Live data from Hacker News

Ask HN: Why did smartphones become a single point of failure?

news.ycombinator.com

51–60 of 289 posts

Re: Ask HN: Why did smartphones become a single point of failure?

#52
Nobody knows how to do a failure analysis. I used to work in r&d, now that I’m building websites and mobile apps the culture doesn’t care. Pointing out obvious design limitations will, more often that not, make me the asshole.

Not even trying to delay ship or get future rework scheduled, just having it documented is too much. Out of sight out of mind.

Re: Ask HN: Why did smartphones become a single point of failure?

#53
post #48

I don't have the same view, in my mind you have created a single point of failure for _yourself_. I use Authy for MFA, which comes with a desktop app. Phones dead / missing? No problem, I can get OTP's from my laptop. What about text messages? Google voice. Which of course has a desktop interface. I've been doing this for years. It's nice not to have to rely on a watch, or phone entirely - although they do make my li…

>Google Voice

Anecdotally, my bank (Wells Fargo) will not accept VOIP numbers for 2FA.

Re: Ask HN: Why did smartphones become a single point of failure?

#54
post #48

I don't have the same view, in my mind you have created a single point of failure for _yourself_. I use Authy for MFA, which comes with a desktop app. Phones dead / missing? No problem, I can get OTP's from my laptop. What about text messages? Google voice. Which of course has a desktop interface. I've been doing this for years. It's nice not to have to rely on a watch, or phone entirely - although they do make my li…

The issue is that some services insist on using their own app as a second factor. You can't choose to use a superior U2F YubiKey, for example. You are also not allowed to have their shitty app installed on multiple phones at the same time. If you lose your phone, you need to call them up to reset this.

To name and shame: BNP Paribas, one of the biggest banks in France.

Re: Ask HN: Why did smartphones become a single point of failure?

#55
post #2

>i can't log in to any of my banks without my phone. Don't know about banks in Europe but in USA, I can log into Bank Of America and JP Morgan Chase without any phone authentication. If I reformat my harddrive or buy a new computer and the bank doesn't recognize the web browser because no previous cookie has been found, the website will generate a one-time code and send it to my email address. I then enter that secur…

A bank in Finland: they try to push their authenticator which doesn't work on my phone (de-googleized android and too old),but they have retained the option of using an OTP code list + sms, previously it was just OTP code list, but due to some silly directives they added sms.

Authenticating with bank OTP also work for government and other stuff. (Common here as there is no state authentication system other than some failed id cards afaik.)

Re: Ask HN: Why did smartphones become a single point of failure?

#56
post #48

I don't have the same view, in my mind you have created a single point of failure for _yourself_. I use Authy for MFA, which comes with a desktop app. Phones dead / missing? No problem, I can get OTP's from my laptop. What about text messages? Google voice. Which of course has a desktop interface. I've been doing this for years. It's nice not to have to rely on a watch, or phone entirely - although they do make my li…

>Google Voice Anecdotally, my bank (Wells Fargo) will not accept VOIP numbers for 2FA.

Yup. Chase does the same thing. They blackhole SMS to Google voice.

Re: Ask HN: Why did smartphones become a single point of failure?

#57
post #50
post #45

Only banks do that. All other services accept TOTP (which you can have on multiple devices) or YubiKeys/webauthn/U2F (where you can add multiple hardware keys). And even here, my bank accepts two (or more) devices with an active instance of their app. So the solution to this spof is the same as always: redundancy. You need a second phone. Your old one is probably good enough.

I've never seen a bank accepting more than a single device with an active instance of their app.. I would be over the moon if they did but they don't. So, last time I broke my phone, it took quite a while to get access to my bank accounts again.

My bank (Polish mBank) even have a section in the webUI to manage these devices along with other access channels.

Re: Ask HN: Why did smartphones become a single point of failure?

#59
post #23

Go through the whole list and figure out which of these services really requires your phone, and which you have set up on your phone because that seemed the easiest path. Tell your workplace you're about to switch from carrying a phone to a landline: what is their fallback option? (It's about 50/50 whether they have one, but they definitely should.)

Depends on the security requirements and terms of employment. Where I work now, you’d get a hard token or work phone if you’re deemed as requiring a phone.

In the previous job, you were sent the form for 24x7 building access and were free to drive into work within the on-call response period. You were also reimbursed for your cell phone, that was the bronze handcuff.

Post reply on HN