49 ms·
Twilio confirms data breach after hackers leak 33M Authy user phone numbers
- khalifaaliumar 2y ago09040246964
- infecto 2y agoGood motivation to stop using Authy.
- fauigerzigerk 2y agoWhat is a good alternative?
- infecto 2y agoMost likely whatever password app you use supports these now. I know for myself, I started using Authy long long ago when there were not really many options. In my case, 1 Password can do this now. I believe the same is true for Bitwarden and Apple passwords.
- fauigerzigerk 2y agoI hesitate to use the same app for both authentication factors. The reason why I started using Authy a long time ago is that it supports multiple devices and isn't linked to any other account (such as Google or Microsoft).
- sofixa 2y agoPersonally I dislike the idea of putting the other factor(TOTP) alongside the main two ones (email/password). Kind of ruins most of the purpose of TOTP and MFA in general.
- lozf 2y agoAlso KeePassXC -- if you don't like the idea of 2FA codes being in the same db as passwords, it's straightforward to use a separate db for 2FA only. Manage your own sync between devices with syncthing, dropbox or whatever you prefer.
- imrehg 2y agoBesides all the other advice of using the password manager as a 2FA store as well, on the stand-alone side there is Aegis. I have good experience with it, and allows better interoperability than Authy as well.
- haswell 2y agoOn iOS, I’ve been using “OTP Auth”. While it’s nice that password managers can handle this as others have mentioned, the whole point of a 2nd factor is to ensure an attacker can’t get in if they somehow get your password. Storing the second factor along with the 1st factor doesn’t make much sense to me.
- attendant3446 2y agoAegis (Android), supports automatic backups. There is also Ente Auth (it's been mentioned on this site), but I haven't used it much.
- cess11 2y agoI'll join the choir and recommend Aegis. It's slick, got features, code on Github.
- rvz 2y agoMy goodness, for the 100,000th time, just stop using phone numbers for 2FA. (I know you won't anyway) There are no more excuses other than asking for your phone to be sim-swapped and your bank accounts or your wallets to be drained by call centers. If this breach doesn't scare you from using phone number for 2FA, then maybe nothing ever will and AI and deep fakes will make this even worse.
- AceyMan 2y agoAuthy doesn't implement SMS 2FA (how could it). A phone number is part of your user profile for registered mobile devices hosting the app.
- Justin_K 2y agoEven worse... Sounds like phone number is irrelevant, yet they collect it.
- oldmariner 2y agoHow else are they going to track people with a hard-to-change identifier?
- Terretta 2y ago> How else are they going to track people with a hard-to-change identifier? Using the device advertisee ID that the user is entitled to change. // Sorry, for a moment I thought you were serious.
- prng2021 2y agoI just did some quick research on these IDs. Correct me if I'm wrong, but it seems like each user account would be tied to one device. It also seems like the user, at least on Apple devices, has to opt into advertising tracking in order for your app to even get access to this. Ignoring the security pitfalls of phone numbers, it really doesn't seem like these advertising IDs are a drop in replacement for using phone numbers.
- simcollect 2y agoHow come companies don't care about encrypting their users' data in their databases? It's been possible for a very long time now. Yet, companies keep leaking. And people keep sleeping.
- sethammons 2y agoWhy would that have helped? The endpoint was exposing the data, not the database. The endpoint would have simply decrypted. encryption of data at rest is for hard drives that walk off, not for access.
- Dma54rhs 2y agoHow to confirm if my number was one of the leaked ones?
- sofixa 2y agoI suppose https://haveibeenpwned.com/ https://haveibeenpwned.com/ will add the information when it can be verified.
- blackeyeblitzar 2y agoAuthy makes it hard to migrate away. Anyone know how to get the seed of the 2FA codes? Is there really no export option?
- conception 2y agoMaybe? https://gist.github.com/gboudreau/94bb0c11a6209c82418d01a59d958c93 https://gist.github.com/gboudreau/94bb0c11a6209c82418d01a59d...
- hypeatei 2y agoAuthy desktop is no longer available and you need a specific version.
- deegles 2y agoYou'll have to reset them one by one.
- snowwrestler 2y agoI use Authy’s iOS app to generate 2FA tokens for a few accounts. I cannot remember ever entering my phone number into it, or establishing an Authy account of any kind. Is there some other way they would have acquired my phone number? I’m trying see if the issue is some unanticipated issue with the iOS client app itself, or if it is only affecting people who created online accounts with Authy to sync their 2FA credentials across devices.
