Live data from Hacker News

Phone numbers are not proper verification

b1nary.ch

1–10 of 159 posts

Re: Phone numbers are not proper verification

#3
Google does let you have 2 factor setup without a phone number as a factor, but strangely you need a phone number temporarily. You add the phone number as a factor, then add other factors (such as Google Authenticator and Yubikeys) then delete the phone number.

Re: Phone numbers are not proper verification

#4

The same properties that make phone numbers bad also make email addresses, postal addresses and other IDs bad. Sometimes a weak option is better than no option at all.

E-mail is far from being perfect (you can get you account unilaterally closed by your provider or you can lose your domain name), but in practice I've been using the same address for more than a decade, and I have aliases that are meant to last forever (my almuni address), while in the same period I've had 5 different mobile numbers that I used for services like banking or IM, which is very inconvenient indeed.

Re: Phone numbers are not proper verification

#5

The same properties that make phone numbers bad also make email addresses, postal addresses and other IDs bad. Sometimes a weak option is better than no option at all.

The point with email is that i CAN control the address myself. Sure i use external services to send and receive, but if that fails for some reason i can still setup my own servers and still have access to my accounts. No way of doing that with phone numbers.

Postal addresses are Name + Address so get invalidated automatically when i move. Therefore i would argue are also better.

Re: Phone numbers are not proper verification

#6
post #3

Google does let you have 2 factor setup without a phone number as a factor, but strangely you need a phone number temporarily. You add the phone number as a factor, then add other factors (such as Google Authenticator and Yubikeys) then delete the phone number.

This is new to me thank you. I am a little afraid of locking myself out so i am hesitate to just try it, i will read into it and give it a try. Seriously thanks.

Re: Phone numbers are not proper verification

#7

The same properties that make phone numbers bad also make email addresses, postal addresses and other IDs bad. Sometimes a weak option is better than no option at all.

E-mail is far from being perfect (you can get you account unilaterally closed by your provider or you can lose your domain name), but in practice I've been using the same address for more than a decade, and I have aliases that are meant to last forever (my almuni address), while in the same period I've had 5 different mobile numbers that I used for services like banking or IM, which is very inconvenient indeed.

Exactly! And you dont simply loose a domain if you dont really fail at renewing it, which usually is a peroid of 2 months getting reminder emails.

Re: Phone numbers are not proper verification

#8
post #3

Google does let you have 2 factor setup without a phone number as a factor, but strangely you need a phone number temporarily. You add the phone number as a factor, then add other factors (such as Google Authenticator and Yubikeys) then delete the phone number.

> Google does let you have 2 factor setup without a phone number as a factor, but strangely you need a phone number temporarily.

I finally set up 2FA on my Google account this weekend.

It struck me as incredibly odd that Google requires a phone number to enable 2FA. NIST recently advocated against using SMS for OoB auth. [0]

If I had been an account hijacker with the password (e.g. obtained via phishing) it would have been ludicrously simple for me to enable 2FA on someone else's account.

I don't understand, I already have an Android phone with Google Play Services installed. Why isn't pressing "Okay" on my phone sufficient? It's certainly not any more insecure than an SMS.

What I view as even worse is on the first attempt the SMS didn't go through, so I asked Google to give me a call. Evidently my provider blocks whatever number they're using to call out of, so my phone never rang. But Google left the verification code anyway, AS A VOICEMAIL!

My inner tin foil hat says Google wants a phone number for other purposes.

[0] www.securityweek.com/nist-denounces-sms-2fa-what-are-alternatives

Re: Phone numbers are not proper verification

#9
post #3

Google does let you have 2 factor setup without a phone number as a factor, but strangely you need a phone number temporarily. You add the phone number as a factor, then add other factors (such as Google Authenticator and Yubikeys) then delete the phone number.

> Google does let you have 2 factor setup without a phone number as a factor, but strangely you need a phone number temporarily. I finally set up 2FA on my Google account this weekend. It struck me as incredibly odd that Google requires a phone number to enable 2FA. NIST recently advocated against using SMS for OoB auth. [0] If I had been an account hijacker with the password (e.g. obtained via phishing) it would hav…

> My inner tin foil hat says Google wants a phone number for other purposes.

Just like Twitter these days. "Telephone number is optional and for your security". 2 minutes later my new accounts are always locked and i need to provide a telephone number to enable it again. They used SMS until recently, now they use a call service which only works with a fraction of numbers. (Tried 2 thai, 1 cambodian number, none accepted)

I seriously dont get what they are trying to do other than creating a database of telephone numbers and locking users in third world countries out.

Also agree with that Google actually knows enough to just verifiy it based on my phone. Telephone number is not necessary, especially i "verified" my account in the past with a phone call, why again?

Re: Phone numbers are not proper verification

#10
This rant is exactly why phone numbers are a good way to do two-factor. The author lost control of their phone number ("as i quit the account shortly...") and subsequently had an extremely hard time authenticating to their bank, Google, Twitter, etc.

Getting a new phone number set up is time consuming, even with a Twilio-like service. This is a good thing. Your IMEI number isn't portable, and until there is a physical token on your phone that is also portable, a phone number is the next best option.

Post reply on HN