Live data from Hacker News

Phone numbers are not proper verification

b1nary.ch

101–110 of 159 posts

Re: Phone numbers are not proper verification

#101
The solution to protect against loss is to have a backup. Keep a backup SIM from your home country (or for every country in which you have an important account), so in case of loss you can switch over to your backup and you can avoid this fuckery. In my experience it's not hard to keep a prepaid SIM active, even if it's not in active use.

This advice also applies to your wallet too: have a second bank account (at least) and second set of credit cards (with different institutions) in a second wallet. If you lose your primary wallet, you can immediately switch over to your backup.

Re: Phone numbers are not proper verification

#103

I know life can be frustrating when you don't fit the conventional profile. It's been the same for me. But organisations like banks need to have systems that adequately balance security, usability and ubiquity, and it turns out that phone number authentication is optimal across those criteria. Of course it's not perfect, but empirically it works better than the alternatives (otherwise they'd already have changed it),…

But the OP does have a point that you don't own the phone number your countries PTT or Regulator does. And for google if you have multiple people using the same google accounts which you would do for many google services 2FA can really mess you up eg if I WFH I cant login to some of our GA GTM and GSC accounts.

The vast majority of people keep the same phone number for a long period of time; at least a few years in most cases, and several decades in some cases.

The telephony system relies on that being the case, which is why it has the nice byproduct of being an identity verification channel for banks and other service providers.

So it doesn't matter who strictly 'owns' the phone number. What matters is that it can be relied on to be linked to a given person over an extended period of time, which it usually is, which is why the system usually works. And when it doesn't work, a fallback process is available, which makes the system work even better. So all's good!

It's easy to point out ways in which the system fails in all kinds of scenarios where people don't/can't fit in with the way the system is designed, but it's ultimately futile.

Service providers will run their system in whatever way is secure enough and usable enough for enough of their customers to be satisfied to stay as customers. There's really nothing more to say about it!

Re: Phone numbers are not proper verification

#104

As someone who changes phone numbers periodically, I couldn't agree more. The worst part is all the services who use it as the only identifier. Services like WhatsApp, Signal, etc should AT LEAST offer an alternative means of identification, be it a user-chosen handle or an email address.

Don't they use phone numbers exactly because they are hard to get/change. A phone number, at least in the UK, means you've been pre-verified in some way - users can't in general generate new phone numbers like they can email addresses. Thus, less problems with anonymous users (eg trolling, spamming) and less abuse from named users as they can usually be traced using the phone number.

I travel a lot and in many countries a prepaid SIM (which will expire after as little as a month without use or top-up) is the cheapest way to go.

Most countries are moving towards requiring identification before activating a SIM card, like you say.

For example in Vietnam, this has only become a thing in the past month or so and it is not enforced in practice in many unaffiliated corner stores. Last month, I just walked into a corner store paid a couple of bucks to get a preactivated SIM card with a couple of GB in two minutes.

Re: Phone numbers are not proper verification

#105
"A phone number is nothing you can just keep. Also i OWN my emails domains."

I don't get the distinction the author is trying to make: if you stop paying the renewal fees for them you'll find you "own" those domains exactly as much as you "own" a phone number.

Re: Phone numbers are not proper verification

#106
post #19
post #17

Earlier quoted context omitted.

I don't know what control means to you. You mean stuff that you don't have to pay for? Stuff that can't be taken away from you? I have had the same number with VOIP.ms for 5 years. Even used it from Mexico. It does not seem to me to be out of my control.

Control means i own it. You never own telephone numbers, maybe you do in some countries i dont know, but they usual contract is that you rent them and they can be taken away from you anytime. Sure they usually dont, but building a security system on something like that is obviously suboptimal.

Not sure I understand the difference between renting a telephone number and renting a domain, or email address, or even a home address. All can be taken away for various reasons, failure to pay rent/renewal/mortgage, legal confiscations, etc.

Re: Phone numbers are not proper verification

#107
post #91
post #13

Earlier quoted context omitted.

Author here. I dont have a fixed telephone number anymore. How to handle that? I dont see why i would need one except for authentification purposes ether. My point is that depending on people have a phone number, and even more one that is widely supported (which my current numbers are not) is simply wrong. Sure i could call my bank one a month to change my telephone number, which i loose control of shortly after that…

> My point is that depending on people have a phone number, and even more one that is widely supported (which my current numbers are not) is simply wrong. Maybe the bank is not interested in serving people like you - and why should they be? A bank needs to be able to loan money to fulfil its function - everything else they do is about enabling the loan business. To be able to make loans they need to be able to have s…

My bank emails me about suspicious transactions.

There's a link for if I authorized it and a link for if I didnt.

In fact, basically everything my bank does is by email, except a few legal documents amd sending replacement cards, which are by mail.

I cant count the number of times they called me on a single hand.

Re: Phone numbers are not proper verification

#109

As someone who changes phone numbers periodically, I couldn't agree more. The worst part is all the services who use it as the only identifier. Services like WhatsApp, Signal, etc should AT LEAST offer an alternative means of identification, be it a user-chosen handle or an email address.

Don't they use phone numbers exactly because they are hard to get/change. A phone number, at least in the UK, means you've been pre-verified in some way - users can't in general generate new phone numbers like they can email addresses. Thus, less problems with anonymous users (eg trolling, spamming) and less abuse from named users as they can usually be traced using the phone number.

>A phone number, at least in the UK, means you've been pre-verified in some way

This seemed interesting to me, so I tried signing up for a UK voip number at the sipgate.co.uk site. They do ask for an address, but they accept anything valid, like the address of a university. Had a 056-0003 XXXX phone number in less than a minute.

Re: Phone numbers are not proper verification

#110
post #106
post #19

Earlier quoted context omitted.

Control means i own it. You never own telephone numbers, maybe you do in some countries i dont know, but they usual contract is that you rent them and they can be taken away from you anytime. Sure they usually dont, but building a security system on something like that is obviously suboptimal.

Not sure I understand the difference between renting a telephone number and renting a domain, or email address, or even a home address. All can be taken away for various reasons, failure to pay rent/renewal/mortgage, legal confiscations, etc.

As far as I can tell, it's just a whine services don't let you use a preferred rented identity listing (that is arguably less tied to the real world).

There's not a lot of genuine security or legal analysis to be found here.

Post reply on HN