TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Ask HN: Daily Twilio OTP attacks, why, just why?

4 pointsby sf4liferover 1 year ago
We're experiencing daily twilio OTP attacks that create accounts. We block IPs and have throttled rate of account creation. But other than running up our bills (~$10 / day) I don't understand what they gain from this. Why are they doing this? What am I missing?

3 comments

leftcenterrightover 1 year ago
Most likely this is being abused for SMS pumping fraud where rogue network providers&#x2F;small providers complicit in fraud use the traffic to generate revenue.<p>- <a href="https:&#x2F;&#x2F;support.twilio.com&#x2F;hc&#x2F;en-us&#x2F;articles&#x2F;8360406023067-SMS-Traffic-Pumping-Fraud" rel="nofollow noreferrer">https:&#x2F;&#x2F;support.twilio.com&#x2F;hc&#x2F;en-us&#x2F;articles&#x2F;8360406023067-S...</a>
tripueover 1 year ago
They often take a share of the revenue from those attacks through iprn number or other fraud schemes
评论 #37577551 未加载
Raed667over 1 year ago
If your business is local, maybe limit the accepted numbers to a specific area or country.<p>Otherwise try to understand if they&#x27;re automating account creation or are they doing it manually? maybe a captcha&#x2F;turnstile during sing-up can slow them down?<p>Anyway, Twillio really dropped the ball on this problem, but why should they care as long as it keeps making them money?