Live data from Hacker News

Phone numbers are not proper verification

b1nary.ch

91–100 of 159 posts

Re: Phone numbers are not proper verification

#91
post #13
post #10

This rant is exactly why phone numbers are a good way to do two-factor. The author lost control of their phone number ("as i quit the account shortly...") and subsequently had an extremely hard time authenticating to their bank, Google, Twitter, etc. Getting a new phone number set up is time consuming, even with a Twilio-like service. This is a good thing. Your IMEI number isn't portable, and until there is a physica…

Author here. I dont have a fixed telephone number anymore. How to handle that? I dont see why i would need one except for authentification purposes ether. My point is that depending on people have a phone number, and even more one that is widely supported (which my current numbers are not) is simply wrong. Sure i could call my bank one a month to change my telephone number, which i loose control of shortly after that…

> My point is that depending on people have a phone number, and even more one that is widely supported (which my current numbers are not) is simply wrong.

Maybe the bank is not interested in serving people like you - and why should they be? A bank needs to be able to loan money to fulfil its function - everything else they do is about enabling the loan business. To be able to make loans they need to be able to have some hope of being repaid, so they need a reliable way of contacting someone tied to that person's identity and expensive to mess with. Emails are ignorable and untraceable. Home address fulfils those functions but isn't really practical as a sole means of contact - would you like them to place suspicions transactions on hold while they send you a letter and wait for your reply?

Re: Phone numbers are not proper verification

#92
FTA:

> A phone number is nothing you can just keep. Also i OWN my emails domains. Therefore they are under MY control.

No, no, no.

Just like phone numbers, your domain can be yanked out from under you. In many cases, their are procedures and appeals that can be worked out but realistically, if someone hijacks your DNS, it's over.

Re: Phone numbers are not proper verification

#93
post #91
post #13

Earlier quoted context omitted.

Author here. I dont have a fixed telephone number anymore. How to handle that? I dont see why i would need one except for authentification purposes ether. My point is that depending on people have a phone number, and even more one that is widely supported (which my current numbers are not) is simply wrong. Sure i could call my bank one a month to change my telephone number, which i loose control of shortly after that…

> My point is that depending on people have a phone number, and even more one that is widely supported (which my current numbers are not) is simply wrong. Maybe the bank is not interested in serving people like you - and why should they be? A bank needs to be able to loan money to fulfil its function - everything else they do is about enabling the loan business. To be able to make loans they need to be able to have s…

As mentioned in some other comment my bank was a bad point, i see why its more relevant for banking. While one of my banks is perfectly happy with what i am doing and offers me paper TANs and contacts me via letters the other isnt.

I am more about everything else than banking tho. Things that dont have the need to contact me ASAP and still use SMS for authentification purposes. (Personally i dont even mind verification, i have a number, just not for long)

Re: Phone numbers are not proper verification

#94
post #53

Earlier quoted context omitted.

In 2008 I moved to Japan from The Netherlands for a year as a graduate student. I didn't want to bother with my Dutch phone number there, so I looked for alternatives. My bank uses one time codes that are normally sent to you via SMS when you perform a transaction. These can also be pregenerated and sent to you via mail. The online banking environment simply asks me to enter code number x . I never changed back, so n…

Here in Germany we get a Digipass 2FA device from our bank (something like this [0]). For every transaction, you put your banking card in, hold it up to the flashing pattern on the screen, and it creates a TAN for you. Very convenient and secure. I thought this is more common in Europe, but apparently it's not? Although, our banks are increasingly pushing towards App-based 2FA because it's cheaper.. but I'm very conf…

> I thought this is more common in Europe, but apparently it's not?

It is. Most of the other Dutch banks do use such a device (I haven't seen devices that try to read your screen yet though).

Re: Phone numbers are not proper verification

#95

I know life can be frustrating when you don't fit the conventional profile. It's been the same for me. But organisations like banks need to have systems that adequately balance security, usability and ubiquity, and it turns out that phone number authentication is optimal across those criteria. Of course it's not perfect, but empirically it works better than the alternatives (otherwise they'd already have changed it),…

> otherwise they'd already have changed it

Do you really believe that? I was just reading someone comment's on Reddit yesterday about him working for a bank that only recently stopped working with credit card number transfers in the clear...

Some if not most of the banks just use ancient technology for the same reason most other big corporations do - they don't really "get" the security "value" so they don't bother to invest hundreds of millions of dollars in new infrastructure.

Re: Phone numbers are not proper verification

#96
post #79

I never get these rants. You want me to take something that works well for 100% (Your case is less than a rounding error), and introduce security weaknesses for you? You've decided to be a non-conformist, and then want the 100% to conform to you. Sorry, but no.

