Live data from Hacker News

Living without a SIM card

habd.as

141–150 of 300 posts

Re: Living without a SIM card

#141
post #112

Earlier quoted context omitted.

exactly the original comment was make sure not to leach, and someone else thought it was a toxic attitude, and I don't think it is too toxic an attitude - because there are people who are leaches after all.

But there's being a leach, and there's trying to cope given a moral-philosophical decision not to use a phone. And you're not distinguishing them.

They aren't mutually exclusive.

Re: Living without a SIM card

#142
post #129

I envy the OP. Unfortunately since September 2019 living without SIM card became (practically) illegal in EU. > most online payments above €30 to go through an extra level of verification such as entering a code received via a text message. [2] Most banks unwisely chosen SMS as Strong Customer Authentication providing little choice to customers. https://ec.europa.eu/info/law/payment-services-psd-2-directi... [2] http…

Where are you? Here in Germany, most banks do not require SMS (many have phased out SMS entirely).

Re: Living without a SIM card

#144
post #122

To me, the price paid to a cellular provider is actually preferable to relying on other people's WiFi networks. Using someone else's WiFi isn't a security advantage, it's the opposite. You're bumming off of someone's network and not even paying them - so who knows what their motivations might be. Who knows if the network that the SSID claims to be is actually that network. Is Starbucks Free WiFi actually run by Starb…

>> Is Starbucks Free WiFi actually run by Starbucks or is it a malicious router placed in the same vicinity? Both. The Starbuck Free WiFi is also a malicious router. All routers should be seen as malicious. That threat model is why we have secure websites. That's why VPNs are always a good idea, or Tor if you are really worried. But even then, those routers too must be deemed untrustworthy. At no point should one eve…

Are there any sites of any importance that don’t use https? What’s the threat model?

Re: Living without a SIM card

#145
post #129

I envy the OP. Unfortunately since September 2019 living without SIM card became (practically) illegal in EU. > most online payments above €30 to go through an extra level of verification such as entering a code received via a text message. [2] Most banks unwisely chosen SMS as Strong Customer Authentication providing little choice to customers. https://ec.europa.eu/info/law/payment-services-psd-2-directi... [2] http…

Banks in the US and EU are required to have the identity on file for all bank accounts (ostensibly to combat terrorism), so sharing your phone number with them shouldn’t change the level of privacy. If it is cost people are worried about they can get a prepaid card and never use it except to receive sms. That’s effectively free.

Combined with the push to get rid of anonymous accounts and phone numbers there has also been a push to get rid of cash. I expect to see a time in my lifetime where a country will fully do away with all anonymous forms of payment, effectively making it impossible to be anonymous.

Re: Living without a SIM card

#146
post #131
post #129

I envy the OP. Unfortunately since September 2019 living without SIM card became (practically) illegal in EU. > most online payments above €30 to go through an extra level of verification such as entering a code received via a text message. [2] Most banks unwisely chosen SMS as Strong Customer Authentication providing little choice to customers. https://ec.europa.eu/info/law/payment-services-psd-2-directi... [2] http…

Unless you summarize the law we don't know what you mean by "practically illegal." When you say "practically illegal" I can only assume you mean "not illegal."

They're referring to the Revised Directive on Payment Services ("PSD2") passed by the European Union which imposes a requirement to use "Strong Customer Authentication" for certain financial transactions (online or contactless) to reduce fraud, among other things.

When you make a payment over a certain size, you're required to verify that it's you making the payment. It's 2FA for payments essentially, you enter the code sent by SMS or you tap the approval button in your banking app, or enter your PIN again for contactless transactions.

It seems a lot of payment institutions have allegedly implemented SMS verification for these transactions. I bank with Monzo (https://monzo.com) which offers an approval notification in their app.

Unless you switch to a "challenger" bank like Monzo, you're going to be getting SMS to verify transactions (otherwise the transaction won't go through) and while I consider it hyperbole to mark this as "practically illegal", it does make things rather difficult for those with no phone or SIM card.

Re: Living without a SIM card

#147
post #142
post #129

I envy the OP. Unfortunately since September 2019 living without SIM card became (practically) illegal in EU. > most online payments above €30 to go through an extra level of verification such as entering a code received via a text message. [2] Most banks unwisely chosen SMS as Strong Customer Authentication providing little choice to customers. https://ec.europa.eu/info/law/payment-services-psd-2-directi... [2] http…

Where are you? Here in Germany, most banks do not require SMS (many have phased out SMS entirely).

In Poland most banks I use (Citibank, Santander, Millenium and others) require confirming logging into account via SMS at least once in two weeks. Some require confirmation via mobile app. (That wasn't obligatory before)

Its rather that banks have phased out other methods like tokens as too expensive and troublesome.

https://www.money.pl/banki/santander-pko-bp-mbank-czy-pekao-...

https://www.spidersweb.pl/2019/09/jak-zalogowac-sie-do-banku...

Re: Living without a SIM card

#148
post #139

Earlier quoted context omitted.

Don't blame the EU just yet. 1. EU didn't force the banks to use SMS 2. EU is aware of the privacy/security issue of SMS and is planning to actually ban using SMS otp as a form of strong auth https://www.zdnet.com/article/german-banks-are-moving-away-f...

I wasn't blaming EU (I am not in a habit of bashing EU) and I am not saying this is completely bad law. I am just observing the reality on the ground.

My point was really that the banks will be forced (by EU)to drop sms as SCA anyway. Legislation for that to happen is already in place.

Re: Living without a SIM card

#149
post #131

Earlier quoted context omitted.

Unless you summarize the law we don't know what you mean by "practically illegal." When you say "practically illegal" I can only assume you mean "not illegal."

They're referring to the Revised Directive on Payment Services ("PSD2") passed by the European Union which imposes a requirement to use "Strong Customer Authentication" for certain financial transactions (online or contactless) to reduce fraud, among other things. When you make a payment over a certain size, you're required to verify that it's you making the payment. It's 2FA for payments essentially, you enter the c…

SMS is not PSD2 compliant. https://www.zdnet.com/article/german-banks-are-moving-away-f...

Re: Living without a SIM card

#150
post #133
post #131

Earlier quoted context omitted.

Unless you summarize the law we don't know what you mean by "practically illegal." When you say "practically illegal" I can only assume you mean "not illegal."

I have edited my answer. Most institutions I know have chosen SMS for Strong Customer Authentication which means sooner or later you in practical life will need your personal SIM card (banking, doctor visit, e-prescription, e-government etc.). Unless you chose to live off the grid for real.

But also, I think you have that situation understood the other way around.

SMS was chosen because everyone has it already. So it's not a matter of being forced to have it, it's a matter of "all other alternatives are less widespread."

I think there are actually more people globally with access to mobile phones than people who have access to basic sanitation, i.e. flushing toilets.

I'm sure that many or most of those organizations have alternative, non-electronic means of interaction - such as phone, paper (writing checks), or in-person. That is the alternative to using a SIM card.

Post reply on HN