news.volyx.in

Twilio confirms data breach after hackers leak 33M Authy user phone numbers (securityweek.com)

663 points by mindracer · 768 days ago · 396 comments on HN

Article summary

Twilio has confirmed a data breach after hackers leaked 33 million phone numbers associated with the Authy two-factor authentication app. The leaked information also included account IDs and other non-personal data. Twilio found no evidence that the hackers gained access to its systems or obtained other sensitive data. The company has taken action to secure the affected endpoint and is urging Authy users to install the latest security updates.

Main themes

  • Data Breach
  • Two-Factor Authentication
  • Cybersecurity
  • Authy App
  • Phone Number Security
  • User Data Protection

What commenters say

  • Using phone numbers for 2FA is insecure and should be stopped due to the risk of SIM swapping and other attacks.
  • Some users argue that storing 2FA secrets alongside passwords in a password manager defeats the purpose of two-factor authentication.
  • Alternative 2FA apps, such as Aegis and KeePassXC, are recommended as more secure options than Authy.
  • Disabling the 'allow multi-device' feature in Authy can prevent SIM swapping attacks, but may not be a viable solution for users who need to access their 2FA codes on multiple devices.
  • There is a need for regulation to prevent the use of phone numbers as a means of verifying identity, as it is a vulnerable method that can be exploited by attackers.
  • Encrypting user data in databases is not a foolproof solution to prevent data breaches, as endpoints can still be vulnerable to attacks.
  • Some users are concerned about the difficulty of migrating away from Authy due to the lack of an export option for 2FA seeds.
  • The use of phone numbers as a username in Authy is seen as a security risk, as it can be used to access 2FA codes without the need for a password.