- inhumantsar 2y agoAuthy is both a SaaS and a consumer-facing authenticator app. When companies integrate Authy into their system, they can use it for SMS OTP (also deliverable by phone call + TTS iirc) as well as regular TOTP, Authy's proprietary TOTP, and others. Your phone number would only be at risk if you used a service which used Authy for SMS 2FA
- ffsm8 2y agoThe consumer app also wants your phone number... It prompts you to "backup" your codes, so that they're not gone if you reinstall the app or switch devices you probably gave them your phone number at some point if youve got authy on multiple devices. /Edit: just checked on a clean install. It prompts for a phone number instantly and won't let you scan codes without creating an account. Not sure when that happened, as I haven't really used it in years.
- inhumantsar 2y agoFigures. I stand corrected then. We used Authy for 2FA at my last company and migrated off it to use a complete auth platform. The amount of user (consumer and business) hostile shit we found in the process was astounding. Twilio was nice to work with way back when it was the only decent API-driven POTS connection service out there. They've steadily gotten worse over the years and acquisitions though. Wouldn't recommend them to my worst enemy these days.
- 2y ago
- MenhirMike 2y agoDoes anyone have a recommendation for an Open Source 2FA OTP app? That's the only thing I use Authy for, to scan the QR Codes into the App and generate the 2FA tokens, but in a way that allows me to migrate to another phone without having to re-set all the 2FA tokens on the vendor side.
- WanderPanda 2y agoI‘m using Raivo. It hasn’t let me down, yet
- pxeger1 2y agoRaivo was bought by a shady developer last year and is no longer open source. If that wasn’t enough, a few weeks ago they released an update which deleted all your codes - failing at literally the one job a 2FA app has!
- mm263 2y agoThe same Raivo that was sold to some shady dev who proceeded to delete all of the OTPs that I had in the app? https://www.reddit.com/r/privacy/comments/1d3zqvv/raivo_authenticator_is_broken_after_latest_update/ https://www.reddit.com/r/privacy/comments/1d3zqvv/raivo_auth...
- deleted 2y ago[deleted]
- TheBozzCL 2y agoI use a YubiKey with their Authenticator app.
- notatworkbro 2y agoI've implanted my 2FA token in my arm and just hope it never breaks :D
- fragmede 2y agoWhich one did you get? Did you get the Apex Flex from Dangerous Things? How do you like it/how was the process? https://dangerousthings.com/product/apex-flex/ https://dangerousthings.com/product/apex-flex/
- localfirst 2y agoThere really has to be steep repercussions for companies that fail to protect user data like this. At this point I can't help but feel that there is wilful neglect with the aim of exfiltrating data with unknowable aim. Our digital data must be recognized as human rights but lately the world has been vocal about it but silent when it comes to action and enforcement. More and more reason why people no longer trust cloud hosted solutions. Offline-first, local-first with optional data sync is the only path forward to combat violation of our rights to our own digital data. Case in point, feeding haveibeenpwned with a bunch of HN user handles reveal a good chunk of you aren't even aware your data has been leaked, especially ironic since I see comments from those handles are very anti-regulation when it comes to user data ownership.
- cj 2y agoI agree the US in particular should have better data protection laws and consequences. But phone numbers aren’t something I’d consider confidential in most cases. Hell, we used to publish our phone numbers in physical books and give them to the whole town for free (literally). The data was even monetized with ads plastering every page. I guess the digital age isn’t all that different from the analog age (in certain ways!)
- localfirst 2y agothat was before internet now phone number leaks can be way more troublesome due to the way all of our data is connected to it via 2FA
- olyjohn 2y agoWe didn't use phone numbers to prove our identity back then. It was only used to call you. You often wanted it to be public so you could be reached. Now it's a critical piece of information required to access services online and prove who you say you are.
- duckmysick 2y ago> Twilio has detected that threat actors were able to identify data associated with Authy accounts, including phone numbers, due to an unauthenticated endpoint. We have taken action to secure this endpoint and no longer allow unauthenticated requests How do I avoid such problems in my own app? Force authentication for all requests with row-level security? Rate limiting? Any testing frameworks that would catch this? Something like "given endpoint /user/phone-number-validate make sure only <user> can access it".
