I've just spent hours attempting to get the Twilio "Quickstart" for iOS working. It just doesn't work. And when I looked through the issues on GitHub, I had the *exact same experience* trying to use the app six years ago. Like, how does nobody ensure these examples work out of the box?? #twilio #iosDev
Feds Charge Five Men in ‘Scattered Spider’ Roundup
https://krebsonsecurity.com/2024/11/feds-charge-five-men-in-scattered-spider-roundup/
#AhmedHossamEldinElbadawy #EvansOnyeakaOsiebo #Ne'er-Do-WellNews #NoahMichaelUrban #ALittleSunshine #JoelMartinEvans #ScatteredSpider #SIMSwapping #Mailchimp #Namecheap #Joeleoli #lastpass #T-Mobile #Kingbob #ogusers #Oktapus #Twilio #Tylerb #Okta #Sosa
Open letter about discriminatory practices at Twilio (which likes to claim it is not)
https://medium.com/@wryanmedford/an-open-letter-to-twilios-leadership-f06f661ecfb4
Old friend of mine just got home after being away for almost a year to find Authy Desktop got EOL'd and they can no longer access their backup password. Any recovery tips? Twilio support is autoclosing the tickets...
UPDATE: Thanks everyone! Backup recovered!
Twilio says #hackers identified cell phone numbers of two-factor app #Authy users
Unrelated to the #Twilio breach in 2022.
Looks like threat actors abused an API endpoint, sending unauthenticated requests and getting phone numbers of 33 million users.
Users should be on the lookout for spear-phishing attacks _and_ are encouraged to consider switching to an #opensource MFA/2FA app.
#Twilio has been hacked again – millions of phone numbers of #Authy users in the wild. https://www.theverge.com/2024/7/3/24191791/twilio-authy-2fa-app-phone-numbers-hack-data-breach
And this is not the first time: remember the "#Signal hack"?
https://support.signal.org/hc/en-us/articles/4850133017242-Twilio-Incident-What-Signal-Users-Need-to-Know
@Mer__edith it's time to get rid of the Twilio services for phone number verification. They are obviously not to be trusted.
(1/2)
En cuanto esto fue vendido a Twilio fue la señal de que había que borrar la cuenta. Con Trello tras su venta a Atlassian más de lo mismo. Pero indistintamente, una app de MFA que requiere tu número de teléfono para funcionar? No hay NADA en este tipo de herramienta que pudiera necesitar tu número de teléfono.
"Roban 33 millones de números de teléfono del famoso Authy 2FA"
https://blog.elhacker.net/2024/07/roban-33-millones-de-numeros-de-telefono-authy-2fa.html
Extra: ni caso a sus recomendaciones de apps.
Me arrepiento de usar Authy de Twilio para gestionar la autenticación de doble factor. No solo porque ya no dan soporte en Linux, sino que además no te da la opción de exportar las claves para irte a otro software.
Al final lo he conseguido usando un script creado por un héroe sin capa.
Lección que estaréis cansados de escuchar: no usar software libre sale caro.
#TwoFactor #twilio
Dass man die #Telefonnummer bei #Signal verbergen kann, ist wichtig. Trotzdem müssen wir weiterhin darauf vertrauen, dass die Nummer in den Händen von Signal und deren Dienstleistern sicher bleibt. Man erinnere sich an den #Twilio-Hack (Twilio ist für die Registration und Verifikation der Telefonnummer bei Signal verantwortlich): https://support.signal.org/hc/en-us/articles/4850133017242-Twilio-Incident-What-Signal-Users-Need-to-Know
Wenn #Anonymität das wichtigste Kriterium ist, empfehle ich aber weiterhin einen #Messenger/Dienst zu nutzen, der die Telefonnummer gar nicht erst erhebt, z.B. #Threema, #DeltaChat, #XMPP / #Conversations oder #Matrix. #SimpleX entwickelt sich ebenso gut. Eine gute Übersicht über verschiedene Möglichkeiten findet ihr in der Messenger-Matrix von @kuketzblog: https://www.messenger-matrix.de/messenger-matrix.html #Security #Privacy
Authy desktop app will go away August 2024 and will only be available as mobile app for Android and iOS
What 2fa apps are you using for desktop?
I was using #Twilio for a personal project that allowed me to text my own phone number programmatically.
Twilio is enforcing new anti-SPAM rules in the US, which I get, but the implementation (called "A2P 10DLC") is completely onerous and burdensome, to the point it feels impossible for a hobbyist to continue using Twilio. I just deleted my account.
I'm gonna use Authy*.
Do you understand the pain I am going to go through having to use my landline to get Authy and my work email connected?
And that's only for ONE of these shits.
Literally only 2% of users are going to bother with this BS. This is the last gasp of the bird.
*Maybe not, since hearing of the whole #Twilio hacked debacle.
@feditips I used to favor #Authy, but parent company #Twilio’s breach this year that also compromised several dozen Authy accounts spooked me to laboriously move to @bitwarden. This is possibly related to what I believe is poor stewardship since they purchased it in 2015.
Unlike #Bitwarden, Authy does not provide any import or export options. You should make sure you’re not locked into whatever you choose.
I guess I should do one of those #introductions. I’m a Massachusetts native, living in the San Francisco Bay Area for the past 25 years, software tech worker (current #Salesforce, ex-#Twilio, ex-#SugarCRM, ex-#Netscape, with a few others along the way). Husband to a fellow tech worker (hi April!), #dog dad to a couple of #AustralianShepherds. Listen to too many sports, pop culture, tech, and comic book podcasts. Read too many #comics and prose #books, when I’m not watching too much #prestigeTV.