Live data from Hacker News

Phone numbers are not proper verification

b1nary.ch

51–60 of 159 posts

Re: Phone numbers are not proper verification

#51
post #11

Earlier quoted context omitted.

E-mail is far from being perfect (you can get you account unilaterally closed by your provider or you can lose your domain name), but in practice I've been using the same address for more than a decade, and I have aliases that are meant to last forever (my almuni address), while in the same period I've had 5 different mobile numbers that I used for services like banking or IM, which is very inconvenient indeed.

I've had the same mobile number for the last fifteen years too. In NZ at least (not sure about other countries) it's trivial to take your number with you when you get a new SIM from any mobile provider. Though this wouldn't work across countries obviously.

As a developer in Europe, moving across countries isn't a particularly crazy pattern I believe :)

Also in some countries keeping your number isn't cheap. And even when it's technically easy, your phone plan might be provided by your employer, in this case it might be very tricky to get your number migrated when you change jobs.

Re: Phone numbers are not proper verification

#52

I know life can be frustrating when you don't fit the conventional profile. It's been the same for me. But organisations like banks need to have systems that adequately balance security, usability and ubiquity, and it turns out that phone number authentication is optimal across those criteria. Of course it's not perfect, but empirically it works better than the alternatives (otherwise they'd already have changed it),…

I shouldnt have mentioned banking, it seems that this is what most people agree with that numbers make sense. And hence i agree to that as well.

One of my banks offers the following 2 alternatives:

* Paper TAN (which most likely will go away in the next years)

* Card reader that scans your EC card

Both completely valid for my situation, my other bank does none of both. Both however are completely valid just not as confidient for the bank i guess.

My whole point is having alternatives, or at least a workflow to fix this issue for people who do not have a fixed phone number (anymore). Its sucks to have way less security as everybody else (because i cant enable 2FA) when email was always there and pretty much just as good. It sucks even more to not be able to create a account because somehow they dont want your current number (I mean how crazy is that that you can not make a Twitter account with one of the most popular Thai providers? How is that not a huge issue?)

Re: Phone numbers are not proper verification

#53
post #13

Earlier quoted context omitted.

Author here. I dont have a fixed telephone number anymore. How to handle that? I dont see why i would need one except for authentification purposes ether. My point is that depending on people have a phone number, and even more one that is widely supported (which my current numbers are not) is simply wrong. Sure i could call my bank one a month to change my telephone number, which i loose control of shortly after that…

In 2008 I moved to Japan from The Netherlands for a year as a graduate student. I didn't want to bother with my Dutch phone number there, so I looked for alternatives. My bank uses one time codes that are normally sent to you via SMS when you perform a transaction. These can also be pregenerated and sent to you via mail. The online banking environment simply asks me to enter code number x . I never changed back, so n…

Here in Germany we get a Digipass 2FA device from our bank (something like this [0]). For every transaction, you put your banking card in, hold it up to the flashing pattern on the screen, and it creates a TAN for you. Very convenient and secure.

I thought this is more common in Europe, but apparently it's not? Although, our banks are increasingly pushing towards App-based 2FA because it's cheaper.. but I'm very confident they'll continue to support as it is the common way to do online banking.

0: https://www.vasco.com/products/two-factor-authenticators/har...

Re: Phone numbers are not proper verification

#54
post #43

Earlier quoted context omitted.

Interesting conclusion and now i am curious what the police/visa offices do with people without fingers. Most likely they offer a alternative, which is all i am ranting for here. If i choose to have "less" security by using email (in fact its more, but thats a different topic) it should be my choice. I should not be forced to own a fixed telephone number, especially for services that just dont know any better. I shou…

If people had the choice of not using a mobile phone when creating and account, 1) recovering lost accounts would be much harder (and that's actual support, it costs them money, so they want to avoid it) and 2) fighting spam would also be harder (everybody gets to create an account and send mail with it? Wow, that's really going to cost them money!) Anyway there are mail providers who won't ask you for a mail. Proton…

Valid arguments indeed. Many roll well with not allowing common mail providers (there are available lists) and as i own my own domains i welcome that.

If they require telephone number i would at least expect them to support a wide range of providers and not only some. Like i really cant get over the fact that Twitter locks out the most popular Thai provider.

They however could also send me a letter, or have me auth with Authy/Google Auth to make a single identity system. Maybe even requiring my passport number + name. Its not like phone would be the only solution.

And yeah i see that may is hard for small providers, but it shouldnt be hard for bigger ones. Or like in Twitters case, its not about having a single account anyway, you can have hundreds with the same phone number, but not a single with a thai phone carrier.

Edit:// To clearify i personally have no issue with initial confirmation over SMS, i mean i own a phone number most of the time. I just not own it for longer than a month, so it is not valid for me for further authentication.