- jmvoodoo 2y agoOne step we have taken is to build an auth system that requires you as the developer to explicitly specify the security of an endpoint using a decorator. If no decorator is provided, then the endpoint is completely locked down even to admins (effectively disabled). If an endpoint is decorated with something that is considered dangerous (i.e. public access), that triggers additional review steps. In addition, the authentication forbids certain combinations of decorators and access patterns. It's not perfect, but it has saved us a few times from securing endpoints incorrectly in code.
- hypeatei 2y ago.NET web apps / APIs have an option where you can require authorization on all controllers (and their actions) by default. If you need an anonymous controller/action, you can use the `[AllowAnonymous]` attribute on it.
- api_or_ipa 2y agoYou can easily do the same with most (all?) routers using middleware. Whether you get it slotted in your roadmap is a different story.
- duckmysick 2y agoThat's pretty cool. > that triggers additional review steps Is this done by some sort of a linter running in CI?
- 2y ago
- otachack 2y agoAs alternatives: I use Authenticator Pro on my phone and keep encrypted backups whenever I modify it. I know others have pointed out Aegis. The issue is starting the migration out of Authy. Assuming Authy has no easy export, I suggest you migrate over a few entries at a time (maybe from top down) while keeping account of transfers somehow. You can have authenticators live side by side in the meantime!
- cmgbhm 2y agoYou can rename them as they are migrated
- jmbwell 2y agoiOS/iCloud has a built-in TOTP function also. Maybe better for friends and family than some people here. https://support.apple.com/guide/iphone/automatically-fill-in-verification-codes-ipha6173c19f/ios https://support.apple.com/guide/iphone/automatically-fill-in...
- mococa 2y agoI have been using Apple’s Passwords, it is great.
- blueelephanttea 2y agoIt's good. And the introduction of the Passwords app this fall will make it better. But it seems to me that Apple only supports adding TOTP codes if you have a password for the account. Which is annoying if you want to split your passwords and second factor into two different places. (For example if you wanted Bitwarden for passwords and TOTP/Passkeys in Apple.) You can of course put a dummy password in Apple. But that is kind of annoying.
- hypeatei 2y agoI just migrated off of Authy last week but I was probably caught in this breach, ugh. Never liked it but they make it extremely difficult to export your data. I used this project for exporting: https://github.com/alexzorin/authy https://github.com/alexzorin/authy EDIT: it appears this project was actually using the unauthenticated endpoint (used in breach, too) to facilitate exporting, lol. Good luck to anyone trying to get off of Authy, Twilio really doesn't want you to export your data for "security" reasons.
- Zetaphor 2y agoI also just recently left for Aegis and have been very happy. I feel much better knowing that my 2FA is completely offline
- teamspirit 2y agoRight, I did the same a while back. Aegis for Android and 2FAS for iOS. Never looked back. Also, if anyone is going either direction, Android <-> iOS, both of these open source options allow easy export.
- lifeinthevoid 2y ago2FAS also exists for Android, is Aegis superior or you don't use 2FAS on Android for another reason?
- teamspirit 2y agoDidn’t realize it exists for Android. I use ios now but Aegis was great on Android.
- eviks 2y agoDo they offer a device-to-device sync with the desktop? Or is it all gone if you lose your phone?
- NelsonMinar 2y ago
- smaddox 2y agoNo wonder I've seen such a major spike in spam calls / texts.
- 29athrowaway 2y ago> due to an unauthenticated endpoint. This is truly unacceptable for an authentication product. An authentication product that doesn't implement authentication correctly in their own APIs?
- flutas 2y agoIMO: I'm pretty sure this is less of an auth issue, than it is a rate limiting issue. I haven't been able to find anything about the endpoint, but based on the data exposed[0] I think the endpoint they are talking about is the register one which requires a phone number. I'd bet they didn't rate limit it, and someone just blasted through all phone numbers with it and stored the data for ones that didn't error out. [0] The CSV data columns: account_id phone_number device_lock account_status device_count
- 29athrowaway 2y agoSo it's wardialing via the API then.
- ilrwbwrkhv 2y agoJesus fucking Christ. Can these companies learn how to write software? Quality is dropping like dogs. Twilio used to be a good company and now they are utter shite. Such a shame. Leetcode and bad hiring practices have done this to our industry.
