Live data from Hacker News

Ask HN: Why did smartphones become a single point of failure?

news.ycombinator.com

41–50 of 289 posts

Re: Ask HN: Why did smartphones become a single point of failure?

#41

Because using phone numbers to decide if human or bot is cheap, easy, and effective. Politically, there is no will for a national identity verification type service as infrastructure. And this way, all the work gets outsourced to ATT/Verizon/T-Mobile, and politicians get to say “it is not our fault” and telecoms get to say “it is not our job”.

The lack of political will you speak of is better seen as a reaction to the deeper problem that there is no political will for protections that would go against commercial desires. Social security numbers were created solely to facilitate social security but had no legal protections enforcing this, and thus are now being widely abused by private companies. The same with driver's license numbers. Without a US GDPR that gives me the right to delete my permanent records from corporate surveillance databases, I am dead set against government mandates that would create even more vulnerabilities for unaccountable surveillance companies to exploit.

Re: Ask HN: Why did smartphones become a single point of failure?

#42
post #23

Go through the whole list and figure out which of these services really requires your phone, and which you have set up on your phone because that seemed the easiest path. Tell your workplace you're about to switch from carrying a phone to a landline: what is their fallback option? (It's about 50/50 whether they have one, but they definitely should.)

Good 2 factor auth systems will provide the option to be called on the number on your account.

Re: Ask HN: Why did smartphones become a single point of failure?

#43

Why did gasoline become a single point of failure in automobiles? Why did the strings on my guitar become a single point of failure? Creating redundancy for every dependency is not always practical or economical.

Terrible comparison. If you don't have gasoline you can still walk, get a cab or take the bus to wherever you're going. It's not gatekeeping anything, it's just a convenience. Strings on your guitar can be readily replaced, and again, it's not gatekeeping you from your finances or your employment (unless you're a musician, but in this case I'm sure you'll have spare strings and instruments so that if one breaks you c…

> If you don't have gasoline you can still walk, get a cab or take the bus to wherever you're going.

Not all of us live in an area where those options are available. But I can transport your arguments back to the OP post. You can still call your bank from someone else's phone. You can still walk into a bank branch or use an ATM. Using their website is just a convenience. If you lose your phone you can just get a new one and carry on without thought (replace it).

Re: Ask HN: Why did smartphones become a single point of failure?

#44
post #2

>i can't log in to any of my banks without my phone. Don't know about banks in Europe but in USA, I can log into Bank Of America and JP Morgan Chase without any phone authentication. If I reformat my harddrive or buy a new computer and the bank doesn't recognize the web browser because no previous cookie has been found, the website will generate a one-time code and send it to my email address. I then enter that secur…

I can log into my bank without my phone in Denmark, but they are pretty much getting rid of that capability. Supposedly more 'secure'

That's code for 'cheaper'. Banks in the Netherlands are constantly trying to push all their customers to their apps, some (like ING) are actively trying to get rid of their alternative (but keep getting somewhat forced to offer it), and some (like BUNQ and KNAB) are 'smartphone only' from the start.

Cryptographically, the idea of a discrete piece of hardware that uses the chip in your debit card to generate secure responses is fairly sound. And if smartphones didn't exist, it would be an unquestioned piece of technology that might even be commodified to the point that any such device could be used by all banks in the country. But smartphones exist, and having the customer loan the banks their hardware (which is often replaced within five years, so free updates too!) is quite attractive. No more hardware to support!

Re: Ask HN: Why did smartphones become a single point of failure?

#45
Only banks do that. All other services accept TOTP (which you can have on multiple devices) or YubiKeys/webauthn/U2F (where you can add multiple hardware keys).

And even here, my bank accepts two (or more) devices with an active instance of their app. So the solution to this spof is the same as always: redundancy. You need a second phone. Your old one is probably good enough.

Re: Ask HN: Why did smartphones become a single point of failure?

#46

I use Google Voice, and the number that I use for PINs I can login to with just a password. That way I can always access text messages even if my phone is gone. You need it when traveling and your shit gets jacked. I haven't tried it but an Android emulator should allow you to use apps without a smartphone.

>I can login to with just a password

If you can, so can anyone. Although using a unique/rare password (globally, not just among your accounts) is probably enough to make this a non-issue.

Re: Ask HN: Why did smartphones become a single point of failure?

#47

I use Google Voice, and the number that I use for PINs I can login to with just a password. That way I can always access text messages even if my phone is gone. You need it when traveling and your shit gets jacked. I haven't tried it but an Android emulator should allow you to use apps without a smartphone.

If the banking software lets you log in via an Android emulator I'd say it's a pretty badly written piece of banking software.

I understand why HN readers would want to maybe use an emulator to avoid having a phone but really what other use case is there than that or a scammer trying to spoof you.

Re: Ask HN: Why did smartphones become a single point of failure?

#48
I don't have the same view, in my mind you have created a single point of failure for _yourself_. I use Authy for MFA, which comes with a desktop app. Phones dead / missing? No problem, I can get OTP's from my laptop.

What about text messages? Google voice. Which of course has a desktop interface. I've been doing this for years. It's nice not to have to rely on a watch, or phone entirely - although they do make my life easier.

Re: Ask HN: Why did smartphones become a single point of failure?

#49

I use Google Voice, and the number that I use for PINs I can login to with just a password. That way I can always access text messages even if my phone is gone. You need it when traveling and your shit gets jacked. I haven't tried it but an Android emulator should allow you to use apps without a smartphone.

Some apps will. But most "secure" apps would refuse to run on the virtual device.

Re: Ask HN: Why did smartphones become a single point of failure?

#50
post #45

Only banks do that. All other services accept TOTP (which you can have on multiple devices) or YubiKeys/webauthn/U2F (where you can add multiple hardware keys). And even here, my bank accepts two (or more) devices with an active instance of their app. So the solution to this spof is the same as always: redundancy. You need a second phone. Your old one is probably good enough.

I've never seen a bank accepting more than a single device with an active instance of their app.. I would be over the moon if they did but they don't. So, last time I broke my phone, it took quite a while to get access to my bank accounts again.
Post reply on HN