Earlier quoted context omitted.
This happened to me with a major bank. They were using the same number for 2FA and some other types of texts. I got locked out of my account for a while because I had unsubscribed from their marketing texts. What an unbelievably dumb way to send 2FA codes.
Yet another reason why SMS 2FA should not be used. Shameful.
Ask HN: Should you reply STOP to unwanted texts?
341–350 of 386 posts
Re: Ask HN: Should you reply STOP to unwanted texts?
#342Earlier quoted context omitted.
I think Twilio requires its customers to go through the process of registering with the CTIA before allowing use of the SMS API. I abandoned a project because the process was too burdensome. Political campaigns are exempt though.
Is that new? I tried it out for fun once and it only took a few minutes and I don't recall any major hoops. I think it's different if you're applying for a shortcode vs a regular or toll free number though. There are different regulations governing all of those.
Having been on the purchasing end for wholesale marketing SMS I can tell you most of sales people will suggest the 'correct' way and happily sell things that let you do it the 'wrong' way.
Re: Ask HN: Should you reply STOP to unwanted texts?
#343A Golden Rule of the internet says that you should never reply to unwanted texts on any medium: - stalkers and trolls live off reactions, both positive and negative ones - spammers will use your reply to verify there's a human at the other side - colleagues and friends will hate you because everybody thinks they're important Replying only has negative effects. Use client-side filtering, kill files, blocking functions…
Except that STOP is handled at the carrier level and isn't even returned to the sender. It's effectively a mandated block command.
Re: Ask HN: Should you reply STOP to unwanted texts?
#3441) Turn on filtered view on iMessage
2) Actually report the abuse to carriers. iOS makes it easy, but it seems pretty ineffective because the abusers can just use another number. But if you complain to the carrier directly, then they can (hopefully) remove you entirely for that shady customer (and possibly kick them off). Here's what I do
a) Go to https://www.ipqualityscore.com/free-carrier-lookup (or whatever site you like, that's just the one I found)
b) Type in the spam number
c) Find the carrier name
d) Google the carrier, go their site, and find "Report abuse" or something similar
e) Fill out the form. Include your contact info so you actually know whether something is done or not.
Re: Ask HN: Should you reply STOP to unwanted texts?
#345Earlier quoted context omitted.
I find it such a weird thing, maybe it's nice in some cases, but really this is a weird mechanism. Phone numbers are exchanged a lot and repurposed. Most providers/carriers will likely have a do-not-use-for-x-amount-of-time bin to put newly reclaimed numbers in, but after a while, it will always be re-used. hence this kind of issue can happen. In my country there's a place to register to disallow unsolicited marketin…
The US has a 'Do Not Call' registry for unsolicited phone calls, but technically doesn't need one for texts because it's illegal to send marketing texts without prior consent in the first place. Thing is, 'consent' often just means failing to notice a checkbox during a signup flow or something, so people end up getting junk anyway. Even more annoyingly, politicians wrote in an exception for themselves. In combination…
Re: Ask HN: Should you reply STOP to unwanted texts?
#346Earlier quoted context omitted.
I think Twilio requires its customers to go through the process of registering with the CTIA before allowing use of the SMS API. I abandoned a project because the process was too burdensome. Political campaigns are exempt though.
Is that new? I tried it out for fun once and it only took a few minutes and I don't recall any major hoops. I think it's different if you're applying for a shortcode vs a regular or toll free number though. There are different regulations governing all of those.
The only phone number I ever texted was my real cell number, it's no longer worth having a Twilio number for a hobby project.
Re: Ask HN: Should you reply STOP to unwanted texts?
#347Beware the edge case: I responded STOP to a message years ago, then was unable to receive SMS from a popular money transmission app during the signup flow to claim funds that a friend sent me. After over a month of troubleshooting, it turns out that I had sent "STOP" to that number years ago on a different device (no longer visible in chat history) and now had to send "UNSTOP" in order to receive the phone verificati…
This happened to me with a major bank. They were using the same number for 2FA and some other types of texts. I got locked out of my account for a while because I had unsubscribed from their marketing texts. What an unbelievably dumb way to send 2FA codes.
Re: Ask HN: Should you reply STOP to unwanted texts?
#348Re: Ask HN: Should you reply STOP to unwanted texts?
#349Earlier quoted context omitted.
Speaking mostly for the US here. The STOP keyword is mandated as unsubscribe at the carrier level (Verizon, ATT, TMo) not just the vendor level. So if you reply STOP, it's very likely that you will not receive another message from that number. This will be true for any programmatic SMS vendor. There could be smaller scale & more manual approaches, but that would be rare. There has been a big effort in the last year+…
> What I want to know is, what's the purpose of those random texts that just say something like, "How's it been?" from a number that I've never communicated with? What's the angle there? Anyone know? My understanding is that they will pretend it's a wrong number, but then make a joke or talk about some innocuous hobby and try to build up trust over weeks/months to eventually phish or scam you. I forget where I read i…
Re: Ask HN: Should you reply STOP to unwanted texts?
#350Earlier quoted context omitted.
TOTP (thing that generates the 6 numbers every 30 seconds) whether that's a dedicated device (secure but very annoying) or a TOTP app on your phone (what most people use).
Password managers like 1Password also support TOTP, it doesn't have to be an app on your phone.
I like this simple TOTP code generator: