Live data from Hacker News

Ask HN: Why are phone numbers considered a secure personal identifier?

news.ycombinator.com

21–30 of 46 posts

Re: Ask HN: Why are phone numbers considered a secure personal identifier?

#21
post #17
post #10

No - it is not a secure personal identifier (in many countries). According to Australian laws, someone can port your mobile number to his/her sim card by filing an online form, as long as they know your date of birth and account number, that person can take your phone number away in minutes. Nothing need to be done in person, no ID will be asked. In fact, the laws are made to explicitly forbid such checks under the n…

Is the port done immediately or do you have something like 24+h between receiving the port notification and it becoming active to reverse the process and/or login to your accounts and activate Google Auth?

It is done immediately.

Re: Ask HN: Why are phone numbers considered a secure personal identifier?

#23
From companies' perspective, SMS has a critical property that U2F dongles and TOTP authenticators lack: Restoring the user's access if they lose it is someone else's problem.

With SMS login, if I lose my phone getting back into my account is an argument between me and my phone provider. And blame for any mistakes in that process lies squarely with my phone provider.

This avoids the "I lost the backup codes as it's 5 years since I printed them out" problem.

Anyone involved in designing a 2FA system knows SMS isn't secure - companies like Apple accept that insecurity, to avoid the support costs of the lost-backup-codes problem.

Re: Ask HN: Why are phone numbers considered a secure personal identifier?

#25
post #9
post #7

Earlier quoted context omitted.

You are an immigrant, not an expat.

I suspect you're trying to fight the "white people are expats brown people are immigrants" stereotype, which is noble. But there is a good argument to be made that Americans are unique in the sense that we are still taxed by America when we leave, so we need a word that describes Americans living abroad.

Not all Americans are white either...

Re: Ask HN: Why are phone numbers considered a secure personal identifier?

#27
post #2

You raise 2 points. First is traveling quite a bit with poor cell signal. This one is unfortunate especially with banks that have no alternative 2fa other than a phone based OTP. Why phone? I would believe it's the one thing that near ubiquitous that has a very low barrier to entry. I never had to train my mother how to use OTP when it's an SMS. If she was required to use google authenticator, I'd probably get a phon…

> Google Voice cannot do shortcode SMS for places like Bank of America.

This is an important point for OP to consider. Twilio definitely can't receive SMS from US short codes[1]. When my number was at Google Voice I thought it could receive messages from short codes, at least in the recent past, but I ported it out so I can't test.

[1] -- https://support.twilio.com/hc/en-us/articles/223181668-Can-T...

Re: Ask HN: Why are phone numbers considered a secure personal identifier?

#28
post #3

Counterpoint: I’ve had the same number for 20 years. In all that time, I’ve had maybe 5 instances where I needed to get a confirmation number and couldn’t get enough reception. It works well enough, the vast majority of the time, for the vast majority of people. You’re an extreme edge case.

Over 1.4 billion people travelled internationally in 2018. You’re making an assumption based on a single data point, just as you imply the author to be. Do you use PayPal? It’s impossible to even login while you are abroad.

I agree with you, it's absurd how much companies rely on the premise that you are still hooked into a national phone network. Because even if you're using a temporary or permanent international SIM card, typically these "convenient" 2FA systems will not text international phone numbers. Conversely, it's typically too expensive on a long-term basis to use a phone plan from one country while traveling / working / living abroad in another country. Now, after countless struggles with it, whenever I see a random request for getting my phone number for 2FA, I instantly reject it. No, I do not want your incompatible extra security system that will lock me out randomly, thank you. For U.S. engineers who basically don't travel abroad for extended periods of time, it may seem weird or unlikely that these problems exist, but I have several friends who would also testify they do - and 2FA with phones doesn't work for us.

Re: Ask HN: Why are phone numbers considered a secure personal identifier?

#30
post #29

We need a DNS service for telephone numbers. This would remove the need for number porting when you switch providers and would give you the ability to use other phone numbers when abroad.

Most countries already have number porting. International porting is probably a 0.1% problem and there are solutions for that (eg. Skype number)
Post reply on HN