Live data from Hacker News

Ask HN: Why did smartphones become a single point of failure?

news.ycombinator.com

121–130 of 289 posts

Re: Ask HN: Why did smartphones become a single point of failure?

#122
post #48

I don't have the same view, in my mind you have created a single point of failure for _yourself_. I use Authy for MFA, which comes with a desktop app. Phones dead / missing? No problem, I can get OTP's from my laptop. What about text messages? Google voice. Which of course has a desktop interface. I've been doing this for years. It's nice not to have to rely on a watch, or phone entirely - although they do make my li…

Can you get OTPs on Google voice? Last I read (years ago) they said don’t do that because some won’t support it

Re: Ask HN: Why did smartphones become a single point of failure?

#123

Earlier quoted context omitted.

The eSim's are available these days so you don't have to wait for new SIM to arrive... if your provider & phone supports this feature.

Don't eSIMs have an even worse failure mode? If the phone itself dies then there's no SIM for you to take out and put into a new phone immediately right? As I understand it you have to first find another phone (with a working line!) to call your provider with, hope that it's within their business hours, and wait on hold for who knows how long, until you finally get it set up? Because of course you don't have anything…

With Vodafone, I just login on the website and swap the esim. It’s ridiculously straight forward and you can set a sim pin that works across devices so even if someone were to steal the login and try to take your esim, they still need the pin to unlock the sim on the device.

Re: Ask HN: Why did smartphones become a single point of failure?

#124
I haven't lost my phone yet, but it's only a matter of time before I get unlucky enough.

I'm prepared for it by using ProtonMail for my main email with (strong, memorized) password only, no 2FA and Starling for my bank, which allows you to log in with password + video of yourself.

Re: Ask HN: Why did smartphones become a single point of failure?

#125

Earlier quoted context omitted.

>Google Voice Anecdotally, my bank (Wells Fargo) will not accept VOIP numbers for 2FA.

Yup. Chase does the same thing. They blackhole SMS to Google voice.

Same with USAA. This is pretty recent though.

Re: Ask HN: Why did smartphones become a single point of failure?

#126
post #88
post #18

This is a big problem for me as a traveller. If I travel long distance and I lose my phone, I lose access to both my personal and business bank. I once dropped my phone in a lake (I'm clumsy) and was locked out of most things for a few weeks. I prefer TOTP for most things. Keepass supports them across platforms, but Aegis has a better experience on mobiles.

Before smartphone, if you lose your passport everything goes wrong as well. (and noticing your phone is missing and finding it back is way easier than passport)

The worrying difference for me here is that when I travel, I pull my phone out of my pocket 50 times a day but I only use my passport once or twice a week and can store it safely in between.

Re: Ask HN: Why did smartphones become a single point of failure?

#127

Earlier quoted context omitted.

It's not that people don't know it's a SPOF. The issue is that if you fail in a way that is common, nobody blames you. Cell phone 2FA is so ubiquitous that when it doesn't work clients wonder if they're the one fucking up. We had a massive internet outage in Canada recently and nobody blamed individual shops for not being able to take credit cards, they blamed the phone company. If you roll your own thing, even if it…

Let's not forget the benefits either. Reduced redundancy is _good_ (as long as nothing fails in the chain, ofc). It enables society to make more, for lower costs. And it works remarkably well, overall.

But thats the problem being expressed - things will fail. Things will always fail, and ignoring that is the equivalent of burying your head in the sand and thinking your ass is covered.

Re: Ask HN: Why did smartphones become a single point of failure?

#128

Nobody knows how to do a failure analysis. I used to work in r&d, now that I’m building websites and mobile apps the culture doesn’t care. Pointing out obvious design limitations will, more often that not, make me the asshole. Not even trying to delay ship or get future rework scheduled, just having it documented is too much. Out of sight out of mind.

It's not that people don't know it's a SPOF. The issue is that if you fail in a way that is common, nobody blames you. Cell phone 2FA is so ubiquitous that when it doesn't work clients wonder if they're the one fucking up. We had a massive internet outage in Canada recently and nobody blamed individual shops for not being able to take credit cards, they blamed the phone company. If you roll your own thing, even if it…

[deleted]

Re: Ask HN: Why did smartphones become a single point of failure?

#129

Earlier quoted context omitted.

Good 2 factor auth systems will provide the option to be called on the number on your account.

Phone isn’t a secure factor in 2022.

If this is due to the vulnerabilities in the SS7 protocol, then it hasn't been secure since 1975.

Or at least 2008 when a set of vulnerabilities were published.

https://en.m.wikipedia.org/wiki/Signalling_System_No._7

Re: Ask HN: Why did smartphones become a single point of failure?

#130
post #71

Earlier quoted context omitted.

Dude, what? How many services require SMS 2FA again? Your phone is indeed a SPOF. If you lose your phone, you're fucked in a variety of scenarios. To say nothing of services that require a custom app and accept nothing else.

Thanks for addressing me as "Dude" and using the f-word! 1. OP is asking smartphone; SMS 2FA does not require a "smartphone", but "mobile phone". 2. Alternative options mentioned above should you be in the misfortune of losing your... "phone"

> Thanks for addressing me as "Dude" and using the f-word!

Sensitive, ha?

> 1. OP is asking smartphone; SMS 2FA does not require a "smartphone", but "mobile phone".

Nitpicking and strawman argument. They're both part of, and compounding, the same problem.

> 2. Alternative options mentioned above should you be in the misfortune of losing your... "phone"

Sure they "should", but they're often not offered... even if you insist.

And more often than not, the alternative options available take weeks of phone calls and visits to the local (if you're lucky to have one) branch office of your /whatever service failed you/.

Post reply on HN