9 ms·
Twitter Lost $60M a Year Because 390 Telcos Used Bot Accounts to Pump A2P SMS
- paulpauper 4y agoI remember someone did this on a smaller, individual scale. Billing a company for SMS messages..I think it was Starbucks or something. This was 4 years ago, it was shared here.
- ayewo 4y agoIn practice, how does the fraud work?
- pcthrowaway 4y agoI think it might be like this one: https://news.ycombinator.com/item?id=34265433 https://news.ycombinator.com/item?id=34265433 Telco companies allow people to set up numbers which cost money to send an SMS to. Then those people set up bot farms to register for Twitter repeatedly, triggering a verification text, which Twitter then has to pay. The telcos aren't committing the fraud directly, but they are profiting from it.
- worksonmine 4y agoWow that's so much more retarded than I expected. I thought it was the telcos setting up bots to get an increased amount of texts with standard fees. Simple, difficult to detect. My private number can't send texts to premium numbers, that an automated 2FA system could is so ridiculous I would never even try it. I guess that's why they're better fraudsters than I can ever be, they expect this level of stupidity while I'm surprised.
- disiplus 4y agoThe problem is, globally you cannot know before is this a premium number or not for some random provider in some random country, so what happens is you send the sms and then bill the number.
- worksonmine 4y agoIf my provider can prevent me I'm sure the tech companies with millions in funding can figure it out. Block anything that doesn't comply. I figured this was solved, aren't there SaaS companies with deals all over the world for texts already? If not there's an opportunity. I'm sure it's cheaper than $60M to have full-time employees vet the numbers and new providers showing up.
- pcthrowaway 4y agoDid you not click parent link to this thread? Twilio (the main SaaS company that does this) doesn't have a good solution here
- praisewhitey 4y agoLooking in that parent link it looks like they do, but it's not a default setting https://www.twilio.com/blog/2015/08/introducing-max-price.html https://www.twilio.com/blog/2015/08/introducing-max-price.ht...
- lupire 4y ago> Telco companies allow people to set up numbers which cost money to send an SMS to. That's cleary being an accomplice. That's like a business that sells a service of smashing windows of any car that drives by your home.
- wodenokoto 4y agoThat's how you bought ringtones back in the day. It's still how you donate money to Unicef.
- longemen3000 4y agoI suppose that Twitter has to pay each time a SMS is sent (ar at least, they pay according to the amount of SMS generated), so the bots pump that amount?
- PragmaticPulp 4y agoI can believe fraud was happening. I have a harder time believing that 390 different telcos were all running the same fraud to the tune of $60 million per year and none of the previous Twitter administration thought to check into it. This feels like another one of those claims that has a kernel of truth, but gets exaggerated for dramatic effect as a PR move. Like those drug busts that find a small amount of drugs, but then use the entire weight of the container it was found in multiplied by the highest possible street value they can imagine so they can claim a gigantic number in the headlines.
- pcthrowaway 4y agoI think Elon was suggesting that Telcos were turning a blind eye to the fraud that was damaging twitter, not that they were committing it directly. I think this is actually the first sensible thing Elon has done since the takeover
- rhaway84773 4y ago> Basically, there are telcos who are not being super honest out there, in other parts of the world, who were basically gaming the system and running, like, two-factor authentication SMS texts over and over again, and just creating a zillion bot accounts to literally run up the tab so that Twitter would SMS text them, and Twitter would pay them millions of dollars, without even asking about it. He’s very clearly accusing the telcos themselves of creating bot accounts.
- pcthrowaway 4y agoTrue, his messaging wasn't consistent. He is calling them fraudsters (and suggesting some of them are doing it directly). Some of the fraud may be indirect though: > Listen, if you stop scamming us, then we will gladly pay you some amount of money for SMS texts but you can’t turn a blind eye to relentless bogus SMS texts The suggestion here is that the telcos are complicit in the fraud, but "blind eye" suggests they may not be directly responsible.
