Ask HN: Why did smartphones become a single point of failure?
111–120 of 289 posts
Re: Ask HN: Why did smartphones become a single point of failure?
#112I still have my bank's physical code-slip and can sign in using it just fine.
My fiance's bank provided her with a small, calculator-looking battery-powered code device.
Re: Ask HN: Why did smartphones become a single point of failure?
#113I don't have the same view, in my mind you have created a single point of failure for _yourself_. I use Authy for MFA, which comes with a desktop app. Phones dead / missing? No problem, I can get OTP's from my laptop. What about text messages? Google voice. Which of course has a desktop interface. I've been doing this for years. It's nice not to have to rely on a watch, or phone entirely - although they do make my li…
Re: Ask HN: Why did smartphones become a single point of failure?
#114Earlier quoted context omitted.
Depends on the security requirements and terms of employment. Where I work now, you’d get a hard token or work phone if you’re deemed as requiring a phone. In the previous job, you were sent the form for 24x7 building access and were free to drive into work within the on-call response period. You were also reimbursed for your cell phone, that was the bronze handcuff.
Under current case law in the US, my understanding is that public ("operational realities" and reasonable suspicion tests) and private employers (fewer tests) have rights to audit any information on employer-compensated devices they wish (and have access to). I only use a work phone for work business. If my work requires me to use a phone, I require a work phone. Carrying two phones is a small price to pay to avoid w…
Even if the business doesn’t want to audit your phones, a litigation event could force the issue.
Re: Ask HN: Why did smartphones become a single point of failure?
#115Earlier quoted context omitted.
Yup. Chase does the same thing. They blackhole SMS to Google voice.
Yet another push to get a better bank, in addition to all their ridiculous fees. Ally blackholes Gvoice (messages just disappear), but gives you an email option to login. When calling customer service, they can do the challenge with a phone call rather than SMS. Capital One, Discover, and Alliant all seem to accept Gvoice just fine. There of course is a major problem that Gvoice seems to be special, in that many plac…
Chase owns the Amazon card, and 5% rebates on Amazon are worth dealing with the drama.
Re: Ask HN: Why did smartphones become a single point of failure?
#116Then change the bank you deal with. At least in EU, this 2FA was due to PSD. Please also note that any changes will impact some people. How often do you lose your smartphone? If every month then it is sad. You need to find a bank that still uses cheques etc. No point in whinging. If something works for 90 % people then get used to it. For example, I did not like joining facebook for my children's school nor whatsapp…
Re: Ask HN: Why did smartphones become a single point of failure?
#117Earlier quoted context omitted.
Sure, blame the user, that is the mature response whenever someone is pointing out that modern ID security is a topple tower. Whatever technical solutions can be made don't really matter unless normal people can and do use them correctly. In any case, simply setting up another non-phone computer to do the job of the smartphone doesn't change the fundamental issue, it can still break, or get stolen, or some account ca…
>"Sure, blame the user, that is the mature response..." We're all here to make our own decisions. We're all here to seek enlightenment. I've made it very clear that the decisions that I have made have placed me where I don't have the same issues as OP. I'm enlightening OP, and everyone who reads these comments, I'm not "blaming" anyone.
Re: Ask HN: Why did smartphones become a single point of failure?
#118there are old folks who aren't that tech-savvy, and smartphones + plans are not that cheap or free in the US, we still have some extreme poverty, penetration is not 100%, if you're going to make smartphone a requirement to participate in society there really need to be super-cheap smartphone options.
Re: Ask HN: Why did smartphones become a single point of failure?
#119Only banks do that. All other services accept TOTP (which you can have on multiple devices) or YubiKeys/webauthn/U2F (where you can add multiple hardware keys). And even here, my bank accepts two (or more) devices with an active instance of their app. So the solution to this spof is the same as always: redundancy. You need a second phone. Your old one is probably good enough.
Some of us use the same phone for years, until it loses OS/security updates. My current phone is 6 years old. By the time I upgrade, my current phone will not be able to run current authenticator or bank apps, which will target an iOS version above the last one supported by my phone. So no, my old one is not "good enough" unless I upgrade more often than I'm comfortable with.
Re: Ask HN: Why did smartphones become a single point of failure?
#120Nobody knows how to do a failure analysis. I used to work in r&d, now that I’m building websites and mobile apps the culture doesn’t care. Pointing out obvious design limitations will, more often that not, make me the asshole. Not even trying to delay ship or get future rework scheduled, just having it documented is too much. Out of sight out of mind.
It's not that people don't know it's a SPOF. The issue is that if you fail in a way that is common, nobody blames you. Cell phone 2FA is so ubiquitous that when it doesn't work clients wonder if they're the one fucking up. We had a massive internet outage in Canada recently and nobody blamed individual shops for not being able to take credit cards, they blamed the phone company. If you roll your own thing, even if it…