- sethammons 2y agoNeither bad hiring not leet code is a problem with Twilio properties in my experience. Quality however, that gets railroaded by "deliverables" -- the problem is craftsmanship is hard to maintain and manage as companies scale while priority shifts to product announcements.
- ilrwbwrkhv 2y agoThere needs to be penalties. Massive penalties for breaches like this. That is the real problem. Nothing will happen to Twilio even though they caused such loss. They need to suffer economically for this, then quality will improve.
- Zambyte 2y agoIt seems much easier to pin the ever-decreasing quality of software on the practice of trying to keep everything secret (propriety). Like, obviously it's not secure if they don't let people audit it...
- cageface 2y agoAgile practices and the elimination of proper QA are also part of the problem.
- okokwhatever 2y agoI still remember how hard was the process to be hired in this company. Maybe just a mask to hide the sad truth.
- mococa 2y agoI never trusted them, I hated the fact of having to use SMS.
- ndneighbor 2y agoI guess this explains the recent uptick in spam...
- pembrook 2y agoWhile this sucks, my phone is in so many data breaches at this point it doesn’t matter. The spam-to-ham ratio on my phone number is now far worse than any other channel for me. The traditional phone network is at risk of going the way of the fax machine if we don’t do something about the spam problem like we did with email. If I’m on a call, even with family, it’s now almost exclusively on FaceTime/zoom/meet/etc. I can’t remember the last time I talked on the traditional phone network or received a legitimate call. Which isn’t great because those aforementioned platforms are all proprietary walled gardens with terrible incentives — once they capture the market fully they will eventually dump ads all over your calls. Don’t believe me? Just look at what Gmail did to monetize the lock-in on your inbox.
- cjbgkagh 2y agoI think that is intentional, AFAIK phone communication is more protected than other types so allowing spam to continue unabated is in the governments interest. Outsourcing the harassment to 3rd parties, similar to how prison torture is outsourced to the inmates. The government could fix these things but would rather not.
- darby_nine 2y agoI think we just don't have very much competition in telecommunications so things never get fixed. Why bother? It's easier to extract rent off largely the same offerings as the rest of your market (difficult to understand pricing tiers that function as a congestion tax more than a transaction, often region-specific monopolies or duopolies, indistinguishable quality of service) and bring home large profits, market efficiency damned. Yes, I'm exaggerating. No, it's not by much.
- cjbgkagh 2y agoAlmost no-one is pro-spam, it’s pretty much universally hated, and in many cases it’s already illegal so it’s more of a matter of enforcement. It is also trivial to detect. Sure there probably is some regulatory capture but if anything at all can be regulated it’s spam calls / messages. If the government can’t regulate spam then what could it be expected to regulate. The general population is increasing worried about scam calls for their elderly relatives, it’s already a big deal.
- jonathanlydall 2y agoWhen I tried SendGrid it was super annoying that I had to install yet another Authenticator app on my phone. Now it’s become a point of data loss. It’s bizarre to me that Twilio decided to get into the Authenticator business at all, especially while SendGrid had plenty enough problems to keep them busy.
- sethammons 2y agoWhat are some of the SendGrid problems you're thinking about?
- deegles 2y agoI have removed all SMS based 2FA from every account that allows it and you should too.
- exabrial 2y agoThat app is so dumb. Completely negated the usefulness of TOTP. Needs just to die already. Some executive over at Twilio signed the check for Authy acquisition and is still trying to justify the expense.
- yakito 2y agoWe should have something similar to Apple's hide my email for phone numbers
- al_borland 2y agoWe’d probably need dedicated country codes to handle the volume.
- moffkalast 2y ago"Company who thought they'd lost all public trust loses last additional bit of trust they didn't even know they still had, more at 11."
- darkr 2y agoThis doesn’t surprise me. I found an information exposure vuln on the user registration endpoint a while ago (given a phone number of an authy user who had previously registered via another customer, retrieve all other numbers/devices/timestamps, email addresses and other info for that user). It took them two years to fix it.
- rvnx 2y ago> Twilio has detected that threat actors were able to identify data associated with Authy accounts, including phone numbers, due to an unauthenticated endpoint Isn’t it what you are describing?
- darkr 2y agoBased on the reports that I’ve read so far, this vuln was different to the one I found, which was on an authenticated endpoint. Definitely some similarities though, I’d love to see some concrete technical information on it.
