Live data from Hacker News

Ask HN: Why did smartphones become a single point of failure?

news.ycombinator.com

141–150 of 289 posts

Re: Ask HN: Why did smartphones become a single point of failure?

#141

Nobody knows how to do a failure analysis. I used to work in r&d, now that I’m building websites and mobile apps the culture doesn’t care. Pointing out obvious design limitations will, more often that not, make me the asshole. Not even trying to delay ship or get future rework scheduled, just having it documented is too much. Out of sight out of mind.

Plenty of people know how to do failure mode analysis. In most webcentric scenarios, though, nobody cares because it's all about the average case. If 99 of your users have a great experience and 1 has a bad-but-not-bad-enough-to-make-the-front-page experience, that's a huge win over 100 users having an okay experience. I hate it too, but that's the market.

Re: Ask HN: Why did smartphones become a single point of failure?

#142
post #2

>i can't log in to any of my banks without my phone. Don't know about banks in Europe but in USA, I can log into Bank Of America and JP Morgan Chase without any phone authentication. If I reformat my harddrive or buy a new computer and the bank doesn't recognize the web browser because no previous cookie has been found, the website will generate a one-time code and send it to my email address. I then enter that secur…

I had a Chase account and for some years was able to use email for 2FA. Somewhere around 2019, they changed their requirements and forced SMS for 2FA. Since I don't use a (SIM-ed) phone and since my wife's phone number was already known to them, I had to pull all of my liquid savings out of the account and move it elsewhere.

I will never bank with an institution that requires SMS for 2FA.

Re: Ask HN: Why did smartphones become a single point of failure?

#143

Because using phone numbers to decide if human or bot is cheap, easy, and effective. Politically, there is no will for a national identity verification type service as infrastructure. And this way, all the work gets outsourced to ATT/Verizon/T-Mobile, and politicians get to say “it is not our fault” and telecoms get to say “it is not our job”.

Regardless of who is doing the job, you're still going to need some device on your person (or otherwise readily accessible) that can be used to confirm that you are actually you, and whatever that device is will become a single point of failure.

The real issue is there needs to be some simple standard workflow for when the device (be it smartphone or otherwise) fails. And in this case the government pretty much already is providing that service, or at least the backbone for it. "You lost your phone? Well send us a picture of your driver's license or passport plus a selfie in [this] pose from a different trusted number and, after we try calling your old number just to make sure it's really lost, we'll use the new number." Financial institutions already have the infrastructure for photo-id confirmation for KYC regulations, and selfie verification is widely used for dating apps. Yeah if someone breaks your phone, steals your id, and can deepfake you then they can probably steal your identity, but someone in that position can probably already steal your identity.

Re: Ask HN: Why did smartphones become a single point of failure?

#144

Earlier quoted context omitted.

Terrible comparison. If you don't have gasoline you can still walk, get a cab or take the bus to wherever you're going. It's not gatekeeping anything, it's just a convenience. Strings on your guitar can be readily replaced, and again, it's not gatekeeping you from your finances or your employment (unless you're a musician, but in this case I'm sure you'll have spare strings and instruments so that if one breaks you c…

If you don't have you banks app, you can still go to the actual bank and tell them to do your transactions.

That's not so easy nowadays.

Firstly with covid-19 many banks don't accept walk-ins and have a long waiting list for appointments.

Secondly, what if the bank or other service i'm using has no physical offices at all?

Or what if they're simply too far away and I'm an octogenarian, perhaps with no driving license? Eh? Am I supposed to take an uber to somewhere 100/200 miles away just because morons are given decision-making power and myopic online-apologists on HN even make excuses for them?

Re: Ask HN: Why did smartphones become a single point of failure?

#145

Earlier quoted context omitted.

