// the find
morozen/pam_twauth
twauth PAM module enables authentication over Twilio SMS API
A PAM module written in C that adds Twilio SMS as a second factor for Linux logins (SSH etc.), reading the target phone number out of the GECOS field in /etc/passwd. Useful only to someone who wants self-hosted SMS 2FA on an old-school Linux box and is comfortable auditing C auth code themselves.
Repurposing the GECOS telephone field to store per-user phone numbers is a neat way to avoid inventing a separate mapping file. The module does exactly one thing and the source is small enough to read end to end in an afternoon. Setup correctly calls out chmod 0600 root:root on the credentials file instead of leaving that as an afterthought.
The README's own TODO admits there's no syslog logging, no reviewed memory allocation/release, and 'improve error handling and sanity checks' — all serious gaps for something sitting in the auth path. Last commit is from 2015 and only verified against Debian 8; it hasn't been built or tested against any libcurl/PAM combination from the last decade. It links against libcurl's GnuTLS flavor specifically, which is an unusual and fragile build requirement on modern distros. There's no mention of rate limiting, OTP expiry, or replay protection on the SMS challenge, so as shipped it's a weak second factor even if it compiles.