The same properties that make phone numbers bad also make email addresses, postal addresses and other IDs bad. Sometimes a weak option is better than no option at all.
E-mail is far from being perfect (you can get you account unilaterally closed by your provider or you can lose your domain name), but in practice I've been using the same address for more than a decade, and I have aliases that are meant to last forever (my almuni address), while in the same period I've had 5 different mobile numbers that I used for services like banking or IM, which is very inconvenient indeed.
Phone numbers are not proper verification
11–20 of 159 posts
Re: Phone numbers are not proper verification
#12Google does let you have 2 factor setup without a phone number as a factor, but strangely you need a phone number temporarily. You add the phone number as a factor, then add other factors (such as Google Authenticator and Yubikeys) then delete the phone number.
> Google does let you have 2 factor setup without a phone number as a factor, but strangely you need a phone number temporarily. I finally set up 2FA on my Google account this weekend. It struck me as incredibly odd that Google requires a phone number to enable 2FA. NIST recently advocated against using SMS for OoB auth. [0] If I had been an account hijacker with the password (e.g. obtained via phishing) it would hav…
"I already have an Android phone with Google Play Services installed."
Guess what - Google already has your phone number before asking for it via the 2FA form. My guess is that the reason they have one platform-independent process for setting up 2FA is for iOS users.
Re: Phone numbers are not proper verification
#13This rant is exactly why phone numbers are a good way to do two-factor. The author lost control of their phone number ("as i quit the account shortly...") and subsequently had an extremely hard time authenticating to their bank, Google, Twitter, etc. Getting a new phone number set up is time consuming, even with a Twilio-like service. This is a good thing. Your IMEI number isn't portable, and until there is a physica…
Sure i could call my bank one a month to change my telephone number, which i loose control of shortly after that (only valid for a few months, prepaid). This is hardly a solution.
On the other side i control my email address, my private key, my home address to a degree, but never my telephone number.
Re: Phone numbers are not proper verification
#14This rant is exactly why phone numbers are a good way to do two-factor. The author lost control of their phone number ("as i quit the account shortly...") and subsequently had an extremely hard time authenticating to their bank, Google, Twitter, etc. Getting a new phone number set up is time consuming, even with a Twilio-like service. This is a good thing. Your IMEI number isn't portable, and until there is a physica…
Author here. I dont have a fixed telephone number anymore. How to handle that? I dont see why i would need one except for authentification purposes ether. My point is that depending on people have a phone number, and even more one that is widely supported (which my current numbers are not) is simply wrong. Sure i could call my bank one a month to change my telephone number, which i loose control of shortly after that…
Re: Phone numbers are not proper verification
#15Earlier quoted context omitted.
> Google does let you have 2 factor setup without a phone number as a factor, but strangely you need a phone number temporarily. I finally set up 2FA on my Google account this weekend. It struck me as incredibly odd that Google requires a phone number to enable 2FA. NIST recently advocated against using SMS for OoB auth. [0] If I had been an account hijacker with the password (e.g. obtained via phishing) it would hav…
> My inner tin foil hat says Google wants a phone number for other purposes. Just like Twitter these days. "Telephone number is optional and for your security". 2 minutes later my new accounts are always locked and i need to provide a telephone number to enable it again. They used SMS until recently, now they use a call service which only works with a fraction of numbers. (Tried 2 thai, 1 cambodian number, none accep…
It seems to be the industry status quo now to assume that everyone uses a smartphone running either Android or IOS, and that everyone wants to use that device for authentication. Meanwhile the tech giants (especially those involved in advertising) probably like having that nice unique alphanumerical identifier for your profile — it tends to be the same for all services you use.
I really hope Fido U2F becomes a de facto alternative for 2FA.
Re: Phone numbers are not proper verification
#16Earlier quoted context omitted.
Author here. I dont have a fixed telephone number anymore. How to handle that? I dont see why i would need one except for authentification purposes ether. My point is that depending on people have a phone number, and even more one that is widely supported (which my current numbers are not) is simply wrong. Sure i could call my bank one a month to change my telephone number, which i loose control of shortly after that…
Go to VOIP.ms set up a number for $1/mo. So 12/year. Have it forward to your number. Use it for verification as well. It supports SMS, though I have found some services won't allow it.
Re: Phone numbers are not proper verification
#17Earlier quoted context omitted.
Go to VOIP.ms set up a number for $1/mo. So 12/year. Have it forward to your number. Use it for verification as well. It supports SMS, though I have found some services won't allow it.
Which i control even less... I dont doubt there are solutions, but the only one i've seen so far that is kind of optimal is Github which allows me to disable lost 2fa access through verifying with a git push like command based on public/private key.
Re: Phone numbers are not proper verification
#18I do not have a mobile phone, and have run into countless issues with so-called security systems which demand a mobile number, everything from airports to online services like Twitter. It's amazing how many services become unavailable when you have no phone number to provide.
Re: Phone numbers are not proper verification
#19Earlier quoted context omitted.
Which i control even less... I dont doubt there are solutions, but the only one i've seen so far that is kind of optimal is Github which allows me to disable lost 2fa access through verifying with a git push like command based on public/private key.
I don't know what control means to you. You mean stuff that you don't have to pay for? Stuff that can't be taken away from you? I have had the same number with VOIP.ms for 5 years. Even used it from Mexico. It does not seem to me to be out of my control.
Re: Phone numbers are not proper verification
#20Earlier quoted context omitted.
E-mail is far from being perfect (you can get you account unilaterally closed by your provider or you can lose your domain name), but in practice I've been using the same address for more than a decade, and I have aliases that are meant to last forever (my almuni address), while in the same period I've had 5 different mobile numbers that I used for services like banking or IM, which is very inconvenient indeed.
I've had the same mobile number for the last fifteen years too. In NZ at least (not sure about other countries) it's trivial to take your number with you when you get a new SIM from any mobile provider. Though this wouldn't work across countries obviously.
At least 2 of them are now reused and given to other people.