this post was submitted on 06 Jul 2024
134 points (100.0% liked)

Android

17813 readers
288 users here now

The new home of /r/Android on Lemmy and the Fediverse!

Android news, reviews, tips, and discussions about rooting, tutorials, and apps.

πŸ”—Universal Link: [email protected]


πŸ’‘Content Philosophy:

Content which benefits the community (news, rumours, and discussions) is generally allowed and is valued over content which benefits only the individual (technical questions, help buying/selling, rants, self-promotion, etc.) which will be removed if it's in violation of the rules.


Support, technical, or app related questions belong in: [email protected]

For fresh communities, lemmy apps, and instance updates: [email protected]

πŸ’¬Matrix Chat

πŸ’¬Telegram channels / chats

πŸ“°Our communities below


Rules

  1. Stay on topic: All posts should be related to the Android OS or ecosystem.

  2. No support questions, recommendation requests, rants, or bug reports: Posts must benefit the community rather than the individual. Please post to [email protected].

  3. Describe images/videos, no memes: Please include a text description when sharing images or videos. Post memes to [email protected].

  4. No self-promotion spam: Active community members can post their apps if they answer any questions in the comments. Please do not post links to your own website, YouTube, blog content, or communities.

  5. No reposts or rehosted content: Share only the original source of an article, unless it's not available in English or requires logging in (like Twitter). Avoid reposting the same topic from other sources.

  6. No editorializing titles: You can add the author or website's name if helpful, but keep article titles unchanged.

  7. No piracy or unverified APKs: Do not share links or direct people to pirated content or unverified APKs, which may contain malicious code.

  8. No unauthorized polls, bots, or giveaways: Do not create polls, use bots, or organize giveaways without first contacting mods for approval.

  9. No offensive or low-effort content: Don't post offensive or unhelpful content. Keep it civil and friendly!

  10. No affiliate links: Posting affiliate links is not allowed.

Quick Links

Our Communities

Lemmy App List

Chat and More


founded 2 years ago
MODERATORS
 

Summary

  • Authy is a 2FA app that recently suffered a data breach that exposed more than 33 million phone numbers.
  • An unsecured API endpoint allowed threat actors to collect linked numbers.
  • If you think your personal information might be among the 33 million leaked numbers, consider securing your accounts with 2FA and be wary of SMS phishing attacks.
all 27 comments
sorted by: hot top controversial new old
[–] [email protected] 15 points 5 months ago (3 children)

Lol so what do you do when the 2fa app you use to protect your accounts is breached?

[–] [email protected] 8 points 5 months ago* (last edited 5 months ago) (1 children)

Don't use cloud based 2fa and you won't need to wonder about this.

Aegis is one of several opensource 2fa apps you can use instead.

[–] dog_ 2 points 5 months ago (1 children)

Ok, but what happens if your phone gets stolen?

[–] [email protected] 3 points 5 months ago

The same as for anything else if your phone gets stolen. You restore from backups.

Aegis allows you to make a backup that you can keep yourself on your computer, your own cloud storage etc.

Every OS has some kind of built in vault/encryption feature. Put the file in there. It only needs to be updated when you add another 2fa account (so very infrequently)

[–] [email protected] 2 points 5 months ago

Good question. You would need to start by changing all your account passwords. Next export your 2 factor auth codes. Import your auth codes in a good open source auth app. Then, one by one set new auth codes for your accounts.

This should be sufficient to protect your online accounts.

[–] Substance_P 10 points 5 months ago (3 children)

Wouldn't it be great if independent auditors were standard, responsible for holding companies accountable for their data security practices, coupled with a rating system akin to those used in the banking sector? Before paying for a service, consumers would be aware of how secure the service is. Say A++ or AAA.

It would be a pain in Silicon Valley's ass for sure, but it would go a long way toward giving consumers peace of mind and bringing about a whole new industry in the process.

[–] Carighan 2 points 5 months ago

coupled with a rating system akin to those used in the banking sector

No. No, that really would not be great.

[–] ddonuts4 2 points 5 months ago

This is already a thing but I believe it's mostly only used by government institutions.

Google ISO27001, NIST CSF, FEDRAMP, PCI-DSS, SOC2, HIPAA

[–] [email protected] 1 points 5 months ago

Rating schemes inevitably become subject to gaming and P2W.

Service providers need to be honest about their stack and its implementation, and people need to git gud.

[–] [email protected] 7 points 5 months ago (1 children)

The real important reminder here is that you should never use SMS as your 2FA delivery method. Phone numbers aren't private and once associated with an account it's far too easy to spoof/sim swap and intercept the code.

[–] [email protected] 8 points 5 months ago (1 children)

Someone needs to convince US Banks of this

[–] [email protected] 4 points 5 months ago

That shit drives me nuts. Wanna be trusted with my life savings, but they can't be bothered to implement modern security features until they're already being phased out. I don't know what will replace modern 2FA schemes, but I guarantee banks will adopt the current ones about three years after the replacements become standard.

Also, they're charging you a poor tax for not having enough money, whether that's a minimum balance or just accidentally spending a nickel more than you had on hand.

[–] [email protected] 5 points 5 months ago (1 children)

Avoid using services that ask for your phone number, for your own good.

[–] [email protected] 1 points 5 months ago (1 children)

Unfortunately all of them do, and if you don't give it to them they won't let you sign up

[–] [email protected] 1 points 5 months ago (1 children)

Is there a service that can't be used without a phone number and has no alternative?

[–] [email protected] 5 points 5 months ago (1 children)
[–] [email protected] 2 points 5 months ago

πŸ™ƒ There might be a few exceptions.

[–] [email protected] 4 points 5 months ago

Twilio has a really cool API that lets you resolve phone numbers to what carrier and if it's been ported.

Shame to see they got pwned.

[–] grayhaze 4 points 5 months ago

Just moved all my 2FA over to Bitwarden and Bitwarden Authenticator, and deleted my Authy account. I'd already been using it for passwords, so it was a natural fit.

[–] [email protected] 1 points 5 months ago* (last edited 5 months ago)

Whoops my bad