Live data from Hacker News

Ask HN: Why did smartphones become a single point of failure?

news.ycombinator.com

91–100 of 289 posts

Re: Ask HN: Why did smartphones become a single point of failure?

#93
post #3

Indeed it's incredibly stupid development. Fuck smartphones, really. I don't own one and I feel happy overall, but life is complicated because nowadays some sort of stupid app is required (most of the time, for no good reason) and dealing with those requirements always cost so much thinking. I don't want a micro-computer in my pocket, I stay at the computer all day anyway, a better one. Why can't I do with a real com…

Absolutely!

I lost my iPhone 7+ recently and had no idea how attached I was to that phone. Being someone conscious of infosec I had iCloud turned off and what I thought were minimal apps installed. That said, and with the fingerprint reader/my 18 char PW, I'm pretty sure no one besides a nation state/NSO could get into my phone. So losing it wasn't really a big deal except for the loss of contacts (had most on a old phone) and being locked out of my email (thanks 2FA).

Unlike you, I haven't gone fully phone free. But I do now have a free Android phone that has nothing on it that I can be locked out of. No medical, no banking, nothing personal except for email. And if I felt I could get away with it, I'd have no phone at all.

Re: Ask HN: Why did smartphones become a single point of failure?

#94
post #2

>i can't log in to any of my banks without my phone. Don't know about banks in Europe but in USA, I can log into Bank Of America and JP Morgan Chase without any phone authentication. If I reformat my harddrive or buy a new computer and the bank doesn't recognize the web browser because no previous cookie has been found, the website will generate a one-time code and send it to my email address. I then enter that secur…

Similar experience in the US with the banks I’ve used. I can simply use the PC without involving my phone.

Also if all else fails I can go in to the bank and take care of things.

Re: Ask HN: Why did smartphones become a single point of failure?

#95

I use Google Voice, and the number that I use for PINs I can login to with just a password. That way I can always access text messages even if my phone is gone. You need it when traveling and your shit gets jacked. I haven't tried it but an Android emulator should allow you to use apps without a smartphone.

> I can login to with just a password

You're logging in with a Google Account and when the account gets locked it's game over with no chance of appeal.

https://news.ycombinator.com/item?id=31070914

Re: Ask HN: Why did smartphones become a single point of failure?

#96
post #29

I hate it. They have been phasing out web for years in the EU. Banks mostly but these days employers too. Getting a separate device, or multiple, seems like the least horrible options to me. Turns out everyone wants a piece of my data I in the name of convenience. Only, it's their convenience, not mine.

"They have been phasing out web for years in the EU." This is such a perfect summary of the situation; thank you for formulating it so clearly. To me is insane that we are switching to a perfectly open and interoperable standard to the walled gardens of iOS and Androids.

This is why I ordered both GNU/Linux phones, Librem 5 and Pinephone, to support the alternative. Of course, I have problems with the apps now, and I refuse to install them as much as possible. Every time someone tells me about an app, I'm asking whether they have an app for my Linux smartphone.

Re: Ask HN: Why did smartphones become a single point of failure?

#97
post #88
post #18

This is a big problem for me as a traveller. If I travel long distance and I lose my phone, I lose access to both my personal and business bank. I once dropped my phone in a lake (I'm clumsy) and was locked out of most things for a few weeks. I prefer TOTP for most things. Keepass supports them across platforms, but Aegis has a better experience on mobiles.

Before smartphone, if you lose your passport everything goes wrong as well. (and noticing your phone is missing and finding it back is way easier than passport)

Everything? The only thing that goes wrong is being unable to travel internationally, but I think consulates often have a process for issuing emergency documents for even that case?

Re: Ask HN: Why did smartphones become a single point of failure?

#98
post #71

Quoted post unavailable.

Dude, what? How many services require SMS 2FA again? Your phone is indeed a SPOF. If you lose your phone, you're fucked in a variety of scenarios. To say nothing of services that require a custom app and accept nothing else.

Yep! I have all of the things above (yubikeys, many PCs, a couple voip numbers with SMS, ability to emulate Android on PC, a host of old smarphones...) still, if I lose the one smartphone on which -that- custom app is installed, I'm hosed.

And I can't even install the app on a second phone, because: ah, ha! Only one at a time! There is no installing two, Luke. Only one there will be. (There you go... quotation inception.)

Re: Ask HN: Why did smartphones become a single point of failure?

#99

Nobody knows how to do a failure analysis. I used to work in r&d, now that I’m building websites and mobile apps the culture doesn’t care. Pointing out obvious design limitations will, more often that not, make me the asshole. Not even trying to delay ship or get future rework scheduled, just having it documented is too much. Out of sight out of mind.

It's not that people don't know it's a SPOF. The issue is that if you fail in a way that is common, nobody blames you. Cell phone 2FA is so ubiquitous that when it doesn't work clients wonder if they're the one fucking up. We had a massive internet outage in Canada recently and nobody blamed individual shops for not being able to take credit cards, they blamed the phone company. If you roll your own thing, even if it…

You hit the nail on the head

Re: Ask HN: Why did smartphones become a single point of failure?

#100
post #23

Go through the whole list and figure out which of these services really requires your phone, and which you have set up on your phone because that seemed the easiest path. Tell your workplace you're about to switch from carrying a phone to a landline: what is their fallback option? (It's about 50/50 whether they have one, but they definitely should.)

Depends on the security requirements and terms of employment. Where I work now, you’d get a hard token or work phone if you’re deemed as requiring a phone. In the previous job, you were sent the form for 24x7 building access and were free to drive into work within the on-call response period. You were also reimbursed for your cell phone, that was the bronze handcuff.

Under current case law in the US, my understanding is that public ("operational realities" and reasonable suspicion tests) and private employers (fewer tests) have rights to audit any information on employer-compensated devices they wish (and have access to).

I only use a work phone for work business. If my work requires me to use a phone, I require a work phone.

Carrying two phones is a small price to pay to avoid worrying about an overzealous employer's IT staff.

https://en.m.wikipedia.org/wiki/City_of_Ontario_v._Quon

https://en.m.wikipedia.org/wiki/O%27Connor_v._Ortega

Post reply on HN