Like your name. Its a rant, thats what they are for, arent they? And no, i am pointing at a growing problem. Since i move within a "digitalnomad" scene i noticed this is a common topic and there are millions of suboptimal solutions to scope around it. I am surely not alone, maybe not 1% yet but remote work is growing VERY fast. Also i dont want anything to be 100% comform to me. No idea where you got this from. I am…

Sorry, you're absolutely right, and you should express this. My day job, I just fight with people who want to do things like this, but with no clue as to the costs and the alternatives that would need to be implemented. But somebody will figure it out, either writing a rant, or maybe reading one, and get an idea... So we should have this, but at this point, margins are so low that we need to start ignoring niches that are less than single digit percents. And it looks like things are about to get tighter.

Re: Phone numbers are not proper verification

#97
post #53

Earlier quoted context omitted.

In 2008 I moved to Japan from The Netherlands for a year as a graduate student. I didn't want to bother with my Dutch phone number there, so I looked for alternatives. My bank uses one time codes that are normally sent to you via SMS when you perform a transaction. These can also be pregenerated and sent to you via mail. The online banking environment simply asks me to enter code number x . I never changed back, so n…

Here in Germany we get a Digipass 2FA device from our bank (something like this [0]). For every transaction, you put your banking card in, hold it up to the flashing pattern on the screen, and it creates a TAN for you. Very convenient and secure. I thought this is more common in Europe, but apparently it's not? Although, our banks are increasingly pushing towards App-based 2FA because it's cheaper.. but I'm very conf…

UK here, quite a few banks have used calculator style[0] devices for 2FA. You insert your chip card, enter the PIN and receive a code. The devices themselves, while branded, seem identical across banks and accounts (I can use one I got from bank A for bank B and vice versa).

Banks now have introduced app based versions of the above, useful if you've not got the calculator or your card handy, but I don't believe they're looking to phase out the physical device just yet.

Seems similar to your device, but instead of an optical sensor to receive a code from the web browser you enter the account code and money amount of a transfer manually.

[0]: https://upload.wikimedia.org/wikipedia/commons/thumb/0/05/Ba...

Re: Phone numbers are not proper verification

#98
post #95

I know life can be frustrating when you don't fit the conventional profile. It's been the same for me. But organisations like banks need to have systems that adequately balance security, usability and ubiquity, and it turns out that phone number authentication is optimal across those criteria. Of course it's not perfect, but empirically it works better than the alternatives (otherwise they'd already have changed it),…

> otherwise they'd already have changed it Do you really believe that? I was just reading someone comment's on Reddit yesterday about him working for a bank that only recently stopped working with credit card number transfers in the clear... Some if not most of the banks just use ancient technology for the same reason most other big corporations do - they don't really "get" the security "value" so they don't bother t…

I'm also old enough to realise that patterns of conduct across global industries like this, don't emerge for purely dumb reasons.

"Don't bother to invest" could be a cynical way of saying they can't justify the financial cost, personnel commitment, organisational upheaval and multi-dimensional risk to adopt the new infrastructure.

But it's not as if they're sitting around doing nothing; all the banks have vast teams of people constantly maintaining and improving their software and infrastructure, doing whatever is necessary to minimise losses and maximise gains.

Those who don't do it enough or do it right go out of business.

Re: Phone numbers are not proper verification

#99

As someone who changes phone numbers periodically, I couldn't agree more. The worst part is all the services who use it as the only identifier. Services like WhatsApp, Signal, etc should AT LEAST offer an alternative means of identification, be it a user-chosen handle or an email address.

Don't they use phone numbers exactly because they are hard to get/change. A phone number, at least in the UK, means you've been pre-verified in some way - users can't in general generate new phone numbers like they can email addresses. Thus, less problems with anonymous users (eg trolling, spamming) and less abuse from named users as they can usually be traced using the phone number.

[deleted]

Re: Phone numbers are not proper verification

#100
post #79

Earlier quoted context omitted.

Like your name. Its a rant, thats what they are for, arent they? And no, i am pointing at a growing problem. Since i move within a "digitalnomad" scene i noticed this is a common topic and there are millions of suboptimal solutions to scope around it. I am surely not alone, maybe not 1% yet but remote work is growing VERY fast. Also i dont want anything to be 100% comform to me. No idea where you got this from. I am…

Sorry, you're absolutely right, and you should express this. My day job, I just fight with people who want to do things like this, but with no clue as to the costs and the alternatives that would need to be implemented. But somebody will figure it out, either writing a rant, or maybe reading one, and get an idea... So we should have this, but at this point, margins are so low that we need to start ignoring niches tha…

I see where you are coming from no worries.
Post reply on HN