Live data from Hacker News

Twitter forces all new users to enter a valid phone number

sucky.ninja

121–130 of 393 posts

Re: Twitter forces all new users to enter a valid phone number

#121
post #114

We're going this way as well (requiring & verifying phone numbers, not locking accounts). We don't have a problem with bots, but users in the "not so tech savvy" segment tend to switch/discard/forget their email address. Rather than try to recover their account with us, this group will subsequently just create a new one, and then wonder & complain that their profiles/settings/content/histories aren't carried over. We…

> Turns out that phone numbers, whilst also subject to flux, have better long-term congruence to identity, and thereby help us to detect account duplication and manage it. What service do you offer? Because I would never give a company where I wasn't paying for the service my phone number. How do you guarantee you won't misuse it or have ample protections in case of a breach?

We're a two-sided network for sports competition management and work with athletes, clubs, associations, and governing bodies. Users pay real money for our services, we don't carry ads or even tracking pixels, and our privacy policy details exactly how, when and to whom PII is disclosed.

The broader point is that collection of phone number isn't intrinsically a bad thing, it's rather the usage and trust level that matters. Judging by the parameters and caveats in your question, you have a similar perspective.

Re: Twitter forces all new users to enter a valid phone number

#124

We're going this way as well (requiring & verifying phone numbers, not locking accounts). We don't have a problem with bots, but users in the "not so tech savvy" segment tend to switch/discard/forget their email address. Rather than try to recover their account with us, this group will subsequently just create a new one, and then wonder & complain that their profiles/settings/content/histories aren't carried over. We…

> Turns out that phone numbers, whilst also subject to flux, have better long-term congruence to identity

Exactly why using verified phone numbers endangers a user's data. A phone number is much closer to a their true identity than an email address, exposing disparate system data to be cross-referenced by breaches and malicious actors.

For this very reason it's illegal in Australia to use a person's government uuid (Tax File Number) as a username.

I'm sure the unwashed masses don't care right now, but the recent kerfuffle over Facebook's sneaky 2FA switcheroo and other privacy sins shows that they might care after enough scandals.

Re: Twitter forces all new users to enter a valid phone number

#125

Earlier quoted context omitted.

I think you know what I mean.

Maybe I don't? Because that's what I thought you meant. I thought you meant Twitter is trying to put the squeeze on the spammers and propaganda ministers because they will lose advertisers if they can't? Did you mean something else?

Did you read the link to the EFF page I added to the post? Why should Twitter be considered any more trustworthy than Facebook when they ask me for something they don't need to know?

They can avoid being victimized by spam and propaganda some other way... preferably some other way that I couldn't trivially defeat by giving them the number of a throwaway SIM card or a public phone booth.

Re: Twitter forces all new users to enter a valid phone number

#126
post #124

We're going this way as well (requiring & verifying phone numbers, not locking accounts). We don't have a problem with bots, but users in the "not so tech savvy" segment tend to switch/discard/forget their email address. Rather than try to recover their account with us, this group will subsequently just create a new one, and then wonder & complain that their profiles/settings/content/histories aren't carried over. We…

> Turns out that phone numbers, whilst also subject to flux, have better long-term congruence to identity Exactly why using verified phone numbers endangers a user's data. A phone number is much closer to a their true identity than an email address, exposing disparate system data to be cross-referenced by breaches and malicious actors. For this very reason it's illegal in Australia to use a person's government uuid (…

[deleted]

Re: Twitter forces all new users to enter a valid phone number

#127
post #86

Linking pseudonyms from two different networks (in this case, Twitter and the phone system) together is a classic and serious privacy leak. It's far from clear exactly what information Twitter, in its longtime effort to combat spam, has already collected on its users. Throwing a phone number into the mix expands to range of activities that can be unambiguously tied to the same individual. Given that Twitter certainly…

Twitter knows what IP you connect from, which might easily be through a VPN. The flip side of low-friction authentication is epidemic abuse by trolls, which arguably damages Twitter's brand.

Unfortunately, most people simply don't understand the implications of any of this.

Well, so you say.

Re: Twitter forces all new users to enter a valid phone number

#128
post #23
post #18

Earlier quoted context omitted.

MAU (monthly active users) is typically the metric they look at.

Twitter specifically said they will no longer share their MAU numbers and will only report "monetizable daily active users" going forward: https://www.recode.net/2019/2/7/18215204/twitter-daily-activ...

thats rad. cant imagine an advertiser doing legitimate spend justification on mau.

Re: Twitter forces all new users to enter a valid phone number

#130
post #67
post #46

Earlier quoted context omitted.

Well, it works, and it's a minor annoyance at most for our legitimate customers. Abusers, on the other hand, have to burn a phone number on each account that gets locked.

I think you don't get it. It's not about annoyance. It's about the complete unreliability of any online service today. All and every customers show (and should rightfully show if they don't yet) complete distrust for a good reason. You are asking my phone number today and next day I will find it out in the open because of your and others' businesses don't give a .... when it comes to security. And don't tell me that'…

We do care about security and hash the phone numbers after sending the verification SMS (we only need to determine whether a given phone number is associated with a locked account - a hash is good enough for that).

Our problem is that criminals open hundreds of accounts with fake data and stolen credit card data, abuse our services until we get abuse complaints or detect it and lock them, then repeat that. This leads to legitimate customers suffering from bad IP reputation and is expensive to clean up.

Requiring phone numbers and blacklisting known throwaway providers has been extremely effectively in preventing this, without generating complaints from our legitimate customers. We don't want to use browser fingerprinting or other intrusive mechanisms for detecting sybil registrations.

What else do you suggest we do?

Post reply on HN