Live data from Hacker News

Ask HN: Why did smartphones become a single point of failure?

news.ycombinator.com

101–110 of 289 posts

Re: Ask HN: Why did smartphones become a single point of failure?

#101

Earlier quoted context omitted.

Yup. Chase does the same thing. They blackhole SMS to Google voice.

Yet another push to get a better bank, in addition to all their ridiculous fees. Ally blackholes Gvoice (messages just disappear), but gives you an email option to login. When calling customer service, they can do the challenge with a phone call rather than SMS. Capital One, Discover, and Alliant all seem to accept Gvoice just fine. There of course is a major problem that Gvoice seems to be special, in that many plac…

Probably Comcast Voice. Comcast/Xfinity Mobile is a Verizon MVNO

Re: Ask HN: Why did smartphones become a single point of failure?

#102
post #23

Go through the whole list and figure out which of these services really requires your phone, and which you have set up on your phone because that seemed the easiest path. Tell your workplace you're about to switch from carrying a phone to a landline: what is their fallback option? (It's about 50/50 whether they have one, but they definitely should.)

Yeah, if my employer wants me to use a smartphone app, they better cough up a smartphone for me to use. I'm not installing anything work-related on my private one, because I am in no position to guarantee that I won't break it or lose it.

I've had pushback from the employer about this a few times, but in the end, there's nothing they can do.

Re: Ask HN: Why did smartphones become a single point of failure?

#103
post #71

Quoted post unavailable.

Dude, what? How many services require SMS 2FA again? Your phone is indeed a SPOF. If you lose your phone, you're fucked in a variety of scenarios. To say nothing of services that require a custom app and accept nothing else.

Thanks for addressing me as "Dude" and using the f-word!

1. OP is asking smartphone; SMS 2FA does not require a "smartphone", but "mobile phone".

2. Alternative options mentioned above should you be in the misfortune of losing your... "phone"

Re: Ask HN: Why did smartphones become a single point of failure?

#104

Earlier quoted context omitted.

The eSim's are available these days so you don't have to wait for new SIM to arrive... if your provider & phone supports this feature.

Don't eSIMs have an even worse failure mode? If the phone itself dies then there's no SIM for you to take out and put into a new phone immediately right? As I understand it you have to first find another phone (with a working line!) to call your provider with, hope that it's within their business hours, and wait on hold for who knows how long, until you finally get it set up? Because of course you don't have anything…

Phone companies don't let you apply for replacement esim through a website?

Re: Ask HN: Why did smartphones become a single point of failure?

#105
I always have a backup Android device setup as per my standard operating environment for this very reason. I'm actually due to setup another one as my previous backup went to my daughter for her birthday recently (but it still has my SOE hidden on it).

But also, I don't use my phone for banking because I still don't trust mobile ecosystems. I use a dedicated VM that requires a decryption password to boot up.

But yeah, banks are pushing for app usage rather than web interface, which is ironic given that my bank still only has SMS 2FA, not token-based. So why would I trust their app to be anywhere near secure in an insecure ecosystem if they can't even support proper multi-factor authentication that's been standard for, what, 5 years already?

Re: Ask HN: Why did smartphones become a single point of failure?

#106
So let's say you change phone numbers and FORGET to change one of the important websites that use that number for authentication?

Or you change phones, wiping the old one before selling it to your friend and setting up the new one from scratch?

Some websites are terrible/impossible at letting you recover your account when you've lost access to the phone number or the exact instance of the phone used for authentication.

Re: Ask HN: Why did smartphones become a single point of failure?

#107
post #48

I don't have the same view, in my mind you have created a single point of failure for _yourself_. I use Authy for MFA, which comes with a desktop app. Phones dead / missing? No problem, I can get OTP's from my laptop. What about text messages? Google voice. Which of course has a desktop interface. I've been doing this for years. It's nice not to have to rely on a watch, or phone entirely - although they do make my li…

Sure, blame the user, that is the mature response whenever someone is pointing out that modern ID security is a topple tower. Whatever technical solutions can be made don't really matter unless normal people can and do use them correctly. In any case, simply setting up another non-phone computer to do the job of the smartphone doesn't change the fundamental issue, it can still break, or get stolen, or some account ca…

Especially when the user is a senior or a minor, blaming the user is not really the solution.

Re: Ask HN: Why did smartphones become a single point of failure?

#108
post #48

I don't have the same view, in my mind you have created a single point of failure for _yourself_. I use Authy for MFA, which comes with a desktop app. Phones dead / missing? No problem, I can get OTP's from my laptop. What about text messages? Google voice. Which of course has a desktop interface. I've been doing this for years. It's nice not to have to rely on a watch, or phone entirely - although they do make my li…

Sure, blame the user, that is the mature response whenever someone is pointing out that modern ID security is a topple tower. Whatever technical solutions can be made don't really matter unless normal people can and do use them correctly. In any case, simply setting up another non-phone computer to do the job of the smartphone doesn't change the fundamental issue, it can still break, or get stolen, or some account ca…

>"Sure, blame the user, that is the mature response..."

We're all here to make our own decisions. We're all here to seek enlightenment. I've made it very clear that the decisions that I have made have placed me where I don't have the same issues as OP.

I'm enlightening OP, and everyone who reads these comments, I'm not "blaming" anyone.

Re: Ask HN: Why did smartphones become a single point of failure?

#109

I use Google Voice, and the number that I use for PINs I can login to with just a password. That way I can always access text messages even if my phone is gone. You need it when traveling and your shit gets jacked. I haven't tried it but an Android emulator should allow you to use apps without a smartphone.

If the banking software lets you log in via an Android emulator I'd say it's a pretty badly written piece of banking software. I understand why HN readers would want to maybe use an emulator to avoid having a phone but really what other use case is there than that or a scammer trying to spoof you.

Is running an app inside an Android Emulator (i.e. the ones that come with Android Studio) something the app can detect then ?

Re: Ask HN: Why did smartphones become a single point of failure?

#110

This has been my point for the last 5 or 10 years. That's why I have a "home phone" with banking apps, 2FA and important stuff installed. It has no SIM card and never leaves home. For everything else I have my "street phone".

What if you go on a vacation?
Post reply on HN