2FA BEST PRACTICES
How to secure your applications with Authy
TWILIOUSER&DEVELOPERCONFERENCE
KELLEY ROBINSON
DEVELOPER EVANGELIST
2FA BEST PRACTICES
How to secure your applications with Authy
© 2018 TWILIO, INC. ALL RIGHTS RESERVED.
FERDINAND PEREZ
SOLUTIONS ARCHITECT
© 2018 TWILIO, INC. ALL RIGHTS RESERVED.
WHY 2FA?
haveibeenpw n ed. c om
© 2018 TWILIO, INC. ALL RIGHTS RESERVED.
2FA TERMINOLOGY
OTP (ONE TIME PASSWORD)
• Generic term
• Single use tokens, usually numeric
© 2018 TWILIO, INC. ALL RIGHTS RESERVED.
© 2018 TWILIO, INC. ALL RIGHTS RESERVED.
WHY IS SMS 2FA "BAD"?
• SS7 vulnerabilities
• SIM swapping (social engineering)
Link: The Post SS7 Future of 2FA
But it's not perfect
SMS 2FA IS
BETTER THAN
NO 2FA
© 2018 TWILIO, INC. ALL RIGHTS RESERVED.
© 2018 TWILIO, INC. ALL RIGHTS RESERVED.
SMS ALTERNATIVES
© 2018 TWILIO, INC. ALL RIGHTS RESERVED.
Push
© 2018 TWILIO, INC. ALL RIGHTS RESERVED.
TOTP
(Time-based One Time Passwords)
© 2018 TWILIO, INC. ALL RIGHTS RESERVED.
2FA ONBOARDING
© 2018 TWILIO, INC. ALL RIGHTS RESERVED.
© 2018 TWILIO, INC. ALL RIGHTS RESERVED.
© 2018 TWILIO, INC. ALL RIGHTS RESERVED.
© 2018 TWILIO, INC. ALL RIGHTS RESERVED.
© 2018 TWILIO, INC. ALL RIGHTS RESERVED.
© 2018 TWILIO, INC. ALL RIGHTS RESERVED.
© 2018 TWILIO, INC. ALL RIGHTS RESERVED.
© 2018 TWILIO, INC. ALL RIGHTS RESERVED.
© 2018 TWILIO, INC. ALL RIGHTS RESERVED.
🔓SIGNED IN CONTENT🔓
© 2018 TWILIO, INC. ALL RIGHTS RESERVED.
2FA USER
EXPERIENCE
© 2018 TWILIO, INC. ALL RIGHTS RESERVED.
© 2018 TWILIO, INC. ALL RIGHTS RESERVED.
© 2018 TWILIO, INC. ALL RIGHTS RESERVED.
© 2018 TWILIO, INC. ALL RIGHTS RESERVED.
© 2018 TWILIO, INC. ALL RIGHTS RESERVED.
ACCOUNT SECURITY
SESSIONS AT SIGNAL
LUCAS VIDAL
ENGINEERING MANAGER
2FA IMPLEMENTATION
BEST PRACTICES
© 2018 TWILIO, INC. ALL RIGHTS RESERVED.
JOSH STAPLES
SENIOR SALES ENGINEER
Dive deeper into 2FA implementation
DAN KILLMER
SALES ENGINEERING MANAGER
BUILDING PHONE VERIFICATION
AT SCALE
Phone verification seems like a simple thing to build on Twilio right? Create
a random code, send it via SMS and then check it? Not so fast! 
© 2018 TWILIO, INC. ALL RIGHTS RESERVED.
SIMON THORPE
DIRECTOR, PRODUCT MARKETING
HOW TO AUTHENTICATE CALLERS AND PREVENT
SOCIAL ENGINEERING ATTACKS USING TWILIO FLEX
© 2018 TWILIO, INC. ALL RIGHTS RESERVED.
JULIAN CANTILLO
SOFTWARE ENGINEER
With Twilio Flex, we have much more modern methods of authentication to
simplify not only inbound, but also outbound calls.
KELLEY ROBINSON
DEVELOPER EVANGELIST
PRACTICAL CRYPTOGRAPHY
Get an introduction to Public Key Cryptography and learn how Twilio uses it
inside the Authy app.
© 2018 TWILIO, INC. ALL RIGHTS RESERVED.
THANK YOU!
TWILIOUSER&DEVELOPERCONFERENCE
KELLEY ROBINSON
KROBINSON@TWILIO.COM
FERDINAND PEREZ
FPEREZ@TWILIO.COM

2FA Best Practices