Live data from Hacker News

Companies must stop requiring people to link their phone numbers

news.ycombinator.com

31–40 of 51 posts

Re: Companies must stop requiring people to link their phone numbers

#31
post #6

> With the growing number of people working remotely from anywhere It's growing, but it's still tiny. Most companies doing this are willing to lose users who don't have permanent phone numbers in order to gain a quick, easy, semi-reliable way to prevent fake account registrations. > Stick to emails. People barely ever change their emails. This is factually wrong. People get married, get divorced, change employers, gr…

I can get thousands of valid phone numbers for temporary use in 15 minutes. I’d say they are both about equal.

No one needs quadrillions of anything, thousands is enough to do 99% of tasks.

Re: Companies must stop requiring people to link their phone numbers

#32

With companies still requiring phone numbers, Google Fi might be a good option if you have a US address. You keep the same number as you travel worldwide and there are no international roaming charges. Edit: There are no international data and texting roaming charges. Cell based calls can be about $.20 per minute, but wifi calling is free.

Google voice is a better option, costs wise. You can port numbers in.

Re: Companies must stop requiring people to link their phone numbers

#33
post #4
post #2

While this is a major problem for people in your situation, there are no other reliable ways to identify a person and ensure one account per user.

This seems like a missed opportunity after all these years. Nobody's tried to go into the business of "verifying individual humans" and succeeded? Seems like that could and should be just a single facet of a very big online ID service. Basically something like Oauth but for real ID, where you can approve/deny requests for variable amounts of identifying information. It's not like all that information isn't floating a…

I think what is needed is a chain of ID verification systems.

At one end would be a service where you verify you identity when signing up to the service by showing up physically and showing them your government issued photo ID. They photograph you and fingerprint you and take your signature and add all that to their records.

Let's call this service a root identity service. Banks would be great candidates for providing root identity services.

You can use this service to create a verified identity with other services. You would generally only do this with the most important other services, such as your email provider and/or if you have your own domain your domain registrar.

The way you would do this is when signing up with your domain registrar, say, you tell them that you want to verify your identity with your root identity provider. There would be a standard protocol for the registrar to query your root identity provider and for you to tell the identity provider that you are indeed trying to prove yourself to the registrar.

Once that is done, the registrar can set up your account as normal with a username and password and whatever 2FA methods they support. But since you have verified your identity with your root provider, the domain registrar would let you set an option to require re-verification with the same root provider if you need to recover your account after forgetting your password or losing your 2FA device, and to prohibit ever changing the root identity associated with the account.

Someone might steal your domain registrar account somehow, but you can always prove you are the owner and get it back as long as you have not lost control of your root identity account. If someone manages to get control of that, you can get that back first by going in person to an office of the root provider with your government ID, and having them in person verify that, and that you match the other ID information they have on file.

Now you can make Google accounts and Facebook accounts and similar. Those accounts you just associate with an email address. If one of those accounts gets compromised, you recover by going through the usual common recovery method that involves proving you control the email address associated with the account.

You can then use things like "sign in with Google" or "sign in with Facebook" for other accounts, confident that if someone hijacks your Facebook or Google account, you will be able to recover that, and so recover the accounts you use Facebook or Google to sign in to. (You still have to worry about Facebook or Google themselves kicking you off of course, but that's not a problem of identity verification so is beyond the scope of this comment).

The idea is you build a chain of identity, with different links in the chain making different choices in the trade off between security and convenience. You decide where you want each thing to be in that chain, but as long each identity chain leads back to a root identity provider you can rebuild the links and recover any lost or stolen accounts.

Re: Companies must stop requiring people to link their phone numbers

#34
post #22

Earlier quoted context omitted.

OTPs are great, until someone calls up your phone company and social engineers their underpaid support staff into giving them control of your phone number. This is not speculative. I've literally had to help relatives with this exact security breach. Using phone numbers for 2FA is insecure for that very reason. You are entrusting all your personal security with the phone company. Using a OTP by phone number as your o…

I'm presenting the thesis that this system works in places like India and Brazil. I don't have data on my hand that such number transfer social engineering hacks are possible/prevalant here, do you have any?

"here" is relative. Here's one data, this one from Canada: https://youtu.be/LlcAHkjbARs at 3:48

Re: Companies must stop requiring people to link their phone numbers

#35
post #31
post #6

> With the growing number of people working remotely from anywhere It's growing, but it's still tiny. Most companies doing this are willing to lose users who don't have permanent phone numbers in order to gain a quick, easy, semi-reliable way to prevent fake account registrations. > Stick to emails. People barely ever change their emails. This is factually wrong. People get married, get divorced, change employers, gr…

I can get thousands of valid phone numbers for temporary use in 15 minutes. I’d say they are both about equal. No one needs quadrillions of anything, thousands is enough to do 99% of tasks.

> I can get thousands of valid phone numbers

How?

Re: Companies must stop requiring people to link their phone numbers

#36
post #31
post #6

> With the growing number of people working remotely from anywhere It's growing, but it's still tiny. Most companies doing this are willing to lose users who don't have permanent phone numbers in order to gain a quick, easy, semi-reliable way to prevent fake account registrations. > Stick to emails. People barely ever change their emails. This is factually wrong. People get married, get divorced, change employers, gr…

I can get thousands of valid phone numbers for temporary use in 15 minutes. I’d say they are both about equal. No one needs quadrillions of anything, thousands is enough to do 99% of tasks.

I'd argue the infrastructure between phone numbers and e-mails are different enough that filtering for fake phone numbers is easier.

You can look up carrier data on a phone number easily enough, and if you're in the industry you have a general idea of which carriers are the ones that actually follow the rules for registering a number. You filter on the ones that don't.

Re: Companies must stop requiring people to link their phone numbers

#37
post #35
post #31

Earlier quoted context omitted.

I can get thousands of valid phone numbers for temporary use in 15 minutes. I’d say they are both about equal. No one needs quadrillions of anything, thousands is enough to do 99% of tasks.

> I can get thousands of valid phone numbers How?

Any VOIP DID provider with a provisioning API, like Twilio or Anveo.

Re: Companies must stop requiring people to link their phone numbers

#38
post #31
post #6

> With the growing number of people working remotely from anywhere It's growing, but it's still tiny. Most companies doing this are willing to lose users who don't have permanent phone numbers in order to gain a quick, easy, semi-reliable way to prevent fake account registrations. > Stick to emails. People barely ever change their emails. This is factually wrong. People get married, get divorced, change employers, gr…

I can get thousands of valid phone numbers for temporary use in 15 minutes. I’d say they are both about equal. No one needs quadrillions of anything, thousands is enough to do 99% of tasks.

But the point is, you wouldn’t be able to use any of them if the service wanted to block voip numbers. I went through a few providers because I wanted to see what was going on with Parler but didn’t want to share my real number.

Nothing worked.

Re: Companies must stop requiring people to link their phone numbers

#39
post #32

With companies still requiring phone numbers, Google Fi might be a good option if you have a US address. You keep the same number as you travel worldwide and there are no international roaming charges. Edit: There are no international data and texting roaming charges. Cell based calls can be about $.20 per minute, but wifi calling is free.

Google voice is a better option, costs wise. You can port numbers in.

I use and like Google Voice, but I do find that some sites won't accept a google voice number for text messages. usually for 2factor. I would like to know what the difference is?
Post reply on HN