Live data from Hacker News

Ask HN: Why did smartphones become a single point of failure?

news.ycombinator.com

11–20 of 289 posts

Re: Ask HN: Why did smartphones become a single point of failure?

#11

Because using phone numbers to decide if human or bot is cheap, easy, and effective. Politically, there is no will for a national identity verification type service as infrastructure. And this way, all the work gets outsourced to ATT/Verizon/T-Mobile, and politicians get to say “it is not our fault” and telecoms get to say “it is not our job”.

And scamming yourself to another persons phone number to entirely take over their digital life is also cheap, easy and effective.

Re: Ask HN: Why did smartphones become a single point of failure?

#12
post #2

>i can't log in to any of my banks without my phone. Don't know about banks in Europe but in USA, I can log into Bank Of America and JP Morgan Chase without any phone authentication. If I reformat my harddrive or buy a new computer and the bank doesn't recognize the web browser because no previous cookie has been found, the website will generate a one-time code and send it to my email address. I then enter that secur…

In Europe we have it in few countries.

In my case - You enter your unique ID (6 numbers), then I’ve to type 4-number PIN on my phone. There’s also verification-number shown on both sides, to compare authenticity . When approving payments, it also shows details and requires longer PIN code.

Much easier than earlier versions.

And authentication provider can be used at Insurancy, e-government, e-signing and other services.

Re: Ask HN: Why did smartphones become a single point of failure?

#14
post #2

>i can't log in to any of my banks without my phone. Don't know about banks in Europe but in USA, I can log into Bank Of America and JP Morgan Chase without any phone authentication. If I reformat my harddrive or buy a new computer and the bank doesn't recognize the web browser because no previous cookie has been found, the website will generate a one-time code and send it to my email address. I then enter that secur…

I can log into my bank without my phone in Denmark, but they are pretty much getting rid of that capability. Supposedly more 'secure'

Re: Ask HN: Why did smartphones become a single point of failure?

#15

Because using phone numbers to decide if human or bot is cheap, easy, and effective. Politically, there is no will for a national identity verification type service as infrastructure. And this way, all the work gets outsourced to ATT/Verizon/T-Mobile, and politicians get to say “it is not our fault” and telecoms get to say “it is not our job”.

You don't need a smartphone to have and use a phone number. I suspect the OP is about smartphone app authentication.

Re: Ask HN: Why did smartphones become a single point of failure?

#16
post #11

Because using phone numbers to decide if human or bot is cheap, easy, and effective. Politically, there is no will for a national identity verification type service as infrastructure. And this way, all the work gets outsourced to ATT/Verizon/T-Mobile, and politicians get to say “it is not our fault” and telecoms get to say “it is not our job”.

And scamming yourself to another persons phone number to entirely take over their digital life is also cheap, easy and effective.

And that is a problem for a sufficiently small population that it is not yet a political priority. Crazy, since the federal government already does passports, and the infrastructure is basically in place with USPS offices.

Re: Ask HN: Why did smartphones become a single point of failure?

#17
post #9
post #7

Are you saying all of these systems enforce SMS-based 2FA rather than the sane choice of TOTP? That's unwise and unfortunate.

Many enforce 2FA through their own app, so TOTP is not an option.

It's the same plague, whether SMS or their own homebaked authentication scheme.

Re: Ask HN: Why did smartphones become a single point of failure?

#18
This is a big problem for me as a traveller. If I travel long distance and I lose my phone, I lose access to both my personal and business bank.

I once dropped my phone in a lake (I'm clumsy) and was locked out of most things for a few weeks.

I prefer TOTP for most things. Keepass supports them across platforms, but Aegis has a better experience on mobiles.

Re: Ask HN: Why did smartphones become a single point of failure?

#19

Because using phone numbers to decide if human or bot is cheap, easy, and effective. Politically, there is no will for a national identity verification type service as infrastructure. And this way, all the work gets outsourced to ATT/Verizon/T-Mobile, and politicians get to say “it is not our fault” and telecoms get to say “it is not our job”.

You don't need a smartphone to have and use a phone number. I suspect the OP is about smartphone app authentication.

Oh, yes, I think I misread. In that case, I guess the spam/bot reduction efforts are outsourced to Apple and Google’s App Store and mobile OSs.

Re: Ask HN: Why did smartphones become a single point of failure?

#20

Why did gasoline become a single point of failure in automobiles? Why did the strings on my guitar become a single point of failure? Creating redundancy for every dependency is not always practical or economical.

Terrible comparison. If you don't have gasoline you can still walk, get a cab or take the bus to wherever you're going. It's not gatekeeping anything, it's just a convenience.

Strings on your guitar can be readily replaced, and again, it's not gatekeeping you from your finances or your employment (unless you're a musician, but in this case I'm sure you'll have spare strings and instruments so that if one breaks you can carry on without much thought).

Post reply on HN