Earlier quoted context omitted.
Are you implying we should have wasted billions manufacturing extra chips just in case there was a shortage and consumers didn't want to wait a year before buying a new car/truck?
I don't see anyone demanding a planned economy. I see people recognizing reality - JIT is efficient but fragile in the face of disruption. Seems to me the sensible thing to do would be to recognize that for what it is and try to strike the right balance in an uncertain world. Even if your concerns are strictly commercial, a couple points margin in good times is unlikely to balance a year of massively screwed up suppl…
Ask HN: Why did smartphones become a single point of failure?
221–230 of 289 posts
Re: Ask HN: Why did smartphones become a single point of failure?
#222Re: Ask HN: Why did smartphones become a single point of failure?
#223The ideal situation is for a site using 2FA to allow me to choose the 2FA application: Google Authenticator, Authy, OneAuth(I think), etc.
Tools like Okta Verify, RSA, Symantec, or SMS based 2FA make the phone a true SPOF. You can't have backup codes, you can't migrate installations. In other words, I hate forcing my phone to be an irreplaceable hard token lest I drop it in the river and have to do a bunch of resets.
Re: Ask HN: Why did smartphones become a single point of failure?
#224This is a big problem for me as a traveller. If I travel long distance and I lose my phone, I lose access to both my personal and business bank. I once dropped my phone in a lake (I'm clumsy) and was locked out of most things for a few weeks. I prefer TOTP for most things. Keepass supports them across platforms, but Aegis has a better experience on mobiles.
It is baffling to me that banks of all places seem to have the absolute shittiest implementations of 2FA I have ever experienced - if they even have it.
FWIW I use 2FA a lot more now that I discovered Authy, which backs your 2FA tokens (encrypted) to the cloud. There is also 1Auth, I believe the name is, which allows you to do offline encrypted backups.
Re: Ask HN: Why did smartphones become a single point of failure?
#225I didn't have a cell phone until work issued me one around 2018 or so. (I never really liked the idea.) Generally, I don't have many single points of failure tied to the phone not tied to work...certainly nothing related to my banking. You can still live in 2022 without one, although the assumption that you have one gets more annoyingly entrenched year-by-year. I don't quite know what these single points of failure a…
How is this possible? Are you from an older generation? Do you live so far away from the city?
Let's pretend you have a smartphone and a computer. Take the phone, and look at every application that you actually use. Make sure that application can be used on a web browser and you have the credentials stored in a password manager. Transfer your cell number to a VOIP service. Find your carrier and cancel your contract or autopay or whatever.
Now shut off the phone, and leave it in a drawer. If you can take out the battery, that's good, but you probably can't without breaking the case.
Put some cash in your pocket if you weren't in the habit of doing that before.
That's it, you're done. Remember to check your mail and messages on the VOIP line from time to time. If you ask the VOIP people to send voice mail to email, that makes it just one thing to check.
Re: Ask HN: Why did smartphones become a single point of failure?
#226Earlier quoted context omitted.
Yup. Chase does the same thing. They blackhole SMS to Google voice.
Same with USAA. This is pretty recent though.
I have no idea why generic TOTP with backup codes is not an option for every site on the planet.
Re: Ask HN: Why did smartphones become a single point of failure?
#227I don't have the same view, in my mind you have created a single point of failure for _yourself_. I use Authy for MFA, which comes with a desktop app. Phones dead / missing? No problem, I can get OTP's from my laptop. What about text messages? Google voice. Which of course has a desktop interface. I've been doing this for years. It's nice not to have to rely on a watch, or phone entirely - although they do make my li…
* mandate MFA
* use proprietary and/or insecure phone-based mechanisms
I agree with all my heart that TOTP with backups is ideal. I discovered Authy a few months ago, and only because of that app did I enable 2FA on Amazon, Discord, AWS, and a number of other sites that offered it.Ask me how many of the six banking and investment apps I use support generic TOTP.
Re: Ask HN: Why did smartphones become a single point of failure?
#228I had a similar problem very recently with OVH. Though it's not related to smartphones. I migrated my personal domain (nameserver and email) to a different IP address. After migrating the server, I wanted to change the glue record on OVH.ie. They detected some suspicious activity and prompted me to enter the code that was sent to my email, email on the domain that has unreachable namesevers because I couldn't log in…
One should be able to login with multiple methods. E.g. with 2FA you should always be able to connect two devices, and if you choose to login with a third party like Google/Facebook you should be able to add a password for login as well.
Re: Ask HN: Why did smartphones become a single point of failure?
#229I didn't have a cell phone until work issued me one around 2018 or so. (I never really liked the idea.) Generally, I don't have many single points of failure tied to the phone not tied to work...certainly nothing related to my banking. You can still live in 2022 without one, although the assumption that you have one gets more annoyingly entrenched year-by-year. I don't quite know what these single points of failure a…
How is this possible? Are you from an older generation? Do you live so far away from the city?
For myself, I have a cell phone, but I don't have anything on it. No banking. No work apps. Nothing. When work asked me to put an authentication app on my phone so I could sign in using their new authentication scheme, I said, "No, I'm not putting any work app on my private phone. Hard no. Give me something else." So they gave me a little USB thingy to use instead.
If I lose my phone, I lose my contacts (but my carrier has a copy of those), my text history (but maybe my carrier has those too?), and any photos that I haven't copied off. That's it.
Re: Ask HN: Why did smartphones become a single point of failure?
#230Earlier quoted context omitted.
how about taking a fully set up back up phone with you? that's what I do. losing a phone travelling nowadays is in deed an expensive and extremely inconvenient mishap.
I travel by bicycle or motorcycle, so space and weight come at a huge premium. And of course my bank only lets me pair one phone per account.
sure, but being protected from losing your digital prowess comes at a high utility per weight ratio.
> And of course my bank only lets me pair one phone per account.
that's a bummer. I can pair several. just need to scan some qr code.