Live data from Hacker News

Phone numbers are not proper verification

b1nary.ch

11–20 of 159 posts

Re: Phone numbers are not proper verification

#11

The same properties that make phone numbers bad also make email addresses, postal addresses and other IDs bad. Sometimes a weak option is better than no option at all.

E-mail is far from being perfect (you can get you account unilaterally closed by your provider or you can lose your domain name), but in practice I've been using the same address for more than a decade, and I have aliases that are meant to last forever (my almuni address), while in the same period I've had 5 different mobile numbers that I used for services like banking or IM, which is very inconvenient indeed.

I've had the same mobile number for the last fifteen years too. In NZ at least (not sure about other countries) it's trivial to take your number with you when you get a new SIM from any mobile provider. Though this wouldn't work across countries obviously.

Re: Phone numbers are not proper verification

#12
post #3

Google does let you have 2 factor setup without a phone number as a factor, but strangely you need a phone number temporarily. You add the phone number as a factor, then add other factors (such as Google Authenticator and Yubikeys) then delete the phone number.

> Google does let you have 2 factor setup without a phone number as a factor, but strangely you need a phone number temporarily. I finally set up 2FA on my Google account this weekend. It struck me as incredibly odd that Google requires a phone number to enable 2FA. NIST recently advocated against using SMS for OoB auth. [0] If I had been an account hijacker with the password (e.g. obtained via phishing) it would hav…

"My inner tin foil hat says Google wants a phone number for other purposes."

"I already have an Android phone with Google Play Services installed."

Guess what - Google already has your phone number before asking for it via the 2FA form. My guess is that the reason they have one platform-independent process for setting up 2FA is for iOS users.

Re: Phone numbers are not proper verification

#13
post #10

This rant is exactly why phone numbers are a good way to do two-factor. The author lost control of their phone number ("as i quit the account shortly...") and subsequently had an extremely hard time authenticating to their bank, Google, Twitter, etc. Getting a new phone number set up is time consuming, even with a Twilio-like service. This is a good thing. Your IMEI number isn't portable, and until there is a physica…

Author here. I dont have a fixed telephone number anymore. How to handle that? I dont see why i would need one except for authentification purposes ether. My point is that depending on people have a phone number, and even more one that is widely supported (which my current numbers are not) is simply wrong.

Sure i could call my bank one a month to change my telephone number, which i loose control of shortly after that (only valid for a few months, prepaid). This is hardly a solution.

On the other side i control my email address, my private key, my home address to a degree, but never my telephone number.

Re: Phone numbers are not proper verification

#14
post #13
post #10

This rant is exactly why phone numbers are a good way to do two-factor. The author lost control of their phone number ("as i quit the account shortly...") and subsequently had an extremely hard time authenticating to their bank, Google, Twitter, etc. Getting a new phone number set up is time consuming, even with a Twilio-like service. This is a good thing. Your IMEI number isn't portable, and until there is a physica…

Author here. I dont have a fixed telephone number anymore. How to handle that? I dont see why i would need one except for authentification purposes ether. My point is that depending on people have a phone number, and even more one that is widely supported (which my current numbers are not) is simply wrong. Sure i could call my bank one a month to change my telephone number, which i loose control of shortly after that…

Go to VOIP.ms set up a number for $1/mo. So 12/year. Have it forward to your number. Use it for verification as well. It supports SMS, though I have found some services won't allow it.

Re: Phone numbers are not proper verification

#15
post #9

Earlier quoted context omitted.

