Summary
- Authy is a 2FA app that recently suffered a data breach that exposed more than 33 million phone numbers.
- An unsecured API endpoint allowed threat actors to collect linked numbers.
- If you think your personal information might be among the 33 million leaked numbers, consider securing your accounts with 2FA and be wary of SMS phishing attacks.
You must log in or register to comment.
That's like saying that the second key of a 2-key nuke launch console is an extra attack vector.
The breach was because of an unsecured API endpoint. No actual auth codes were leaked. without 2FA the attacker would just need your password and email to get account access.
Avoid using services that ask for your phone number, for your own good.
Unfortunately all of them do, and if you don't give it to them they won't let you sign up
Is there a service that can't be used without a phone number and has no alternative?