Live data from Hacker News

Ask HN: Why did smartphones become a single point of failure?

news.ycombinator.com

211–220 of 289 posts

Re: Ask HN: Why did smartphones become a single point of failure?

#211

This has been my point for the last 5 or 10 years. That's why I have a "home phone" with banking apps, 2FA and important stuff installed. It has no SIM card and never leaves home. For everything else I have my "street phone".

Many banking apps require a phone number/SIM card to operate, but assuming you can copy codes, etc, what happens when you want to use those apps out and about (or abroad) if the phone never leaves home?

> when you want to use those apps out and about

Fortunately, my lifestyle places me out of that use case.

Re: Ask HN: Why did smartphones become a single point of failure?

#212

This has been my point for the last 5 or 10 years. That's why I have a "home phone" with banking apps, 2FA and important stuff installed. It has no SIM card and never leaves home. For everything else I have my "street phone".

What if you go on a vacation?

I can use my credit card.

Re: Ask HN: Why did smartphones become a single point of failure?

#213

How do I backup all my 2fa that I have on my phone? I would like to have a backup at home in case of the phone being stolen.

Also interested in this. In Brazil, whenever you get your phone stolen, the robbers will screw you over by getting access to accounts and issuing pre approved loans to other accounts. I'd love for my 2FA to be tied elsewhere instead of the same device where I do transactions.

Re: Ask HN: Why did smartphones become a single point of failure?

#214

Earlier quoted context omitted.

But thats the problem being expressed - things will fail. Things will always fail, and ignoring that is the equivalent of burying your head in the sand and thinking your ass is covered.

If things go right 8 times out of 10 overall, that's a net win. Expected value - I get Product X $2 cheaper if things go right, but lose $6 if things go wrong. Expected value = 2*.8-6*.2 = .4. Overall net positive.

"The price for something is measurably higher if the manufacturer maintains a surplus of components with an inelastic supply" is not really true though.

Once the initial investment in creating a stock of those items is done, there's only a minimal storage cost. For things like chips for cars, that storage cost is probably measured in double-digit dollars a year to create billions of dollars worth of vehicles.

Is investing in a business to smooth over supply chain problems really so taboo to a modern businessman?

Re: Ask HN: Why did smartphones become a single point of failure?

#215
post #152

Earlier quoted context omitted.

There are low end phone plans in the range of $10-15/mo. You can get a prepaid smartphone for like $40, and if you aren't using cellular data, you can get the smartphone itself for around $20.

Yeah, so I can wait in the lobby for 17 minutes while some 1.8 star museum app downloads to my phone over a crappy network that my provider lied about the performance of instead of someone just handing me a paper map.

Or you use wifi like a normal person.

We call them phones because that's what they evolved from but smartphones are fully functional computers that we can use anywhere with ease, and using cellular data to make phone calls is only one small facet of their usage.

For the overwhelming majority of people, being able to just pull up a map on their phone is the more convenient and preferred option. "Just handing you a paper map" is not so simple when you don't have paper maps because getting custom paper maps printed is expensive.

Re: Ask HN: Why did smartphones become a single point of failure?

#216
post #144

Earlier quoted context omitted.

If you don't have you banks app, you can still go to the actual bank and tell them to do your transactions.

That's not so easy nowadays. Firstly with covid-19 many banks don't accept walk-ins and have a long waiting list for appointments. Secondly, what if the bank or other service i'm using has no physical offices at all? Or what if they're simply too far away and I'm an octogenarian, perhaps with no driving license? Eh? Am I supposed to take an uber to somewhere 100/200 miles away just because morons are given decision-m…

Your argumentation is myopic. I'm not seeing anyone making excuses. I'm seeing people face the realities that few systems (if any) are without single points of failure.

Take the mobile app dependency away from banking. Then what? There's a dependency on having a computer. A dependency on having power and internet. Why did the banking system build around these single points of failure?

The reality of system design dictates that you measure risk in terms of what is acceptable vs not-acceptable, the solution on whether it is practical vs not-practical, and the implementation on whether it is economically viable. Raising a stink because your bank wants you to use a mobile phone for verification is like complaining that your car requires gasoline to work. Are there other ways of solve the problem? Sure. Did the solution they landed on meet their requirements, yes. I hardly consider them morons for going with the cell phone approach.

Re: Ask HN: Why did smartphones become a single point of failure?

#217
Ask your bank and other to give you a different way for authentication. You will get a other tool for that. There are serval hardware-authenticators and other tools out there and each bank or service offers this to you. Its yourself who create this single point of failure. I have a second (old) phone at home, ready for reactivation if needed. I am teaching my kids to not use the same Mailadress / mobile number for each service and to be sure to have a good backup for really important accounts (really important for my kid means: for Steam and other games). Try to find different way to get the authentication. They exist. The only disadvantage is: you have to ask and it isn't as simple as an mobile.

Re: Ask HN: Why did smartphones become a single point of failure?

#218
post #143

Earlier quoted context omitted.

Regardless of who is doing the job, you're still going to need some device on your person (or otherwise readily accessible) that can be used to confirm that you are actually you, and whatever that device is will become a single point of failure. The real issue is there needs to be some simple standard workflow for when the device (be it smartphone or otherwise) fails. And in this case the government pretty much alrea…

> you're still going to need some device on your person (or otherwise readily accessible) that can be used to confirm that you are actually you Nah, we don't need that. We've been doing without that for thousands of years.

Well there's this new thing called the computer which offers both exciting new opportunities like online banking but also new challenges like password cracking which mean we can no longer rely on old methods of identity verification like pulling swords from stones.

Re: Ask HN: Why did smartphones become a single point of failure?

#219

I didn't have a cell phone until work issued me one around 2018 or so. (I never really liked the idea.) Generally, I don't have many single points of failure tied to the phone not tied to work...certainly nothing related to my banking. You can still live in 2022 without one, although the assumption that you have one gets more annoyingly entrenched year-by-year. I don't quite know what these single points of failure a…

Recently I had the displeasure of traveling through Newark Airport and at least at Terminal C, you cannot order anything from any bar or restaurant without a phone. You must scan the QR code and order that way. If you talk to a worker or even manager and tell them you don't have a phone, they will tell you they can't help you.

That feels just asinine, specially in place like airport where people might prefer not to use their phones for various reasons...

Re: Ask HN: Why did smartphones become a single point of failure?

#220
post #2

>i can't log in to any of my banks without my phone. Don't know about banks in Europe but in USA, I can log into Bank Of America and JP Morgan Chase without any phone authentication. If I reformat my harddrive or buy a new computer and the bank doesn't recognize the web browser because no previous cookie has been found, the website will generate a one-time code and send it to my email address. I then enter that secur…

A bank in Finland: they try to push their authenticator which doesn't work on my phone (de-googleized android and too old),but they have retained the option of using an OTP code list + sms, previously it was just OTP code list, but due to some silly directives they added sms. Authenticating with bank OTP also work for government and other stuff. (Common here as there is no state authentication system other than some…

I really never got the point of the SMS. If I was deciding it I would have mandated that authentication can't be on the same device payment happens. Just to see how they solve that issue...
Post reply on HN