make me dispute a charge faster than being told not to dispute a charge
- deleted 4y ago[deleted]
- randyburden 4y agoWe've been hit by this at work as well. We had to add CAPTCHA and a several other techniques to defend against this. How it works: 1. Attacker leases 1 or more premium rate numbers in an international country. - Attacker can lease a premium rate number for as little as $10/month - Typically, the attacker gets to keep 70% of the money generated by the premium rate number. 2. Attacker then finds companies with OTP (One-Time Passcodes) or 2FA (Two-Factor Authentication) endpoints that require no validation and writes a script to automate the webpage or call the API endpoint - Attacker will typically obtain a new IP address per API call using a VPN or a rented botnet from the dark web. 3. If the premium rate number costs 10 cents, then each successful text message they can send to the number generates 7 cents for them. 4. The attacker then just needs to send 150 SMS to the premium rate number to break-even on their $10 investment, not counting the cost of the VPN or rented botnet. There is a lot of money to be made here by an attacker unfortunately. :(
- EGreg 4y agoWith AI, you won't be able to tell humans and computers apart anymore. Anyone with enough determination can execute a sybil attack on any service that doesn't require in-person verification.
- eitau_1 4y ago> premium rate number costs 10 cents wut, the absolutely most ordinary (in the realm of single telecom) text costs me ~6.5 cents
- ender341341 4y agoCan I ask where? I'm in the US and any of the big carriers offer unlimited texting as a baseline, and we have pretty crappy carriers compared to a lot of the world.
- TeMPOraL 4y agoMaybe on prepaid plans? Been a while since I've heard of SMS costing anything on subscription plan, outside of roaming charges. Mobile Internet effectively cannibalized that income stream for the phone companies.
- CaveTech 4y agoWe've been hit by this exact issue, especially over the last month. We tried to mitigate as cleanly as possible for our users, adding one-time nounces to signup requests, adding rate-limiting rules, locking down regions, but we still faced an onslaught of tens of thousands of fraudulent signups per day. On our tier we don't have the ability to set block rules ourselves - it requires a support request that takes 2-3 days to get a response on. Our choices are to eat thousands of dollars per day in toll fraud, or disable sign-ups until we can add more fraud prevention on top of what Twilio enables. The problem is the fraudsters are using real browsers across thousands of IPs located in dozens of different countries. Similar to the OP, Twilio tries to say this is our fault and leaves it up to us to both pay for the issue and to try and fix it.
- csharpminor 4y agoJust curious because you didn't mention it - have you considered putting a captcha in front of your OTP flow? Are the fraudsters also defeating that?
- CaveTech 4y agoWe were trying to avoid the use of a captcha; originally believing that our API infrastructure was the target. A captcha did end up being the solution, but is not particularly user friendly, and I was also trying to avoid pulling developers out of bed on Christmas to implement - but we're protected now!
- charcircuit 4y agoIf you told Twilio to text a number and they text it, I don't see how Twilio is at fault. It would be valuable if they let you avoid texting premium numbers, but that's just a feature on top of the service they provide.
- CaveTech 4y agoThey should be better equipped to detect and prevent the abuse. It's an order of magnitude higher request volume for phone #s located in remote regions of the world. Twilio knows full-well where those numbers go, and can see them being abused simultaneously across many customers. I don't possess the same ability to know this... unless I use Twilio to run a reverse-lookup, which would of course still incur a cost.
- hartator 4y ago> They added a toggle for “fraud guard” Where do you find this? I've spent 10 minutes on our Twilio account and couldn't find the toggle.
- billychasen 4y agoTheir console is very confusing, but if you are using Twilio Verify, you select your Service and tab over to SMS.
- colinclerk 4y agoIf anyone's facing this in their auth flows, we're happy to help at https://clerk.dev https://clerk.dev We're in the same cat-and-mouse game with the attackers as everyone else, but since we're an auth company, we have full-time folks monitoring for issues and resolving when they come up. It's worth mentioning that Twilio is in an understandably tough position here. They only receive API requests from your server, and real requests look the same as attack requests except for the phone number. Clerk is in a better position to help because our API accepts traffic directly from the attacker (e.g. POST /verify-phone-number). We know their IP, user agent, whether they're connecting from AWS, etc, etc. We very much rely on this data to help stop them.
- andrewstuart 4y agoWhen I recently wrote Twilio code the first thing I did was add in as much stuff as I could to prevent this sort of thing happening. I think I put in captcha and also IP address throttling and request counting. At the time I wondered if I was overengineering or gold plating but apparently not. I do seem to recall that Twilio writes about this issue quite alot and includes strategies in its best practices for avoiding the issue.
