Live data from Hacker News

It’s time to stop using SMS for security

lucky225.medium.com

41–50 of 149 posts

Re: It’s time to stop using SMS for security

#41
post #19

Living in Germany, I don't remember the last time I used an SMS. When I was in south-east Asia I don't think I ever used SMS, it was always Line (or WeChat in China) or email. Is there a reason SMS are so much in use in the US but not in other parts of the world?

I also live in Germany. I don’t want to get some extra service tied to my phone number, so contact with people is via sms if it has to be mobile, E-Mail otherwise.

Re: It’s time to stop using SMS for security

#42
post #19

Living in Germany, I don't remember the last time I used an SMS. When I was in south-east Asia I don't think I ever used SMS, it was always Line (or WeChat in China) or email. Is there a reason SMS are so much in use in the US but not in other parts of the world?

I am in Switzerland and half of web services ask for a sms confirmation these days. Its not an US issue

Re: It’s time to stop using SMS for security

#43
post #7

So, I work in telecom and dabble a bit in software. I don’t understand the hatred for SMS 2FA on HN. Can someone explain to me why SMS is such a bad method comparative to other solutions where the practical user adoption is near impossible at scale? At some point, software is going to need to bend to the way people work. When does that happen instead of obsessing over ubiquitous “zero trust”. I’d love a parable of ho…

You might want to ask some of your greybeard coworkers...

https://www.itnews.com.au/news/telcos-declare-sms-unsafe-for...

Re: It’s time to stop using SMS for security

#45
post #7

So, I work in telecom and dabble a bit in software. I don’t understand the hatred for SMS 2FA on HN. Can someone explain to me why SMS is such a bad method comparative to other solutions where the practical user adoption is near impossible at scale? At some point, software is going to need to bend to the way people work. When does that happen instead of obsessing over ubiquitous “zero trust”. I’d love a parable of ho…

You never own the number. It could anytime go to someone else without notice (most contracts contain that line) and if you do not pay for only a few months its very likely someone else suddenly gets your 2fa.

Using phones is honestly a huge security issue

Re: It’s time to stop using SMS for security

#47
post #32
post #19

Living in Germany, I don't remember the last time I used an SMS. When I was in south-east Asia I don't think I ever used SMS, it was always Line (or WeChat in China) or email. Is there a reason SMS are so much in use in the US but not in other parts of the world?

I don't think that's true though. Maybe you haven't SEND any, but I bet you receive a lot. At least I do: from my bank, from some of my bank accounts, from my mobile service provider, from my parcel delivery service. From Coinbase, from PayPal... The list goes on and on.

So, I just checked, during the past ~6 months I got the following:

- Clubhouse invite

- A security code from a trading exchange

- My mobile internet provider telling me I reached 80% of my monthly data budget

- A few codes to validate my phone number when creating new accounts on platforms

And that's basically it.

Re: It’s time to stop using SMS for security

#49
post #42
post #19

Living in Germany, I don't remember the last time I used an SMS. When I was in south-east Asia I don't think I ever used SMS, it was always Line (or WeChat in China) or email. Is there a reason SMS are so much in use in the US but not in other parts of the world?

I am in Switzerland and half of web services ask for a sms confirmation these days. Its not an US issue

Not even niche web services. Yesterday Amazon insisted I tell them the code they sent to a phone I haven’t owned in 5 years.
Post reply on HN