- foobazgt 4y ago$60M in fraudulent texts alone is wild. I couldn't imagine being the director responsible for those costs and not having investigated earlier.
- foobazgt 4y agoTo put this in context, you could have hired a 100 person org at that run rate... from fraudulent texts alone. How does that go unchecked? Mind blown.
- aaomidi 4y agoI’m here looking for 2-3 MUSD a year to start a new CA meanwhile Twitter here burning 60 M over text messages.
- qup 4y agoHow often do you contrast your personal finances to that of the biggest companies on the planet?
- aaomidi 4y agoQuite often in fact with relation to starting a CA. More companies should start CAs. It’s a good thing to help the webtrust ecosystem.
- MasterScrat 4y agoWhat's a CA?
- aaomidi 4y agoCertificate Authority
- deleted 4y ago[deleted]
- oxfordmale 4y ago
- lvl102 4y agoReally goes to show how poorly run Twitter was from the very beginning. Jack Dorsey probably doing the same thing with Square right now.
- hypothesis 4y agoIf someone made a fortune at Twitter by running it “poorly”, would it not be reasonable to try it again next time? Just chill at a sunny beach and let someone else figure it out.
- guax 4y agoTwitter growth, revenue and eventual sale is the absolute dream of so many companies that its kinda funny reading people here calling it the worst thing ever because of this.
- chrisgd 4y agoMakes more sense anyway why now only Twitter blue accounts can use 2FA
- yellowpencil 4y agoWhich company does Twitter use to send these SMS messages, Twilio?
- Oras 4y agoAssuming an average sms rate of $0.04, they have sent 1.5 billion messages a year. 2022 stats indicate Twitter had 396.5 Million users. So for the full picture, it would be around 5 messages per user per year, which I don’t see as a large number. This might be why it wasn’t unnoticed.
- OJFord 4y agoWith your numbers (not checking) this would be 1.5B supposed new users requesting to sign up (or existing ones verify a new number I suppose) and then bouncing, every year. Which is a lot if you have 0.4B completed-signup users, and shouldn't go unnoticed.
- cptaj 4y agoThose are not the only times when 2FA happens. It happens every time you log in after closing a session. This could be multiple times a day for some users.
- deleted 4y ago[deleted]
- OJFord 4y agoIt's really surprising this can go unchecked: 1) it makes the cost of acquiring users artificially high, since its an expense that doesn't lead to a completed signup 2) you'd think the verification process would be monitored anyway, in case of deliverability issues or false negatives on checking the codes - even if not spikey because this was always happening, surely the high baseline 'code requested and never entered' would raise questions?
- VirusNewbie 4y agoI worked for a telco that did SMS and voice, and while we spent time investigating and shutting down various scams and spam, I never saw this one.
- TheLoafOfBread 4y agoAre you trying to tell me, that Elon is lying again? No way.
- VirusNewbie 4y agoIt very well could have been only targeted at poorly managed big companies, but I didn’t see this despite seeing quite a lot of scams. This was a smaller telco though. When I worked at one of the largest telcos I wasn’t involved in SMS.
- netsharc 4y agoWith the number 390, it's either "Every man in this village is a liar" or it's one man saying his own version of the facts is the true one...
- throwawaaarrgh 4y agoWhy is he sitting on some weird video conference for hours just talking at strangers? Is this a thing other CEOs do? Is he lonely?
- diebeforei485 4y agoTwitter Spaces is an audio chat room. It's good for company leaders to use the company's product actually. He was probably on a plane or something.
- foogazi 4y agoLets check it with @ElonJet
- americafun 4y ago> But perhaps we should not be surprised by the lack of interest in fraud exhibited by Twitter’s former management. The tech industry in general suffers from a cancerous disposition towards encouraging fake traffic, fake users, and fake online activity because it makes businesses appear to be more successful than they really are. Criminals are fed millions of dollars by executives who think that price is worth paying if it will mislead investors into believing inflated valuations. The presumption is that current losses are also worth sustaining because the business will turn today’s paper valuation into real value at some vaguely-defined point in the future. That's it. If you can't figure someone's intentions, look at their actions, and infer the intentions.