- deleted 4y ago[deleted]
- Rastonbury 4y agoI use twilio, can anyone suggest alternatives that they've migrated to from twilio?
- yashap 4y agoWe’ve had the same problems. We use Twilio for SMS based OTP login, lost lots of money to toll fraud, and spent lots of time putting up various mitigation strategies to reduce it. Now we only lose a bit of money to toll fraud, but if was lots of engineering effort and $$ down the drain. My main suggestion would be to avoid any sort of flow, like SMS OTP login, that allows triggering SMS messages without being logged in. Just do a more traditional login, SMS OTP isn’t worth the headaches. Haven’t tried Twilio Verify, didn’t exist when we were solving these problems ourselves. But like most fraud prevention, it’s probably far from perfect, better to just avoid fraud-prone workflows if you can.
- deleted 4y ago[deleted]
- kylehotchkiss 4y agoGreat reminder to close unused personal twilio account. I'm not gonna risk these charges to play with their tech!
- jjjjjjjjjjjjjjj 4y agoI spent a lot of time playing cat and mouse with this type of toll fraud in 2022. 1. Rate limited SMS by number/ip: bypassed by large number of proxies/vpn. 2. Added captcha: bypassed by attacker manually signing up thousands of accounts (mechanical turks?) over months and then iterating over them for login OTP. 3. Identifying what carriers/operators are involved and blocking them asap (usually obscure ones). 4. Careful monitoring of SMS send rates and alerting of anomalies to investigate.
- from 4y agoGood advice. By the way, the reason captcha didn't stop it is because Recaptcha is $2 per 1000 solves on 2captcha.com (or any other solving service), at $0.02/SMS this only lowers their profitability by 10%.
- MTmind 4y agoI spent a lot of time working on this exact problem at a "Big Tech Retailer". 6 different teams had worked on it before we did, and all had given up. This is actually a very difficult problem that is at the intersection of two other very big and familiar problems... spam phone calls and bots on the internet. Spam phone calls... the global phone system is a network of relays. No telecom provider connects everyone on the planet together. To call our grandmother in Russia, we may have to go through Verizon, Deutsche Telecom, MTS, and ~five different smaller, regional telecom providers. The first telecom provider will request the second to complete the call, will trust they do this, and will accept the price they charge upon which they'll add their own costs. This occurs recursively until the phone call has been connected and completed. This implicit trust enables fraudulent actors to get into the circle of trust. Verizon may trust Deutsche, Deutsche may trust MTS, and MTS may trust a smaller telecom provider who in turn trusts a spam caller. This enables you to get spam calls. Telecom providers themselves don't know all the callers on the global telecom network and don't really know how much people will be charged. There is no global government to legislate across all telecoms. Bots on the internet... the internet as a whole doesn't have a firm sense of identity. It's just a network protocol routing packets to ip addresses. In the past, these ip addresses were mostly human beings. In the current time, the majority of the participants on the internet are bots/computer programs. A website like "Big Tech Retailer" has >90% of all traffic from computer programs. Elon Musk was probably right that Twitter is full of bots, because the entire internet is swimming with bots. They can be incredibly difficult to detect because AI blurs humans with bots. This toll fraud problem is that bots we struggle to detect place phone messages to phone numbers we struggle to identify. This ends up costing a huge and growing amount of money. You cannot truly solve the problem without solving the two underlying problems of bots on the internet and spam calls. Solutions to those problems may require rethinking and rebuilding the entire communication system we've built our lives around. Nonetheless, we can greatly reduce the effect of this problem. At "Big Tech Retailer", myself and two others we were able to reduce the cost to a small percentage of what it was. After that point, the business sort of stopped caring because the fraud cost less than the staff. There were perhaps five techniques that were most helpful, all of which were contemporary fraud fighting/bot fighting/security techniques. If you're a startup facing this problem, I can help give you some guidance. Twilio will probably see this post and start working on a solution, but that may take a long time. There are easy things you can do to mitigate the problem right now. You can contact me at manrajt@gmail.com.
- wbharding 4y agoWe were defrauded by Twilio as well: https://bill.harding.blog/2019/08/13/twilios-incentives-to-allow-customer-fraud/ https://bill.harding.blog/2019/08/13/twilios-incentives-to-a... Maybe a class action possibility here?
- deleted 4y ago[deleted]
- benlivengood 4y agoCould this stop every random company from asking for my phone number to send me SMS? I hope so. Email works fine, is more reliable, latency is fine, and it works across devices and on desktops. Deduplicate your accounts some other way. Owning a bunch of phone numbers is (clearly, from the article) not a hurdle for attackers.
- a-r-t 4y agoDoes this still apply if only US and Canada are selected in the text messaging geo permissions?
