Live data from Hacker News

Phone numbers are not proper verification

b1nary.ch

81–90 of 159 posts

Re: Phone numbers are not proper verification

#81
post #9

Earlier quoted context omitted.

> Google does let you have 2 factor setup without a phone number as a factor, but strangely you need a phone number temporarily. I finally set up 2FA on my Google account this weekend. It struck me as incredibly odd that Google requires a phone number to enable 2FA. NIST recently advocated against using SMS for OoB auth. [0] If I had been an account hijacker with the password (e.g. obtained via phishing) it would hav…

> My inner tin foil hat says Google wants a phone number for other purposes. Just like Twitter these days. "Telephone number is optional and for your security". 2 minutes later my new accounts are always locked and i need to provide a telephone number to enable it again. They used SMS until recently, now they use a call service which only works with a fraction of numbers. (Tried 2 thai, 1 cambodian number, none accep…

It's protection against bulk account creation. Getting a phone number costs money, so requiring a phone number makes it expensive to get 1000 accounts.

Phones are ubiquitous enough that very few customers have to pay this cost.

Obviously, this reasoning doesn't (and shouldn't) extend to using phones for authentication.

Re: Phone numbers are not proper verification

#82
post #35

Somewhat off-topic, but honest question: In the article the author says that he OWNs his email domains. Is this really possible? In my understanding it's more like you rent the domain name from the registrar, and you need to keep renewing it. My question is (please forgive my ignorance in this matter): what prevents the registrar from some day raising the price for your domain to astronomical values? Maybe some well-…

Author here, this is a valid thought indeed. My point rather was is that they can not take it away from me. My specific registrar only allows themself to invalidate domains for a few days when they contain swear words. I am not entirely sure if they can increase the price while i own it. In fact last time they increased the price it did not affect me because i already owned it but only new registered domains. Even th…

A registrar that invalidates domains just for having swear words is bounds beyond what is acceptable here in the west.

From your other posts, I gather you live in south-east asia, so I guess it's a local domain.

Re: Phone numbers are not proper verification

#83
post #31

Earlier quoted context omitted.

You can in most countries as far as i know. But in my example i quit my account (so made it prepaid essentially) and lost the SIM card, which means i lost my account forever. Now it waits for the simcard to invalidate and then will most likely sell the number again. It was a "easy number" (as in people remember that number after telling them once) so i assume it will be resold rather fast. But just because you can do…

You'd be surprised. Number portability is a big pain in the arse for us (determining the network from an MSISDN is important in my industry) so it's always a nice bonus when we come across countries without it. Most recently, Philippines: http://www.prefix.ph/smart-users/updated-philippine-mobile-p...

This is a really interesting example! Thank you, i obviously only thought about my rather small digitalnomad bubble & issues. But this is a good example for the same problem on a much bigger scale.

Once again it shows you cant just close your eyes and judge from yourself to others.

Re: Phone numbers are not proper verification

#84
post #82
post #35

Earlier quoted context omitted.

Author here, this is a valid thought indeed. My point rather was is that they can not take it away from me. My specific registrar only allows themself to invalidate domains for a few days when they contain swear words. I am not entirely sure if they can increase the price while i own it. In fact last time they increased the price it did not affect me because i already owned it but only new registered domains. Even th…

A registrar that invalidates domains just for having swear words is bounds beyond what is acceptable here in the west. From your other posts, I gather you live in south-east asia, so I guess it's a local domain.

My domain is actually .ch. I am not entirely sure how this goes, and i highly assume swear words are not what i actually ment. They just reserve their right to invalidate domains a few days in case they are inappropriate (i think that is the exact phrasing they use). This is also true for .eu, .de, .it, .li, .at but i doubt it happens often. Maybe it only refers to using registered trademarks? Dunno

I just tried to look it up. Seems it mostly happens for things like "Trademarksucks" which is afaik illegal (smearing or whatever the law is called) in most of europe.

Re: Phone numbers are not proper verification

#85
post #81
post #9

Earlier quoted context omitted.

> My inner tin foil hat says Google wants a phone number for other purposes. Just like Twitter these days. "Telephone number is optional and for your security". 2 minutes later my new accounts are always locked and i need to provide a telephone number to enable it again. They used SMS until recently, now they use a call service which only works with a fraction of numbers. (Tried 2 thai, 1 cambodian number, none accep…

It's protection against bulk account creation. Getting a phone number costs money, so requiring a phone number makes it expensive to get 1000 accounts. Phones are ubiquitous enough that very few customers have to pay this cost. Obviously, this reasoning doesn't (and shouldn't) extend to using phones for authentication.

Yeah, after writing the article i also realized i dont mind verification actually. As long as they support whatever carrier i currently have. Its authentification that i bother with. (As in i have a phone number, i want internet on my phone, but i change it often monthly)

Also services like Twitter that allow any rented SMS service and multiple accounts for each number this seems not be the reason why they ask for a number.

Re: Phone numbers are not proper verification

#86

As someone who changes phone numbers periodically, I couldn't agree more. The worst part is all the services who use it as the only identifier. Services like WhatsApp, Signal, etc should AT LEAST offer an alternative means of identification, be it a user-chosen handle or an email address.

Don't they use phone numbers exactly because they are hard to get/change.

A phone number, at least in the UK, means you've been pre-verified in some way - users can't in general generate new phone numbers like they can email addresses.

Thus, less problems with anonymous users (eg trolling, spamming) and less abuse from named users as they can usually be traced using the phone number.

Re: Phone numbers are not proper verification

#87
For one I like to opt out of phone based 2fa whenever possible. It is just inconvenient as demonstrated in the post without any upside really. Most of the time it actually prevents me from doing things. Lose/forget your phone and you are in a very bad position. I'm satisfied with a secure password, thanks.

Re: Phone numbers are not proper verification

#88
post #3

Google does let you have 2 factor setup without a phone number as a factor, but strangely you need a phone number temporarily. You add the phone number as a factor, then add other factors (such as Google Authenticator and Yubikeys) then delete the phone number.

Can you even create a working Google account without a phone number? When I last tried that, it seemed to be mandatory from the start.

It never seemed to be a security measure, but an anti-spam measure. You can buy captcha solving as a service for fractions of a cent, and bulk create thousands of accounts for sending spam. Buying working phone numbers is more hassle and more expensive, and will leave a payment trail if you use a service like Twilio.

Re: Phone numbers are not proper verification

#89
post #87

For one I like to opt out of phone based 2fa whenever possible. It is just inconvenient as demonstrated in the post without any upside really. Most of the time it actually prevents me from doing things. Lose/forget your phone and you are in a very bad position. I'm satisfied with a secure password, thanks.

In most cases i totally agree. Some places enforce it tho :/

Re: Phone numbers are not proper verification

#90

I know life can be frustrating when you don't fit the conventional profile. It's been the same for me. But organisations like banks need to have systems that adequately balance security, usability and ubiquity, and it turns out that phone number authentication is optimal across those criteria. Of course it's not perfect, but empirically it works better than the alternatives (otherwise they'd already have changed it),…

But the OP does have a point that you don't own the phone number your countries PTT or Regulator does.

And for google if you have multiple people using the same google accounts which you would do for many google services 2FA can really mess you up eg if I WFH I cant login to some of our GA GTM and GSC accounts.

Post reply on HN