- awahab92 2y agowhat do people use instead of twilio today? they make 2dcp verifications take too long
- blackeyeblitzar 2y agoWhat’s a better 2FA product that is E2E encrypted and lets me export the seeds?
- godzillabrennus 2y agoAuthy is basically unsupported. Not surprised. I switched my accounts to 1Password when they announced the end of life of the macOS app.
- bonestamp2 2y agoThat makes sense. In case it helps others... when they announced end of life of the mac app, that was because Apple Silicon macs can run the iOS version of Authy. So, if you have an M series mac then you can still use and get updates to authy.
- encom 2y agoAuthy is terrible. I recently tried to delete my account, because I've (finally) moved everything to Keepass, and they make it as difficult as possible. Then they make you wait 30 days before they actually delete it, making sure to email you constantly in the mean time, to ask you to please reconsider. My 30 days expired a few days ago, so if they had actually deleted my account when I told them to, my info maybe wouldn't have been leaked. Dog shit company. Avoid.
- godzillabrennus 2y agoAfter I transferred everything I only had dead sites no longer around like FTX in the app. I feel like it needs to be left around as a kind of Time Machine…
- mort96 2y agoI chose Authy back in the day because that's what everyone was suggesting. I hate it. I hate the whole cyber"security" community.
- peblos 2y ago> I hate the whole cyber"security" community. Why do you hate the whole community?
- 2y ago
- bonestamp2 2y agoI recently setup a focus profile on my iPhone that only lets calls ring through from knowns contacts. There is going to be an adjustment period as I discover people and companies (such as doctors/hospitals) that I want to allow calls from and add them to the whitelist. But otherwise, it has been really nice to cut down on all of the interruptions.
- al_borland 2y agoYou can flip on the option in the settings to silence unknown callers. It does a decent job, and prevents a lot of the manual micro-managing. I will sometimes toggle it off if I’m expecting a call from an unknown number, but it will also pull numbers it sees in texts and email and known. I manually set this up several years ago, to only ring for contract in my address book. It was annoying, but worked. At the same time, I submitted the feature request to Apple and it came to iOS about a year later. I found my calls have gone down dramatically since using it. I used to get 3-4 calls per day. Now, even if I have the feature toggled off, I might get a couple calls in a month. Once the number appears inactive, I think it drops off a lot of lists.
- bonestamp2 2y agoThank you for drawing attention to this. Whenever I've scrolled past that option in the settings, I incorrectly assumed how it works and it's actually much more useful than I realized. I've adjusted my settings accordingly and I'll give it a chance. Thanks again.
- gz5 2y agoconsider* putting endpoints on a private overlay network in which network access is cryptography-gated (e.g. x.509 cert based). then, a misconfigured endpoint (or a zero day etc.) can't be exploited by any_actor_on_the_internet - actors need to first complete the provisioning process you choose to enforce to be authorized to use the private overlay. *not one size fits all, e.g. bad option if endpoints need to accept requests from unknowns. however, many endpoints only need to accept requests from known (identified, authenticated, authorized) endpoints, and the added friction to id/authN/authZ get use the private overlay is not a business impediment. there is a stigma here due to the horrors of NAC on private enterprise WANs. but NAC goals can be accomplished without that baggage via internet overlays and modern cryptography. to be clear, i am by no means advocating to abandon traditional methods of endpoint auth - this it is just another layer which recognizes that single layers are rarely airtight (e.g. what just happened to Authy and Twilio).
- hypeatei 2y ago> many endpoints only need to accept requests from known (identified, authenticated, authorized) endpoints Do you mean clients for the last part? I'm not a networking expert but I don't see how layering on certs here is going to help?
- mihaaly 2y agoAnd they wonder in random organizations and businesses that I am not willing to give all my personal details right away on first contact despite their 'utmost importance' of handling my data very securely, all this just to be informed about their product. And they seems to be offended with a "but we did it so for many years now" on my refusal and saying goodbye if they try to insist this "company policy". Unluckily sooo many give zero or negative fáck among their potential and existing customers. This includes businesses providing medical services sending all the clien't data and medical results in clear text email and even declaring for their own convenience that "The property and copyright or other intellectual property rights in the contents of any document or images provided to you shall remain our property", for your ultrasound results. Your medical results are their property for those use their services. So they do as they plase with their data, not your data, not your concern if it is protected or not. And people go there and rate this service 4.8 on google, insane. Of course no-one really reads TOC, not even for sensitive medical services. People do not learn.