- dahfizz 4y agoThis is the first I'm hearing of this, so I might be missing some information, bit I don't understand how this is Twilio's fault or responsibility. Your service got hit with a ddos-style attack that translated into you using twilio to send lots of texts. This cost you a lot of money. I don't see how this is categorically different than your kid "accidentally" buying movies on Amazon prime or something like that. No way a credit card company would accept a chargeback in that scenario. Ultimately, you used their product in the intended way. Of course you're on the hook for the bill.
- richbell 4y ago> I don't see how this is categorically different than your kid "accidentally" buying movies on Amazon prime or something like that. No way a credit card company would accept a chargeback in that scenario. The issue isn't the scale or volume, per se, it's that a bad actor has set up premium numbers (that cost $$$ to message) and is systematically wracking up fraudulent charges via websites sending 2FA codes. Twilio is seemingly aware of the fraud campaign targeting its users, but is not doing a great job protecting them and forcing them to bear the costs. A better analogy, I think, would be a crime ring skimming credit cards at a gas station and wracking up charges that should be obvious fraud (different country, large amounts, etc.); and when a victim contacts their CC company they go "oh yeah that Shell station is notorious for fraud we've had lots of complaints recently" but refuse to chargeback.
- snake_plissken 4y agoI've read through a lot of the responses and I am still kind of confused how the fraud actually works: 1) Scammer leases a "premium phone number" from a provider. From doing some reading, premium numbers are where the caller/texter pays extra for interacting with the service at this number. So like a 1-900-phone-sex line from back in the day, where if you call, you get charged like $5.00 a minute. The provider leased the number to the phone sex operator for $1 per minute. The phone sex operator runs the service and charges access via your telco at $5 a minute, and ends up netting $4. The telco bills you $5 for your 1 minute call. 2) In Twilio's case, they get a request to send a text to a premium phone number leased by the scammer. This text is actually initiated by the scammer, via something like requesting a new one-time password. Twilio sends the text. 3) Twilio then determines that the destination number is a premium phone number. Twilio charges you extra for sending the text because of this. Twilio then remits a payment to someone, either the scammer or the premium phone number provider. 4) Scammer repeats step 3 a very large amount of times and collects. Twilio bills you for all of those texts they sent, on your behalf, to the scammer's premium number. Step 3 is where I am confused. How do the payment flows work. Is Twilio remitting the money to the scammer, who then needs to pay for the leased number? Or are they remitting the payment to the premium phone number provider, who then pays some portion of that to the scammer? And come to think of it, how does the phone sex line example work? Which entity actually contracts with the telco to set the cost/toll?
- luma 4y agoThe carrier offers the pay-per-call/sms service to a business (like your phone sex operator). The carrier charges the fee and some percentage is given to their customer. So, rent one of their numbers with a fee attached, get a bunch of CAPTCHA texts sent to your number. Your carrier charges Twilio some amount for each call, then sends you a check for some percentage of that.
- iamleppert 4y agoIs it not possible to ban pay Toll numbers in 2FA applications? Why doesn't Twilio do this by default? I would absolutely dispute the charge. Or better yet use only virtual credit cards for these services like Twilio that cannot be trusted, with fixed spending limits and monitor them closely.
- mcstempel 4y agoI find it particularly frustrating that they force you to upgrade to Verify to solve the problem unless you want to build out a lot of your own internal risk detection (which we ended up doing instead) With the rise of AI APIs, I expect we'll see similar attack vectors for apps that integrate APIs from OpenAI or Stability. There won't be a colluding telecomm, but the API output (a completed task) is relatively fungible and far more valuable in itself than a SMS API response. Something to keep in mind if you're building an AI application: https://stytch.com/blog/securing-ai-against-bot-attacks/ https://stytch.com/blog/securing-ai-against-bot-attacks/
- mcstempel 4y agoAlso, a tip for anyone that feels like the low hanging fruit prevention methods aren't working (e.g. CAPTCHA, rate limits, etc.) Consider installing a device fingerprinting system -- this has be the single most effective solution we've seen our customers integrate for more sophisticated bot problems: https://stytch.com/docs/fraud#device-fingerprinting https://stytch.com/docs/fraud#device-fingerprinting. I'd recommend against the off-the-shelf solutions (e.g. open source ones) because many of them are easily reverse engineered, so they work well for low-level threats but not for persistent ones. In addition to our solution, Arkose and Fingerprint Pro are a couple ones I'm aware of
- Raed667 4y agoHad some good results with SEON (https://seon.io/ https://seon.io/) underneath they use fingerprint.js (https://fingerprint.com https://fingerprint.com) to give you a confidence score.
