Live data from Hacker News

Phone numbers are not proper verification

b1nary.ch

71–80 of 159 posts

Re: Phone numbers are not proper verification

#71
post #60

Earlier quoted context omitted.

Yeah, that can happen, it's one of the reasons why I don't recommend Google accounts anymore. Hardware/software factors ("new devices"...) trigger their automatic security checks and can easily lock you out of your account, even if you did nothing wrong. Big providers are more and more tailoring to the lowest common denominator (people who can't manage passwords, get malware...) and pushing for mobile authentication.…

Are you using long, automatically generated passwords? I've had two very similar Google accounts that I log in at the same time on PCs, and one account with a 15 char password kept wanting additional checks. It stopped when I changed the password to 16 chars.

Over 16 chars, not auto generated.

Re: Phone numbers are not proper verification

#72
post #60

I've got an odd issue with a Google mail account. That has no email or phone number associated with it. On my main laptop, I can access the account with username and password, on another computer, I'm locked out - because of security checks. The credentials don't matter. Which really bothers me. I'm effectively locked out the account. I don't really care for a telephone either.

Yeah, that can happen, it's one of the reasons why I don't recommend Google accounts anymore. Hardware/software factors ("new devices"...) trigger their automatic security checks and can easily lock you out of your account, even if you did nothing wrong. Big providers are more and more tailoring to the lowest common denominator (people who can't manage passwords, get malware...) and pushing for mobile authentication.…

I agree its stupid, but it personally gives me a good feel about their security as well. I rather trust my gmail account than my phone.

The "trick" is to never change your laptop/desktop and phone at once so you can always verify the other. At best, if you travel, have a old computer somewhere that someone else can access to verify when needed.

Its not perfect, and i still have bad dreams about loosing access and no googler ever going to help me. But on the other side when someone accesses my account somehow, i know nothing happens and they get locked out.

I move country and change internet regularly, and i am glad this is not a reason to lock my account like with many providers who have less advanced tactics.

Re: Phone numbers are not proper verification

#73

I've got an odd issue with a Google mail account. That has no email or phone number associated with it. On my main laptop, I can access the account with username and password, on another computer, I'm locked out - because of security checks. The credentials don't matter. Which really bothers me. I'm effectively locked out the account. I don't really care for a telephone either.

Can't you just add an email?

It kind of defeats the point. It all gets chicken and egg. I've some accounts that I want totally and utterly divorced from each other.

Re: Phone numbers are not proper verification

#74
post #12

Earlier quoted context omitted.

> Google does let you have 2 factor setup without a phone number as a factor, but strangely you need a phone number temporarily. I finally set up 2FA on my Google account this weekend. It struck me as incredibly odd that Google requires a phone number to enable 2FA. NIST recently advocated against using SMS for OoB auth. [0] If I had been an account hijacker with the password (e.g. obtained via phishing) it would hav…

"My inner tin foil hat says Google wants a phone number for other purposes." "I already have an Android phone with Google Play Services installed." Guess what - Google already has your phone number before asking for it via the 2FA form. My guess is that the reason they have one platform-independent process for setting up 2FA is for iOS users.

> Guess what - Google already has your phone number before asking for it via the 2FA form. My guess is that the reason they have one platform-independent process for setting up 2FA is for iOS users.

Only if the phone number is the same one I use for my Android phone. But yes, I realize that any SIM I put into my phone will also be known by Google.

It's just an incredibly shit onboarding method. They already have a more secure way than SMS to determine the account owner, so why not offer it as an option?

Re: Phone numbers are not proper verification

#75
As someone who changes phone numbers periodically, I couldn't agree more. The worst part is all the services who use it as the only identifier. Services like WhatsApp, Signal, etc should AT LEAST offer an alternative means of identification, be it a user-chosen handle or an email address.

Re: Phone numbers are not proper verification

#76
This hits me too because I travel a lot. Try installing Signal on your phone when your only connection to the world is over WiFi. Try getting an SMS when you're not on a compatible network. You can't. That doesn't mean I don't have my phone with me. The requirement for a contactable phone number instead of an email address or other message is like pretending that your IP address and your hardware MAC address are the same thing, when they're obviously not. One identifies an actual piece of equipment, and the other is literally just bits on the wind.

Re: Phone numbers are not proper verification

#77
post #31

In the UK mobile networks are required to offer number portability[1]. I don't know if that means a mobile network can take your number away, but just like managing the registrar on a domain, you can manage the portability of your number. [1] https://www.ofcom.org.uk/phones-telecoms-and-internet/inform...

You can in most countries as far as i know. But in my example i quit my account (so made it prepaid essentially) and lost the SIM card, which means i lost my account forever. Now it waits for the simcard to invalidate and then will most likely sell the number again. It was a "easy number" (as in people remember that number after telling them once) so i assume it will be resold rather fast. But just because you can do…

You'd be surprised. Number portability is a big pain in the arse for us (determining the network from an MSISDN is important in my industry) so it's always a nice bonus when we come across countries without it.

Most recently, Philippines: http://www.prefix.ph/smart-users/updated-philippine-mobile-p...

Re: Phone numbers are not proper verification

#79

I never get these rants. You want me to take something that works well for 100% (Your case is less than a rounding error), and introduce security weaknesses for you? You've decided to be a non-conformist, and then want the 100% to conform to you. Sorry, but no.

Like your name. Its a rant, thats what they are for, arent they? And no, i am pointing at a growing problem. Since i move within a "digitalnomad" scene i noticed this is a common topic and there are millions of suboptimal solutions to scope around it. I am surely not alone, maybe not 1% yet but remote work is growing VERY fast.

Also i dont want anything to be 100% comform to me. No idea where you got this from. I am really just trying to put some light on a issue i see. All i actually expect is having people think about this issue and if possible offer solutions if not offer a workflow to not make this a complete pain.

Post reply on HN