3 ms·
Twilio said the data was accessible between May 10 and May 15, 2024[0]. I mean, even if we disregard the auth codes thing, which according to CCC were being ge
by skilled 2y ago
Twilio said the data was accessible between May 10 and May 15, 2024[0].
I mean, even if we disregard the auth codes thing, which according to CCC were being generated on a static timer, if someone did get access to this bucket - they would have gotten away with a juicy list of phone numbers and names from some of the top companies, at the very least.
I'm not sure how hard it would be for an S3 scanner to guess "idmdatastore", so it is difficult to say if anyone else got in. Even if not, a live database storing live data without encryption or anything is crazy. I feel like IdentifyMobile will feel the wrath of this no matter what.
[0]: https://stackdiary.com/twilio-issues-an-alert-about-a-security-incident-with-a-3rd-party-carrier/ https://stackdiary.com/twilio-issues-an-alert-about-a-securi...