Re: Phone numbers are not proper verification

#55
post #52

I know life can be frustrating when you don't fit the conventional profile. It's been the same for me. But organisations like banks need to have systems that adequately balance security, usability and ubiquity, and it turns out that phone number authentication is optimal across those criteria. Of course it's not perfect, but empirically it works better than the alternatives (otherwise they'd already have changed it),…

I shouldnt have mentioned banking, it seems that this is what most people agree with that numbers make sense. And hence i agree to that as well. One of my banks offers the following 2 alternatives: * Paper TAN (which most likely will go away in the next years) * Card reader that scans your EC card Both completely valid for my situation, my other bank does none of both. Both however are completely valid just not as co…

Yeah, I get what you're saying.

But for every new system/feature/mechanism a service provider builds to accommodate every increasingly narrow edge-case, there's a huge additional cost and commitment in development, maintenance and support.

So the reality is it just comes down to dollars. If you're in the mainstream, you'll be looked after. If you're in the fringes, well, you're in the situation you're in now. That's how the world works.

Whilst complaining might help you to feel better, it's not going to change much unless there are big dollars at stake for the service provider.

Re: Phone numbers are not proper verification

#57
post #54

Earlier quoted context omitted.

If people had the choice of not using a mobile phone when creating and account, 1) recovering lost accounts would be much harder (and that's actual support, it costs them money, so they want to avoid it) and 2) fighting spam would also be harder (everybody gets to create an account and send mail with it? Wow, that's really going to cost them money!) Anyway there are mail providers who won't ask you for a mail. Proton…

Valid arguments indeed. Many roll well with not allowing common mail providers (there are available lists) and as i own my own domains i welcome that. If they require telephone number i would at least expect them to support a wide range of providers and not only some. Like i really cant get over the fact that Twitter locks out the most popular Thai provider. They however could also send me a letter, or have me auth w…

You live in Switzerland. If you can create a phone number with a Thai carrier from there, I am sure you understand why Twitter refuses to deal with such a carrier.

Re: Phone numbers are not proper verification

#58
post #53

Earlier quoted context omitted.

In 2008 I moved to Japan from The Netherlands for a year as a graduate student. I didn't want to bother with my Dutch phone number there, so I looked for alternatives. My bank uses one time codes that are normally sent to you via SMS when you perform a transaction. These can also be pregenerated and sent to you via mail. The online banking environment simply asks me to enter code number x . I never changed back, so n…

Here in Germany we get a Digipass 2FA device from our bank (something like this [0]). For every transaction, you put your banking card in, hold it up to the flashing pattern on the screen, and it creates a TAN for you. Very convenient and secure. I thought this is more common in Europe, but apparently it's not? Although, our banks are increasingly pushing towards App-based 2FA because it's cheaper.. but I'm very conf…

One of my banks does this, paper TAN is more confident for me as i dont have to carry a additional device and worry about driver support. But i surely will change to that as soon paper tan is over.

The other bank only offers different phone based solutions. Clearly my fault for not checking first, and also not a issue for me as i dont actually access that account.

If i could use that with other websites, Twitter, Github, whatever, i would happily carry that device with me :)

Re: Phone numbers are not proper verification

#59
post #13

Earlier quoted context omitted.

Author here. I dont have a fixed telephone number anymore. How to handle that? I dont see why i would need one except for authentification purposes ether. My point is that depending on people have a phone number, and even more one that is widely supported (which my current numbers are not) is simply wrong. Sure i could call my bank one a month to change my telephone number, which i loose control of shortly after that…

In 2008 I moved to Japan from The Netherlands for a year as a graduate student. I didn't want to bother with my Dutch phone number there, so I looked for alternatives. My bank uses one time codes that are normally sent to you via SMS when you perform a transaction. These can also be pregenerated and sent to you via mail. The online banking environment simply asks me to enter code number x . I never changed back, so n…

The ING smartphone app can now also be used to approve payments (https://www.ing.nl/particulier/mobiel-en-internetbankieren/i...), but that doesn't exactly remove the phone dependency.

Re: Phone numbers are not proper verification

#60

I've got an odd issue with a Google mail account. That has no email or phone number associated with it. On my main laptop, I can access the account with username and password, on another computer, I'm locked out - because of security checks. The credentials don't matter. Which really bothers me. I'm effectively locked out the account. I don't really care for a telephone either.

Yeah, that can happen, it's one of the reasons why I don't recommend Google accounts anymore. Hardware/software factors ("new devices"...) trigger their automatic security checks and can easily lock you out of your account, even if you did nothing wrong.

Big providers are more and more tailoring to the lowest common denominator (people who can't manage passwords, get malware...) and pushing for mobile authentication. So if you're someone who can manage passwords and is willing to accept responsibility, you get annoyed at best and locked out of your account at worst.

Post reply on HN