Live data from Hacker News

Ask HN: Why did smartphones become a single point of failure?

news.ycombinator.com

191–200 of 289 posts

Re: Ask HN: Why did smartphones become a single point of failure?

#191

Earlier quoted context omitted.

Are you implying we should have wasted billions manufacturing extra chips just in case there was a shortage and consumers didn't want to wait a year before buying a new car/truck?

So, a couple of companies did actually stockpile chips (Toyota was one IIRC), because it was a component whose manufacturing flexability is pretty minimal. It was financially lucrative for them, since they could sell vehicles at a time where no other manufacturers could.

Indeeed. Sometimes doing the right thing pays very well. :)

Re: Ask HN: Why did smartphones become a single point of failure?

#192
post #48

I don't have the same view, in my mind you have created a single point of failure for _yourself_. I use Authy for MFA, which comes with a desktop app. Phones dead / missing? No problem, I can get OTP's from my laptop. What about text messages? Google voice. Which of course has a desktop interface. I've been doing this for years. It's nice not to have to rely on a watch, or phone entirely - although they do make my li…

> in my mind you have created a single point of failure for _yourself_. I use Authy for MFA

Since Authy requires an SMS verification for setup, now you’ve made yourself vulnerable to SIM jacking. A better approach would be to use a TOTP generator that doesn’t verify you by SMS.

In general, there’s no point in people dissing SMS OTP as insecure and at the same time adopting a service that uses it.

Re: Ask HN: Why did smartphones become a single point of failure?

#193

So let's say you change phone numbers and FORGET to change one of the important websites that use that number for authentication? Or you change phones, wiping the old one before selling it to your friend and setting up the new one from scratch? Some websites are terrible/impossible at letting you recover your account when you've lost access to the phone number or the exact instance of the phone used for authenticatio…

This is why I stopped using authenticator apps tied to my phone and started using Bitwarden’s TOTP feature.

Re: Ask HN: Why did smartphones become a single point of failure?

#195
post #102
post #23

Go through the whole list and figure out which of these services really requires your phone, and which you have set up on your phone because that seemed the easiest path. Tell your workplace you're about to switch from carrying a phone to a landline: what is their fallback option? (It's about 50/50 whether they have one, but they definitely should.)

Yeah, if my employer wants me to use a smartphone app, they better cough up a smartphone for me to use. I'm not installing anything work-related on my private one, because I am in no position to guarantee that I won't break it or lose it. I've had pushback from the employer about this a few times, but in the end, there's nothing they can do.

The way to handle this situation that respects your space while minimizing conflict, is to have a second phone just for work only that they can mobile device manage to their heart's content with all their useless apps.

This means using one of your older devices for it if available, otherwise you can purchase the cheapest unlocked one sold at an outlet store and consider it a cost of doing business like clothing.

Re: Ask HN: Why did smartphones become a single point of failure?

#196
post #143

Earlier quoted context omitted.

Regardless of who is doing the job, you're still going to need some device on your person (or otherwise readily accessible) that can be used to confirm that you are actually you, and whatever that device is will become a single point of failure. The real issue is there needs to be some simple standard workflow for when the device (be it smartphone or otherwise) fails. And in this case the government pretty much alrea…

> you're still going to need some device on your person (or otherwise readily accessible) that can be used to confirm that you are actually you Nah, we don't need that. We've been doing without that for thousands of years.

We also did without anesthesia for thousands of years. This is not a great argument against something.

Re: Ask HN: Why did smartphones become a single point of failure?

#197

Earlier quoted context omitted.

Phone isn’t a secure factor in 2022.

If this is due to the vulnerabilities in the SS7 protocol, then it hasn't been secure since 1975. Or at least 2008 when a set of vulnerabilities were published. https://en.m.wikipedia.org/wiki/Signalling_System_No._7

Well, yeah. Back in 1975, we weren't generally using our phones for authentication. The environment has changed and the security issues are far more important now.

Re: Ask HN: Why did smartphones become a single point of failure?

#198

Your phone is leveraged so much because it provides companies with deeper tracking capabilities. Most laptops and PCs only geo locate based on their connection points, phones have accelerometers and more accurate location and ID info in them, so many app makers hobble browser-based app iterations to encourage mostly phone use. They also know users are engaged and focused on content more when they are on phones becaus…

For reddit- sure, but why banks? Surely managing hundreds of thousands of my money is worth more than some geo data.

Banks are in the smartphone game for a few more reasons other than tracking:

1. They tend to trust a locked-down, reasonably secured environment more than a hackable, general-purpose operating system, especially for 2FA.

2. They’re under pressure from fintech, so they have to focus more on things customers want.

Re: Ask HN: Why did smartphones become a single point of failure?

#199
post #88

Earlier quoted context omitted.

Before smartphone, if you lose your passport everything goes wrong as well. (and noticing your phone is missing and finding it back is way easier than passport)

I live in the US. Passports are effectively irrelevant for me, even should I travel several thousand miles. Phones… not so much. And I’m not mentioning the US because its unique in this attribute.

It’s different if you’re a foreign national.

In ‘05 I was traveling in the EU, across the open borders, and got checked by customs agents because of a bombing in, I believe, London. Thought it was weird but, whatever… Later on I pieced together what happened because even if they were only doing spot checks it’s not like I don’t perfectly blend in with Europeans.

A bit of an aside, custom agents absolutely loved my customs stamp from Iraq back then. Well, aside from the Dutch.

Re: Ask HN: Why did smartphones become a single point of failure?

#200
post #152

it's crazy when museums don't give out paper maps and expect you to use your smartphone - https://twitter.com/austinkleon/status/1556466475354963968 there are old folks who aren't that tech-savvy, and smartphones + plans are not that cheap or free in the US, we still have some extreme poverty, penetration is not 100%, if you're going to make smartphone a requirement to participate in society there really need to be s…

There are low end phone plans in the range of $10-15/mo. You can get a prepaid smartphone for like $40, and if you aren't using cellular data, you can get the smartphone itself for around $20.

Yeah, so I can wait in the lobby for 17 minutes while some 1.8 star museum app downloads to my phone over a crappy network that my provider lied about the performance of instead of someone just handing me a paper map.
Post reply on HN