Live data from Hacker News

Ask HN: Why did smartphones become a single point of failure?

news.ycombinator.com

131–140 of 289 posts

Re: Ask HN: Why did smartphones become a single point of failure?

#131
post #88
post #18

This is a big problem for me as a traveller. If I travel long distance and I lose my phone, I lose access to both my personal and business bank. I once dropped my phone in a lake (I'm clumsy) and was locked out of most things for a few weeks. I prefer TOTP for most things. Keepass supports them across platforms, but Aegis has a better experience on mobiles.

Before smartphone, if you lose your passport everything goes wrong as well. (and noticing your phone is missing and finding it back is way easier than passport)

I live in the US. Passports are effectively irrelevant for me, even should I travel several thousand miles. Phones… not so much.

And I’m not mentioning the US because its unique in this attribute.

Re: Ask HN: Why did smartphones become a single point of failure?

#132

Nobody knows how to do a failure analysis. I used to work in r&d, now that I’m building websites and mobile apps the culture doesn’t care. Pointing out obvious design limitations will, more often that not, make me the asshole. Not even trying to delay ship or get future rework scheduled, just having it documented is too much. Out of sight out of mind.

It's not that people don't know it's a SPOF. The issue is that if you fail in a way that is common, nobody blames you. Cell phone 2FA is so ubiquitous that when it doesn't work clients wonder if they're the one fucking up. We had a massive internet outage in Canada recently and nobody blamed individual shops for not being able to take credit cards, they blamed the phone company. If you roll your own thing, even if it…

> modern financial capitalism has squeezed redundancy out of everything

If by "modern financial capitalism" you mean "customers who prefer cheaper to superior quality of product and/or service", then I agree with you.

Re: Ask HN: Why did smartphones become a single point of failure?

#133
post #108

Earlier quoted context omitted.

>"Sure, blame the user, that is the mature response..." We're all here to make our own decisions. We're all here to seek enlightenment. I've made it very clear that the decisions that I have made have placed me where I don't have the same issues as OP. I'm enlightening OP, and everyone who reads these comments, I'm not "blaming" anyone.

When you acknowledge that there is a problem in the system and have solved it by way of a third party application, why do you still place the blame on the user for not solving the problem the same way you did instead of the system for having holes in it

How does providing information have anything to do with placing blame?

Re: Ask HN: Why did smartphones become a single point of failure?

#134
post #132

Earlier quoted context omitted.

It's not that people don't know it's a SPOF. The issue is that if you fail in a way that is common, nobody blames you. Cell phone 2FA is so ubiquitous that when it doesn't work clients wonder if they're the one fucking up. We had a massive internet outage in Canada recently and nobody blamed individual shops for not being able to take credit cards, they blamed the phone company. If you roll your own thing, even if it…

> modern financial capitalism has squeezed redundancy out of everything If by "modern financial capitalism" you mean "customers who prefer cheaper to superior quality of product and/or service", then I agree with you.

If you're a naive economist and you think Homo Economicus is real.

Re: Ask HN: Why did smartphones become a single point of failure?

#135
post #61

Nobody knows how to do a failure analysis. I used to work in r&d, now that I’m building websites and mobile apps the culture doesn’t care. Pointing out obvious design limitations will, more often that not, make me the asshole. Not even trying to delay ship or get future rework scheduled, just having it documented is too much. Out of sight out of mind.

It's not that they don't know how to. It's that there's an economic incentive to not care. So they don't.

Exactly, and the incentive is that customers do not care.

Build quality, keep redundancy, and in the next pandemic your business will flourish... unless you'll have had to close it before 'cause of people buying cheap and not good!

Re: Ask HN: Why did smartphones become a single point of failure?

#136
post #71

Earlier quoted context omitted.

Dude, what? How many services require SMS 2FA again? Your phone is indeed a SPOF. If you lose your phone, you're fucked in a variety of scenarios. To say nothing of services that require a custom app and accept nothing else.

Thanks for addressing me as "Dude" and using the f-word! 1. OP is asking smartphone; SMS 2FA does not require a "smartphone", but "mobile phone". 2. Alternative options mentioned above should you be in the misfortune of losing your... "phone"

I hate to put this to you, but your post sounds like a whinge on my language, dude

Re: Ask HN: Why did smartphones become a single point of failure?

#138
post #48

I don't have the same view, in my mind you have created a single point of failure for _yourself_. I use Authy for MFA, which comes with a desktop app. Phones dead / missing? No problem, I can get OTP's from my laptop. What about text messages? Google voice. Which of course has a desktop interface. I've been doing this for years. It's nice not to have to rely on a watch, or phone entirely - although they do make my li…

Can you get OTPs on Google voice? Last I read (years ago) they said don’t do that because some won’t support it

Some of the financial services I use do, some don't. Things like discord don't either which is also annoying.

Re: Ask HN: Why did smartphones become a single point of failure?

#139
post #18

This is a big problem for me as a traveller. If I travel long distance and I lose my phone, I lose access to both my personal and business bank. I once dropped my phone in a lake (I'm clumsy) and was locked out of most things for a few weeks. I prefer TOTP for most things. Keepass supports them across platforms, but Aegis has a better experience on mobiles.

I don't travel much, especially recently, so this may not be worth the hassle for frequent travellers, but I factory reset before going overseas, or use a non-current phone to take overseas.

Whence through customs etc, reinstall only the essential apps for the trip, just remember your passwords or your single password to your password manager.

You can also spread about an encrypted set of instructions amongst free email hosting.

Some people would say it's a hassle, but it keeps customs' nose out of my private life. I'm getting to an age where it's not necessarily weird to have the appearance of barely any online presence.

Re: Ask HN: Why did smartphones become a single point of failure?

#140
post #87

Nobody knows how to do a failure analysis. I used to work in r&d, now that I’m building websites and mobile apps the culture doesn’t care. Pointing out obvious design limitations will, more often that not, make me the asshole. Not even trying to delay ship or get future rework scheduled, just having it documented is too much. Out of sight out of mind.

> Pointing out obvious design limitations will, more often that not, make me the asshole. Being an "asshole" isn't always a bad thing, assuming you mean "frowned upon for providing dissent along lines of unhappy, but factual, technical realities which are applicable in the current context". If this is the new definition of asshole, then I am the king of assholes.

As long as your new definition of 'asshole' also comes with a new definition of 'bad thing' that doesn't include 'will piss off your users and cause you/your client to lose money'...
Post reply on HN