- AlphaWeaver 4y agoI used to work on toll fraud as part of IT for a large tech organization. Not FAANG but several thousand employees. My impression at the time was the fraud detection heuristics helped, but the root cause was scammers working with telcos overseas. Many of these companies have extremely high rates in the first place, and turn a blind eye to the practice because it makes them much of their money. Some VoIP providers like Twilio may be the same. As a middleman / carrier, they will always profit from traffic on their network, even if they disavow it as fraudulent and wag their finger at you about it.
- inetknght 4y ago> Many of these companies have extremely high rates in the first place, and turn a blind eye to the practice because it makes them much of their money Not a telco but loosely related... I will never forget the day I was working for MediaFire (~2013) and complained directly to the CFO about advertisements on the website that directly violated the advertisement policy. CFO stated that "they paid us a lot of money" and that he's late for a ping pong match then walked out of my office. Well, they might have paid the company a lot of money but I was directly not paid a lot of money and was very much burned from friends for working with scum. Suffice to say that people in positions to do things about it should be much less forgiving about it.
- matlin 4y agoWe had this exact thing happen to us. I think the most offensive part is that Twilio still makes money as their customers get scammed so are financially incentivized to keep letting it happen. And on top of that they disrespect their customers by forcing you to prepay for your usage but will still happily let some scammer run your balance into the deep negatives even if you turn off auto-refill.
- jalaziz 4y agoWe faced this at my last company and this is actually a super mild case. In our case, we were dealing with call toll fraud. We ended up with tens of thousands of dollars in charges in less than 24 hours. In our case, Twilio reached out to us to tell us they were detecting toll fraud. Before that, we actually had no idea what toll fraud was. We quickly tried to address it with distributed rate limiting and that worked, for all of a couple of hours. The fraudsters quickly figured out the rate limit and worked around it by spacing out the calls and using more IPs. Eventually, we had to disable a set of countries known for toll fraud and change our product to not connect calls in a variety of scenarios.
- farhadhf 4y agoAnd to top it off, disabling auto recharge doesn't prevent Twilio from charging your account. They won't charge your card but they won't stop processing requests when your balance reaches 0. We were just hit with toll fraud and even though auto recharge was disabled, they continued processing requests until our balance reached NEGATIVE 4,000 USD and then suspended the account. We received to emails in total: 1. Your balance is running low at -65 USD 2. (30 seconds later) your account is suspended, I checked the account an hour later when I saw this email and the balance was -4,000 USD I asked support why they continued charging our account even with auto recharge disabled, but they just ignore the question. Support says it's our fault, asks us not to dispute the charge (although there has been no charge yet as we disabled auto recharge), and said it will take 10 days for finance to issue a partial refund (that was 24 days ago).
- BonoboIO 4y agoLOL. Please don’t dispute the charges. Of course I will.
- BonoboIO 4y agoBoy, Twilio sucks in this story! The Tweets he mentioned, that they lost 200.000 Dollars. Unbelievable. And this „please don’t dispute the charge“ is the icing on the cake.
- xyst 4y agoyet another reason to avoid using SMS to verify users. It's a very poor method that's subject to spoofing and even account takeovers
- cvalka 4y agoUse whatsapp messages instead!
- tripue 4y agoWe faced the same problem at Zenly and had to build our own anti-spam strategies to prevent it since Twilio was not taking care of the problem for us. We used multiple providers to improve our conversion rate and reduce cost. We are now building this as a service https://www.ding.live/ https://www.ding.live/ and are seeing huge improvements for our first customers in term of cost savings and conversion rate. Feel free to reach out if it could be any interest to you hello@ding.live.
- julianilson 4y agoSame thing happened to us, same day. We're now on the hook for $3,500. When Twilio PROFITS from known fraud, they have no incentive to stop it even when it's obvious. (In our case, tens of thousands of premium SMSs to the same number within the span of a few hours). They aren't issuing a refund for us. As an unfunded startup, this is incredibly deflating. We feel robbed, and Twilio should feel ashamed for pocketing a juicy kick-back from the robber for letting them continue their robbery without making a peep.
- 0xWiz 4y agoI trust those with more expertise on the matter understand they nuances and difficulties here better than most or any of us do. This is Twilio we’re talking about - they turned down a ton of money in 2022 political advertising to protect their customers from campaigns that were overly aggressive and had ignored customer requests to opt out. They’re not money grabbing thieves. That’s all to say I imagine this issue is more complex than most of us understand. I will say though this isn’t a great look and hopefully Twilio addresses it. Perhaps there are significant trade-offs to enabling this option by default, but it does _seem_ (from an admittedly naive perspective) like perhaps it’s better to start folks with the training wheels on and make sure they know how to ride the bike before you let them go in the street.