> Google does let you have 2 factor setup without a phone number as a factor, but strangely you need a phone number temporarily. I finally set up 2FA on my Google account this weekend. It struck me as incredibly odd that Google requires a phone number to enable 2FA. NIST recently advocated against using SMS for OoB auth. [0] If I had been an account hijacker with the password (e.g. obtained via phishing) it would hav…

> My inner tin foil hat says Google wants a phone number for other purposes. Just like Twitter these days. "Telephone number is optional and for your security". 2 minutes later my new accounts are always locked and i need to provide a telephone number to enable it again. They used SMS until recently, now they use a call service which only works with a fraction of numbers. (Tried 2 thai, 1 cambodian number, none accep…

Steam does this as well. Even if you add your phone number after a lot of nagging, Steam still keeps bothering you to install their Android or IOS authenticator software (even if you can't). I wish Steam would consider Fido U2F as well, but getting through to anyone who can influence this at Valve is nigh impossible.

It seems to be the industry status quo now to assume that everyone uses a smartphone running either Android or IOS, and that everyone wants to use that device for authentication. Meanwhile the tech giants (especially those involved in advertising) probably like having that nice unique alphanumerical identifier for your profile — it tends to be the same for all services you use.

I really hope Fido U2F becomes a de facto alternative for 2FA.

Re: Phone numbers are not proper verification

#16
post #14
post #13

Earlier quoted context omitted.

Author here. I dont have a fixed telephone number anymore. How to handle that? I dont see why i would need one except for authentification purposes ether. My point is that depending on people have a phone number, and even more one that is widely supported (which my current numbers are not) is simply wrong. Sure i could call my bank one a month to change my telephone number, which i loose control of shortly after that…

Go to VOIP.ms set up a number for $1/mo. So 12/year. Have it forward to your number. Use it for verification as well. It supports SMS, though I have found some services won't allow it.

Which i control even less... I dont doubt there are solutions, but the only one i've seen so far that is kind of optimal is Github which allows me to disable lost 2fa access through verifying with a git push like command based on public/private key.

Re: Phone numbers are not proper verification

#17
post #16
post #14

Earlier quoted context omitted.

Go to VOIP.ms set up a number for $1/mo. So 12/year. Have it forward to your number. Use it for verification as well. It supports SMS, though I have found some services won't allow it.

Which i control even less... I dont doubt there are solutions, but the only one i've seen so far that is kind of optimal is Github which allows me to disable lost 2fa access through verifying with a git push like command based on public/private key.

I don't know what control means to you. You mean stuff that you don't have to pay for? Stuff that can't be taken away from you? I have had the same number with VOIP.ms for 5 years. Even used it from Mexico. It does not seem to me to be out of my control.

Re: Phone numbers are not proper verification

#18
+1

I do not have a mobile phone, and have run into countless issues with so-called security systems which demand a mobile number, everything from airports to online services like Twitter. It's amazing how many services become unavailable when you have no phone number to provide.

Re: Phone numbers are not proper verification

#19
post #17
post #16

Earlier quoted context omitted.

Which i control even less... I dont doubt there are solutions, but the only one i've seen so far that is kind of optimal is Github which allows me to disable lost 2fa access through verifying with a git push like command based on public/private key.

I don't know what control means to you. You mean stuff that you don't have to pay for? Stuff that can't be taken away from you? I have had the same number with VOIP.ms for 5 years. Even used it from Mexico. It does not seem to me to be out of my control.

Control means i own it. You never own telephone numbers, maybe you do in some countries i dont know, but they usual contract is that you rent them and they can be taken away from you anytime. Sure they usually dont, but building a security system on something like that is obviously suboptimal.

Re: Phone numbers are not proper verification

#20
post #11

Earlier quoted context omitted.

E-mail is far from being perfect (you can get you account unilaterally closed by your provider or you can lose your domain name), but in practice I've been using the same address for more than a decade, and I have aliases that are meant to last forever (my almuni address), while in the same period I've had 5 different mobile numbers that I used for services like banking or IM, which is very inconvenient indeed.

I've had the same mobile number for the last fifteen years too. In NZ at least (not sure about other countries) it's trivial to take your number with you when you get a new SIM from any mobile provider. Though this wouldn't work across countries obviously.

And I have changed (lost) around 10. People and their behavioral patterns are drastically different. (ADD sucks).

At least 2 of them are now reused and given to other people.

Post reply on HN