Don't eSIMs have an even worse failure mode? If the phone itself dies then there's no SIM for you to take out and put into a new phone immediately right? As I understand it you have to first find another phone (with a working line!) to call your provider with, hope that it's within their business hours, and wait on hold for who knows how long, until you finally get it set up? Because of course you don't have anything…

Phone companies don't let you apply for replacement esim through a website?

[deleted]

Re: Ask HN: Why did smartphones become a single point of failure?

#146
post #18

This is a big problem for me as a traveller. If I travel long distance and I lose my phone, I lose access to both my personal and business bank. I once dropped my phone in a lake (I'm clumsy) and was locked out of most things for a few weeks. I prefer TOTP for most things. Keepass supports them across platforms, but Aegis has a better experience on mobiles.

Agree. I bring my phone oversees, but don't have an international plan, so I usually purchase a local SIM card and swap it out. But all my mfa fails then, because it is trying to text my US number!

Re: Ask HN: Why did smartphones become a single point of failure?

#147
post #108

Earlier quoted context omitted.

Sure, blame the user, that is the mature response whenever someone is pointing out that modern ID security is a topple tower. Whatever technical solutions can be made don't really matter unless normal people can and do use them correctly. In any case, simply setting up another non-phone computer to do the job of the smartphone doesn't change the fundamental issue, it can still break, or get stolen, or some account ca…

>"Sure, blame the user, that is the mature response..." We're all here to make our own decisions. We're all here to seek enlightenment. I've made it very clear that the decisions that I have made have placed me where I don't have the same issues as OP. I'm enlightening OP, and everyone who reads these comments, I'm not "blaming" anyone.

you can't expect most consumers to make these same decisions — the vast majority of people are nowhere near as savvy as the typical hacker news commenter.

Re: Ask HN: Why did smartphones become a single point of failure?

#148

Nobody knows how to do a failure analysis. I used to work in r&d, now that I’m building websites and mobile apps the culture doesn’t care. Pointing out obvious design limitations will, more often that not, make me the asshole. Not even trying to delay ship or get future rework scheduled, just having it documented is too much. Out of sight out of mind.

It's not that people don't know it's a SPOF. The issue is that if you fail in a way that is common, nobody blames you. Cell phone 2FA is so ubiquitous that when it doesn't work clients wonder if they're the one fucking up. We had a massive internet outage in Canada recently and nobody blamed individual shops for not being able to take credit cards, they blamed the phone company. If you roll your own thing, even if it…

> There's also something to be said for how modern financial capitalism has > squeezed redundancy out of everything. Supply chains are just-in-time,

Hence the automotive/chips and other recent shortages...

Re: Ask HN: Why did smartphones become a single point of failure?

#149
post #140
post #87

Earlier quoted context omitted.

> Pointing out obvious design limitations will, more often that not, make me the asshole. Being an "asshole" isn't always a bad thing, assuming you mean "frowned upon for providing dissent along lines of unhappy, but factual, technical realities which are applicable in the current context". If this is the new definition of asshole, then I am the king of assholes.

As long as your new definition of 'asshole' also comes with a new definition of 'bad thing' that doesn't include 'will piss off your users and cause you/your client to lose money'...

Agreed. I think how you deliver your unhappy truths is 99% of keeping the other party from going bananas. There are very few things that cannot be reframed in a more positive light.

Being able to sell a "no" is much more important than being able to sell someone on a shiny piece of bullshit.

Re: Ask HN: Why did smartphones become a single point of failure?

#150
post #48

I don't have the same view, in my mind you have created a single point of failure for _yourself_. I use Authy for MFA, which comes with a desktop app. Phones dead / missing? No problem, I can get OTP's from my laptop. What about text messages? Google voice. Which of course has a desktop interface. I've been doing this for years. It's nice not to have to rely on a watch, or phone entirely - although they do make my li…

>Google Voice Anecdotally, my bank (Wells Fargo) will not accept VOIP numbers for 2FA.

Many companies, not just financial are the same. They usually fail silently, too, so you sit around wondering if the text ever sent.
Post reply on HN