- surfingdino 2y agoBritish Gas has taken to removing their bank account details from their invoices so that you have to set up an online account with them and then set up a Direct Debit (permission to take arbitrary amounts of money from your UK bank account).
- ehPReth 2y agois this just like anotherservicetwilioruined.example.com/api/doesthispersonhaveanaccount?phone=+12012000000 and then the service says 'yeah that number has an account' (and nothing else?)? then whomever repeats that for every possible phone number? or... more than that?
- vishnumohandas 2y agoWe built ente.io/auth If you need a cross platform authenticator, do check it out. FOSS, optional e2ee backups.
- deleted 2y ago[deleted]
- memset 2y agoI switched to this from authy months ago and never looked back. Thank you! I followed this guide - basically, run an older version of authy with devtools enabled and use the js console to export your items. https://gist.github.com/gboudreau/94bb0c11a6209c82418d01a59d958c93 https://gist.github.com/gboudreau/94bb0c11a6209c82418d01a59d...
- vishnumohandas 2y agoGlad to hear Auth is being useful! If anyone else is considering a switch, our community has documented a migration guide here: https://help.ente.io/auth/migration-guides/authy https://help.ente.io/auth/migration-guides/authy
- kylehotchkiss 2y agoTwilio requires Authy for 2fa for sendgrid and maybe even twilio itself instead of supporting more standardized 2fa that’d allow 1pass to be used. This is all the more frustrating because I was forced to use Authy to protect an account instead of my regular tooling and they still managed to screw it up. Twilio, take a hint and stop forcing people to use your custom thing https://www.twilio.com/docs/sendgrid/ui/account-and-settings/two-factor-authentication
- qingcharles 2y agoUgh. I hate that some apps require use of specific auth apps. This should not be a thing, we have great generic systems for this already.
- mort96 2y agoI just hate that some apps/services require 2FA. My 32 random characters which are unique to each service are secure enough. Adding another service on top just increases risk (as shown here; Authy was never going to do anything to protect me, but it has now leaked info about me.)
- cqqxo4zV46cp 2y agoNo. TOTP MFA’s mechanics make it a significant security improvement regardless of how impressively large (???) your password is. It doesn’t inherently implicate “another service”. That’s the beauty of it. This issue is SPECIFICALLY due to forced use of Authy. Forced MFA for high-value accounts is a good thing. “A long password will protect me” is 2006 thinking.
- raincole 2y agoWhat happens when you lose your phone then? Do you have recovery code printed out? Do you carry them with you? If you do then what's the difference between this and a password?
- Featherknight 2y agoSucks that Twitch.tv still relies on it. My only service that uses it still, I’ve since migrated to other managers
- xyst 2y agoTerrible. Glad I moved away from Authy a long time ago. Small reminder that I need to delete the account though.
- jordigh 2y agoTook a while, but this commenter is finally correct: > Why does Authy require I provide my cell phone number and email address? Why do I have to have a user account? This is completely ridiculous. I do not need nor want cloud syncing or backup. You are making Authy a potential target for attacks by associating a user to cloud stored 2FA information. > This is not in the spirit of 2FA. https://news.ycombinator.com/item?id=9100560 https://news.ycombinator.com/item?id=9100560
- deleted 2y ago[deleted]
- 8474_s 2y agoYou can't pick and choose "Not a real scotsman" since 99% of users will be on bigcorp 2FA that does it in most ass-backwards way possible. 2FA as mobile apps locked to hardware is not going to go away without 2FA being replaced by something else.
- brewdad 2y agoThe entire use case for Authy is the cloud backup and syncing across devices. If you don’t want that, use any of the other free and more open 2FA apps.
- deleted 2y ago[deleted]
- akamaka 2y agoTwilio was forcing users to install Authy. See this thread: https://1password.community/discussion/116314/sendgrid-requires-authy-for-2fa-can-i-use-1password-instead https://1password.community/discussion/116314/sendgrid-requi...
