I’m also curious how much customer data an attacker should have been able to get into from outside. Is there no 2fa-auth vpn needed to get in? Or is there just lots of customer data hanging out in email/whatever?
I’m also curious how much customer data an attacker should have been able to get into from outside. Is there no 2fa-auth vpn needed to get in? Or is there just lots of customer data hanging out in email/whatever?
The only 2FA that protects against this is a hardware token, like a Yubikey, if used in U2F/FIDO2 mode. Twilio does use Yubikeys for some roles and access types, but not all, and presumably there was enough sensitive data that was only gated by TOTP 2FA.
I think in this day and age, if I were running a company infosec department, I would mandate U2F/FIDO2 for access to every system, and try to structure things so employees don't need to access company systems on their mobile device. (Yes, I know it's possible to do hardware 2FA on mobile, but I feel like it'd create a large IT support burden since it's not always so straightforward.) And if there are company services that aren't suitable for hardware 2FA, they need to be rare exceptions that are granted, and need to be firewalled off from the rest of the company.
A "zero trust" approach where nothing is trusted and you pass through an SSO with MFA like Okta is better in that Okta do a better job in security than "random network team running an unpatched firewall from vendor X" do on average. And each service has an auth layer and doesn't implicitly trust some IPs are good.
In any case, a phishing that captures login+password+mfa means game over in both scenarios.
This is one of the worst pieces of advice to be repeated ad deafenun.
I'm sure there are some VPNs that are implemented a poorly as you describe, but I'm not sure that's the common case like you seem to think.
Which you get from TLS. Strong authentication and authorization per-web-application using short-lived tokens through OAuth/OIDC is about a billion times more robust than any VPN network security.
90% of what VPNs are useful for is connecting you to a non-routable network.
TLS is another _layer_ of security, but it still reveals who you are talking to via SNI and DNS queries, and worse: how often you are talking to them.
It's another story that will drum up support for another integrated authentication system. I say this as someone who was recently targeted in an attack.
It's peek-a-boo, I get that, but damn is it frustrating.
But they'll get what they want. They'll get their secure system.