- moremetadata 4y agoI think this TikTokker found out to her peril that a million followers many of them bots can be expensive and humiliating. Same TikTokker different Reddit Threads. https://www.reddit.com/r/TikTokCringe/comments/vkv8hu/aww_this_tik_tok_creator_with_a_million_followers/ https://www.reddit.com/r/TikTokCringe/comments/vkv8hu/aww_th... https://www.reddit.com/r/sadcringe/comments/wf1a0k/nigerian_tiktok_star_organises_a_meet_greet/ https://www.reddit.com/r/sadcringe/comments/wf1a0k/nigerian_... Still those bots probably helped make TikTok popular and probably helped boost stock prices, like we see with other social media platforms and even SuperStonk! https://www.reddit.com/r/Superstonk/ https://www.reddit.com/r/Superstonk/ If you or someone you know has a social media presence with people you dont know, do the <s>computer</s> bots say no?
- hrunt 4y agoAt a previous job, we had a product that was attractive with criminals. We were seeing some elevated chargeback rates and refund rates, so I dug in and determined that at least 25% of our new account purchases were fraudulent (unreported stolen credit cards). I put in some rudimentary fraud analysis, and injected a hoop that suspected fraud users had to go through before their account would be billed, simply to prevent the credit card networks from blacklisting our merchant account. The fraud rates dropped considerably with a small false-positive rate, but the new-user metrics slowed with it. A week after I left my role, the company disabled it. They were sure that the system was a significant cause of some major userbase declines. Within three months, one of their credit card processors threatened to lock them out for elevated fraud rates, and they spent the next six months getting it resolved. Growth never returned. No one was trying to be dishonest, but no one wanted to look bad, either. The entirety of the metrics showed something was off, but the growth narrative was so important, it was easy to ignore the questionable parts. This was not a VC-backed business, so the pressure to perform was entirely internal. Nothing was faked, but the success wasn't (entirely) real, either.
- deleted 4y ago[deleted]
- MarkMc 4y agoFor those who doubt the old Twitter management could be so incompetent: These are the same people who never noticed they were showing me ads in a language I couldn't understand whenever I went on vacation.
- Scoundreller 4y agoIt’s not just twitter that does that. Could blame the advertiser: can they filter by language and chose not to?
- Ankaios 4y agoDoes anyone run a blackhole list for these numbers and operators? (Or a historical phone number -> SMS price mapping?) In a sane system, no one should pay fees unless they're listed up front. Lacking that, a way to identify and avoid bad actors would be helpful.
- def_true_false 4y agoPaying for incoming texts and calls is not common outside the US. When you call or text someone, you pay the fee listed in your contract (not theirs). That is to say, the sane system exists and most countries use it. Edit: Ironically, it seems that this can also be foot-gun: https://news.ycombinator.com/item?id=34847873 https://news.ycombinator.com/item?id=34847873
- deleted 4y ago[deleted]
- Ankaios 4y agoPreventing the fraud described in your edit is what I'm asking about. I'm wondering if anyone has set up lists to help avoid surprise prices for sending messages via SMS service APIs, not from texting someone from a phone.
- archagon 4y agoThis title needs to be prefixed by “Elon Musk Says.”
- two_handfuls 4y agoThis is an interesting article, but I was distracted by the Byzantine ways people write “millions of dollars.” I’ve seen “MM” before, and now “mn”. Perhaps I’m the only one who is fond of standard prefixes and uses “M$” for millions of dollars.
- ksherlock 4y agoTo me, M$ will always mean Microsoft. Although given inflation and revenue growth, maybe M$ is B$
- ravagat 4y agoUnfortunately this is a case and proof of the classic kickback scheme that occurs in many corporate companies. Also common in many bureaucratic companies, countries. If you don't think $60M/yr is real, you are in a hell of a seat when you see the billing/accounting that goes in corporates and governments.
- platypusrex256 4y agoSource?