- j1elo 2y agoThen make it an independent email+password thing, so in case of a leak, something as critical and personal as a phone number doesn't get involved in the stolen data. (I know the irony of this in particular being Authy, but nevertheless phone numbers should NOT be risked to be exposed anyhow)
- instagib 2y agoFor iPhone, put the phone in do not disturb. It will send all calls to voicemail. If someone is on your emergency contacts, favorites, or 1by1 focus then a repeated call will actually ring your phone. Otherwise no notification. Not even a text counter increase unless the person taps (notify anyway). Tried to do the same on an android phone and it didn’t work. You can also port your phone to google voice or Fi and give away all your call information to them. Very few spam calls get through their filter. I like the change phone area code to out of area and block all phone calls from that area that some call services provide.
- rcostin2k2 2y agoActually, I have a Samsung S20+ and "Do not disturb" works pretty well, even scheduled
- denkmoon 2y agoIf you've got anything in Authy that isn't using the authy custom authentication scheme (ie. just regular TOTP) now is the time to get it out. Exporting the raw totp tokens can only be done from the desktop version that is currently deprecated and scheduled to be nuked from existence later this year. It requires getting the tokens loaded into the desktop app, then downgrading to an older version so you can use the chrome remote debugger to run a javascript function against the desktop app (embedded chromium) which pulls out the raw tokens and gives them to you.
- mort96 2y ago> Exporting the raw totp tokens can only be done from the desktop version that is currently deprecated and scheduled to be nuked from existence later this year Oh. Fucking great. So I'm locked in to using Authy forever now I guess. I hate 2FA. It literally does exactly nothing for security, it's just another tool for these big companies like Google and Twilio to put themselves between me and the services I need access to, all while locking me in to their services and siphoning out information they can sell to advertisers. I hate it. I hate the "security" people who are pushing this garbage. I hate everyone involved in this space. I hate that I now can't log in to anything without going to fetch my phone. I hate these people.
- denkmoon 2y agoHaha, I see you manically rage posting in this topic. I empathise, it's fucking shit when "smart" people foist something unwanted on you because they think it's better for you. FWIW, I'm feeling pretty liberated to have moved my OTP codes out of authy and into multiple locations - my data, as much as I'd prefer not to use it, is now under my control. You can get the old desktop version from chocolatey/choco - https://community.chocolatey.org/packages/authy-desktop/ https://community.chocolatey.org/packages/authy-desktop/ If anyone wants to try this themselves, this is the recipe that worked for me; - Enable multi device for authy on my phone - Install the 3.0 desktop authy client from chocolatey - Get logged in and set up on the desktop client so that you can see the current OTP codes (not the lock symbol) - Uninstall the 3.0.0 desktop authy client - Install the 2.2.3 desktop authy client from chocolatey (https://community.chocolatey.org/packages/authy-desktop/2.2.3 https://community.chocolatey.org/packages/authy-desktop/2.2.... or choco install authy-desktop --version=2.2.3) - DISCONNECT FROM THE INTERNET AFTER OPENING 2.2.3 AND BEFORE IT POPS THE UPDATE DIALOG - The update dialog will block the program and you can't use the chrome remote debugger in the later steps - Start from step 2 of https://gist.github.com/gboudreau/94bb0c11a6209c82418d01a59d958c93 https://gist.github.com/gboudreau/94bb0c11a6209c82418d01a59d...
- 486sx33 2y agoDamn 2FA with telephone numbers, I hate it!
- Fire-Dragon-DoL 2y agoI had to use authy for damn twitch which couldn't go for normal authenticator. Thank you -.-
- andrewstuart 2y agoCan you imagine being the one to tell the CEO.
- ZunarJ5 2y agoI have to thank this hacker for motivating me to move fully off this app again. Stopped being useful without the desktop app.
- xarope 2y agoI have resisted moving off Authy as I liked the idea of cross-platform cloud sync. That'll teach me. Any other suitable alternatives? Aegis is android only. I do run vaultwarden, but it means I need another 2FA to login to it, before I can use it as a 2FA for other sites.
- Inocez 2y agoBitwarden released a standalone authenticator app recently. You can give it a try. https://bitwarden.com/blog/bitwarden-just-launched-a-new-authenticator-app-heres-what-it-means-to-users/ https://bitwarden.com/blog/bitwarden-just-launched-a-new-aut...
- jszymborski 2y agoKeePassXC (and the associated apps) can store TOTP, and you can sync it with SyncThing on any device. Add an always-on NAS with SyncThing and you'll always have an up-to-date vault, even when your other devices are offline.
