Summary
- Authy is a 2FA app that recently suffered a data breach that exposed more than 33 million phone numbers.
- An unsecured API endpoint allowed threat actors to collect linked numbers.
- If you think your personal information might be among the 33 million leaked numbers, consider securing your accounts with 2FA and be wary of SMS phishing attacks.
this is why i hate 2fa.
just another attack vector.
Well that’s just oversimplification.
That is exactly like saying having a separate deadbolt on your door is adding another attack vector…
That’s like saying that the second key of a 2-key nuke launch console is an extra attack vector.
The breach was because of an unsecured API endpoint. No actual auth codes were leaked. without 2FA the attacker would just need your password and email to get account access.
Don’t throw the baby out with the bath water