Live data from Hacker News

Ask HN: Why did smartphones become a single point of failure?

news.ycombinator.com

151–160 of 289 posts

Re: Ask HN: Why did smartphones become a single point of failure?

#151
I didn't have a cell phone until work issued me one around 2018 or so. (I never really liked the idea.) Generally, I don't have many single points of failure tied to the phone not tied to work...certainly nothing related to my banking.

You can still live in 2022 without one, although the assumption that you have one gets more annoyingly entrenched year-by-year.

I don't quite know what these single points of failure are, but they must tend not to exist when you have a "hard no--I have no such device" in your back pocket...you can choose services that don't require it, use hardware token 2FA, or something. Somehow, it does still work out to simply not have one, but it seems hard to avoid reliance on it once you've got it, since you don't see a service and think "well, I guess I just can't sign up for that one", but instead whip out the cell phone and comply.

Re: Ask HN: Why did smartphones become a single point of failure?

#152

it's crazy when museums don't give out paper maps and expect you to use your smartphone - https://twitter.com/austinkleon/status/1556466475354963968 there are old folks who aren't that tech-savvy, and smartphones + plans are not that cheap or free in the US, we still have some extreme poverty, penetration is not 100%, if you're going to make smartphone a requirement to participate in society there really need to be s…

There are low end phone plans in the range of $10-15/mo. You can get a prepaid smartphone for like $40, and if you aren't using cellular data, you can get the smartphone itself for around $20.

Re: Ask HN: Why did smartphones become a single point of failure?

#153
post #148

Earlier quoted context omitted.

It's not that people don't know it's a SPOF. The issue is that if you fail in a way that is common, nobody blames you. Cell phone 2FA is so ubiquitous that when it doesn't work clients wonder if they're the one fucking up. We had a massive internet outage in Canada recently and nobody blamed individual shops for not being able to take credit cards, they blamed the phone company. If you roll your own thing, even if it…

> There's also something to be said for how modern financial capitalism has > squeezed redundancy out of everything. Supply chains are just-in-time, Hence the automotive/chips and other recent shortages...

Are you implying we should have wasted billions manufacturing extra chips just in case there was a shortage and consumers didn't want to wait a year before buying a new car/truck?

Re: Ask HN: Why did smartphones become a single point of failure?

#154
Because they're the thing in your life that you have the least control over. Businesses and governments can lower all kinds of costs by using your phone to manage you. If kings had the ability to distribute smartphones when feudalism was in full swing, feudalism never would have ended.

They watch you while you watch them, and there's nothing you can do about it. What I really wonder is whether we're 10 years away from police being dispatched if your phone is turned off (which, of course, would have started as opt-in, and ended as getting a ticket for letting your battery die), if we're 50 years away, or if there will be some sort of Butlerian Jihad before it happens.

edit: we can pretend this is just about authentication, but the reason smartphones work for authentication is because you have no control over them. If you root your phone, it becomes useless for authentication.

Re: Ask HN: Why did smartphones become a single point of failure?

#155
post #143

Because using phone numbers to decide if human or bot is cheap, easy, and effective. Politically, there is no will for a national identity verification type service as infrastructure. And this way, all the work gets outsourced to ATT/Verizon/T-Mobile, and politicians get to say “it is not our fault” and telecoms get to say “it is not our job”.

Regardless of who is doing the job, you're still going to need some device on your person (or otherwise readily accessible) that can be used to confirm that you are actually you, and whatever that device is will become a single point of failure. The real issue is there needs to be some simple standard workflow for when the device (be it smartphone or otherwise) fails. And in this case the government pretty much alrea…

> you're still going to need some device on your person (or otherwise readily accessible) that can be used to confirm that you are actually you

Nah, we don't need that. We've been doing without that for thousands of years.

Re: Ask HN: Why did smartphones become a single point of failure?

#156
post #87

Nobody knows how to do a failure analysis. I used to work in r&d, now that I’m building websites and mobile apps the culture doesn’t care. Pointing out obvious design limitations will, more often that not, make me the asshole. Not even trying to delay ship or get future rework scheduled, just having it documented is too much. Out of sight out of mind.

> Pointing out obvious design limitations will, more often that not, make me the asshole. Being an "asshole" isn't always a bad thing, assuming you mean "frowned upon for providing dissent along lines of unhappy, but factual, technical realities which are applicable in the current context". If this is the new definition of asshole, then I am the king of assholes.

Asshole here too. Left previous job, people sent messages thanking me for being the only person asking hard questions.

Re: Ask HN: Why did smartphones become a single point of failure?

#157

Because using phone numbers to decide if human or bot is cheap, easy, and effective. Politically, there is no will for a national identity verification type service as infrastructure. And this way, all the work gets outsourced to ATT/Verizon/T-Mobile, and politicians get to say “it is not our fault” and telecoms get to say “it is not our job”.

The lack of political will you speak of is better seen as a reaction to the deeper problem that there is no political will for protections that would go against commercial desires. Social security numbers were created solely to facilitate social security but had no legal protections enforcing this, and thus are now being widely abused by private companies. The same with driver's license numbers. Without a US GDPR tha…

Or vulnerablities for fully accountable governments to exploit, either. Governments may be accountable to their supporters, but they're not necessarily accountable to me. They could decide tomorrow that it's illegal to be Jewish or to have been descended from Jews, and they have before.

Re: Ask HN: Why did smartphones become a single point of failure?

#158
post #45

Only banks do that. All other services accept TOTP (which you can have on multiple devices) or YubiKeys/webauthn/U2F (where you can add multiple hardware keys). And even here, my bank accepts two (or more) devices with an active instance of their app. So the solution to this spof is the same as always: redundancy. You need a second phone. Your old one is probably good enough.

> Your old one is probably good enough. Some of us use the same phone for years, until it loses OS/security updates. My current phone is 6 years old. By the time I upgrade, my current phone will not be able to run current authenticator or bank apps, which will target an iOS version above the last one supported by my phone. So no, my old one is not "good enough" unless I upgrade more often than I'm comfortable with.

[deleted]

Re: Ask HN: Why did smartphones become a single point of failure?

#159
post #48

I don't have the same view, in my mind you have created a single point of failure for _yourself_. I use Authy for MFA, which comes with a desktop app. Phones dead / missing? No problem, I can get OTP's from my laptop. What about text messages? Google voice. Which of course has a desktop interface. I've been doing this for years. It's nice not to have to rely on a watch, or phone entirely - although they do make my li…

"I use Authy for MFA, which comes with a desktop app"

Fantastic. A lot of banks (at least here in Canada) ONLY have text or phone call for 2FA (which is awful, but welcome to banking).

Re: Ask HN: Why did smartphones become a single point of failure?

#160
post #18

This is a big problem for me as a traveller. If I travel long distance and I lose my phone, I lose access to both my personal and business bank. I once dropped my phone in a lake (I'm clumsy) and was locked out of most things for a few weeks. I prefer TOTP for most things. Keepass supports them across platforms, but Aegis has a better experience on mobiles.

I don't travel much, especially recently, so this may not be worth the hassle for frequent travellers, but I factory reset before going overseas, or use a non-current phone to take overseas. Whence through customs etc, reinstall only the essential apps for the trip, just remember your passwords or your single password to your password manager. You can also spread about an encrypted set of instructions amongst free em…

I have traveled a lot over the past few years, including several times through hostile customs (eg USA). I have never had any of them go through my phone or even ask to see it. And to be quite frank, I don't see what use a border agent or the government would use from my phone that they couldn't get in a different, simpler, less blatant way. I'm not sure what threat model you're fighting against, but it may exist only in your mind.
Post reply on HN