- pndy 2y ago2FAS - https://github.com/twofas https://github.com/twofas and I did replaced Authy with it some year ago; I'm using it mainly on iPhone while having a backup file on desktop and second app installed on Samsung phone
- eviks 2y agoCould try that FOSS ente app And there is a FOSS app I forgot the name of to allow exporting Authy tokens from cli
- zenkan 2y agoOne major problem I see with this hack is that the phone numbers exposed in the leak is the single factor of authentication needed to get access to an Authy account, including all the MFA tokens that the account has saved. If there are any high-profile victims in this list SIM Swapping those phone numbers should be a very attractive approach. I think security cautious companies should consider turning off multi-device support and start planning for a migration. This leak feels way riskier to me than what media reports it to be.
- eviks 2y agoBut it's not the single factor? > There are account recovery options outside of multi-device, but those require the attacker to compromise your primary email. These also take a minimum of 24 hours, during which you would receive email notifications, and could request a cancellation https://help.twilio.com/articles/19753631468059 https://help.twilio.com/articles/19753631468059 And for multi device you can require current device to approve new ones
- zenkan 2y agoI just had to try it out now to make sure I'm correct on this and I believe I am. Here's what I found: Multi-entity is enabled by default when creating an account. Enrolling a second device is possible via an OTP code received via a text message. This makes the phone number (in my mind at least) the default single-factor needed to access an Authy account. As far as I can tell, the user has to either enroll either a second device, or manually disable multi-device support to make Authy SIM swapping resistant. I have not been an active Authy user for many years now so I might be mistaken here, but I strongly suspect a majority of Authys non-technical users have not done either. Meaning they would be susceptible to SIM Swapping attacks. My old Authy account definitely was, at least.
- m00x 2y agoIt's sad how awful Twilio's engineering has become. I used it super early on and it was amazing, and while they had hiccups, they were never major and they were growing pains. Today they have incidents almost every week, and now data breaches.
- original_idea 2y agoYeah, its not surprising what a bunch of layoffs will do. The Authy people have been gone for a while.
- MaxHoppersGhost 2y agoThe company has had terrible profitability metrics and needed to cut a ton of fat. Maybe they laid off the wrong people though.
- maerF0x0 2y agoNot financial advice: Also having an investor base that demands removing as much equity compensation as possible. (Whilst, IMO, not being aggressive enough to cut executive compensation) But it's no surprise that when you ask management/executives "who needs to be laid off", the answer is not that many managers/executives... I do think Kho is the right person for the job though, and Aidan was surprisingly smart too, so I my[1] bet is that they'll get there. [1]: I'm long twilio btw.
- hi-v-rocknroll 2y agoAuth0, Authy, Okta, and the like were and are the fail of delegating critical functions to third-parties. For authentication, authorization, and 2FA, run it yourself on-prem or go home.
- m4tthumphrey 2y agoI only answer the phone now if I know the caller or if I’m expecting a call, and even then I would usually let it go to voicemail and call them back.
- tristor 2y agoSo fun story, I recently switched away from Authy for various reasons, but the key one was that I had to restore from a backup on a device and when I did so I realized the Authy had never actually deleted any of the 2FA/TOTP accounts I'd configured over the years, things that had been deleted on device literally 5+ years ago were still stored and available on request via their API. In general, after that I started poking, and discovered a lot of things I hadn't bothered looking into before that make me extremely suspect of Authy's general security. For those looking for an alternative, I use 2FAS and Yubico Authenticator with a Yubikey now. Yubikey only allows you to store up to 32 TOTP slots, which is very limiting (I have more than 60 TOTP accounts for 2FA), so I use two apps and "tier" my 2FA.
- maerF0x0 2y agoIt feels funny to say "Hacker" when it was just someone one using something on the open internet the way it was (defacto) designed for, and just used it a lot. Like if I crawl hackernews and download all the somethings am I a "hacker"? To me a hack is some kind of escalation of privilege beyond what I'm truly entitled to (such as stuffing passwords, tricking software to run a payload, crafting a payload for service A so that it tricks Service B) ... Not using curl on a loop.
- otterpro 2y agoThe main reason I didn't use Authy was that it requested phone number when signing up, and it didn't make any sense to me why they'd need it. Since then, I've been using 2FAS, since there's no personal data that can be leaked.