Live data from Hacker News

Ask HN: Why did smartphones become a single point of failure?

news.ycombinator.com

201–210 of 289 posts

Re: Ask HN: Why did smartphones become a single point of failure?

#201
post #23

Go through the whole list and figure out which of these services really requires your phone, and which you have set up on your phone because that seemed the easiest path. Tell your workplace you're about to switch from carrying a phone to a landline: what is their fallback option? (It's about 50/50 whether they have one, but they definitely should.)

This is the best way to go about this (the first line, the second line is rather variable). Phones didn't suddenly become a single point of failure, it's mostly middle-management combined with checkbox-security that ends up with SMS, TOTP and push-based confirmation factors. It's not the best way, but the easiest way to set things up. To make matters worse, TOTP is easy to copy for 'backup' purposes, so it's really n…

> all other second factors can be lost too

The problem is how the phone is irreplaceable and non-redundant, and not that it can be lost.

Re: Ask HN: Why did smartphones become a single point of failure?

#202
post #18

This is a big problem for me as a traveller. If I travel long distance and I lose my phone, I lose access to both my personal and business bank. I once dropped my phone in a lake (I'm clumsy) and was locked out of most things for a few weeks. I prefer TOTP for most things. Keepass supports them across platforms, but Aegis has a better experience on mobiles.

how about taking a fully set up back up phone with you? that's what I do. losing a phone travelling nowadays is in deed an expensive and extremely inconvenient mishap.

I travel by bicycle or motorcycle, so space and weight come at a huge premium. And of course my bank only lets me pair one phone per account.

Re: Ask HN: Why did smartphones become a single point of failure?

#203

Earlier quoted context omitted.

I don't travel much, especially recently, so this may not be worth the hassle for frequent travellers, but I factory reset before going overseas, or use a non-current phone to take overseas. Whence through customs etc, reinstall only the essential apps for the trip, just remember your passwords or your single password to your password manager. You can also spread about an encrypted set of instructions amongst free em…

I have traveled a lot over the past few years, including several times through hostile customs (eg USA). I have never had any of them go through my phone or even ask to see it. And to be quite frank, I don't see what use a border agent or the government would use from my phone that they couldn't get in a different, simpler, less blatant way. I'm not sure what threat model you're fighting against, but it may exist onl…

Same. 50+ countries and I only had to turn my laptop on for the TSA.

Re: Ask HN: Why did smartphones become a single point of failure?

#204
post #10
post #2

>i can't log in to any of my banks without my phone. Don't know about banks in Europe but in USA, I can log into Bank Of America and JP Morgan Chase without any phone authentication. If I reformat my harddrive or buy a new computer and the bank doesn't recognize the web browser because no previous cookie has been found, the website will generate a one-time code and send it to my email address. I then enter that secur…

In Italy it's a disaster. You need the phone /and/ their specific app, for mostly everything. From burgers, to banks and everything in between...

The biggest bank in Slovenia also requires an app, but I wrote a webapp that implements the reverse engineered protocol the bank uses in the mobile app (the protocol is basically a TOTP implementation brought from a private company).

Re: Ask HN: Why did smartphones become a single point of failure?

#205
post #88

Earlier quoted context omitted.

Before smartphone, if you lose your passport everything goes wrong as well. (and noticing your phone is missing and finding it back is way easier than passport)

The worrying difference for me here is that when I travel, I pull my phone out of my pocket 50 times a day but I only use my passport once or twice a week and can store it safely in between.

I strapped mine to a motorcycle and subjected it to sun, rain and dust for a few months. The GPS interface was baked into the screen, but it kept going. It even flew off the bike at speed once. I never had a phone fail from abuse.

But I had much dumber failures:

- Walk on a log to get a better picture of a lake, slip, and drop the phone in freezing water. Took multiple weeks to regain access to everything.

- The humidity presses buttons in my pocket. Too many passcode attempts, iPhone factory resets itself while abroad. Lost a bunch of unsynced photos that time.

Re: Ask HN: Why did smartphones become a single point of failure?

#206

Earlier quoted context omitted.

This is the best way to go about this (the first line, the second line is rather variable). Phones didn't suddenly become a single point of failure, it's mostly middle-management combined with checkbox-security that ends up with SMS, TOTP and push-based confirmation factors. It's not the best way, but the easiest way to set things up. To make matters worse, TOTP is easy to copy for 'backup' purposes, so it's really n…

> all other second factors can be lost too The problem is how the phone is irreplaceable and non-redundant, and not that it can be lost.

That is not really the problem, that is the symptom. Making it redundant makes the factor property moot. And while it might be hard to replace, it's not irreplaceable. One issue is that if you have 60 TOTP accounts on an app on a phone and you desire to replace it you'll end up with a keyring full of FIDO keys. Those are just as 'non-redundant' and 'irreplaceable' as the phone was.

The problem that causes the symptom is pass-the-audit mentality in the implementation of MFA. You have many options to make this "better" like picking any push, FIDO, U2F and TOTP method at authentication time. Lose 3 of those and you still have one available for the normal flow. And then there are backup codes that most people don't actually print and store because for some reason they are either unaware of it or believe that it will never affect them.

Re: Ask HN: Why did smartphones become a single point of failure?

#207
I had a similar problem very recently with OVH. Though it's not related to smartphones.

I migrated my personal domain (nameserver and email) to a different IP address. After migrating the server, I wanted to change the glue record on OVH.ie. They detected some suspicious activity and prompted me to enter the code that was sent to my email, email on the domain that has unreachable namesevers because I couldn't log in to their dashboard. I had no 2FA enabled.

The interesting part about this is that I knew it might cause problems, so I also added a secondary email address to OVH, the one from our national academic research network. But OVH only sends codes to the primary mail! How useful ...

Re: Ask HN: Why did smartphones become a single point of failure?

#208

Earlier quoted context omitted.

Let's not forget the benefits either. Reduced redundancy is _good_ (as long as nothing fails in the chain, ofc). It enables society to make more, for lower costs. And it works remarkably well, overall.

But thats the problem being expressed - things will fail. Things will always fail, and ignoring that is the equivalent of burying your head in the sand and thinking your ass is covered.

If things go right 8 times out of 10 overall, that's a net win. Expected value - I get Product X $2 cheaper if things go right, but lose $6 if things go wrong. Expected value = 2*.8-6*.2 = .4. Overall net positive.

Re: Ask HN: Why did smartphones become a single point of failure?

#210
post #182

Earlier quoted context omitted.

How often are customers really given that choice, as opposed to companies making the decision on their behalf because customers are stupid (they just want a better horse after all). We can't buy what doesn't exist after all.

> How often are customers really given that choice? You and your competition produce two equivalent products. They sell theirs for $100: do you feel confident in pricing yours at $110 and base your commercial copy on "We rely on a more robust logistic chain in case of a world-wide catastrophe"?

This isn't asking the customer to make a choice, it's asking a businessman if they're willing to invest in their business.

And it is an investment, not an ongoing significant cost. Once you have a local surplus established, you can simply buy what you use going forward - the same as any other JIT manufacturing process - with a minimal ongoing cost for storage space.

As such, a businessman who wishes to invest in the in the longevity of the business over maximizing this year's profits would be happy to sacrifice some profit for the ability to remain solvent in the next supply chain breakdown.

Because there will be another one.

Post reply on HN