Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I've encountered several services that demand a mobile number for verification. Google Voice numbers are rejected and surprisingly, so are landline numbers. Only numbers for mobile are accepted. It's just another case of how the tech world has outsources identity verification to the mobile telecom companies.


Companies that mandate use of another company offer a good reason to shun both companies, when there are independent competitors which prioritize customer relationships over "business partner" relationships.

SMS is woefully insecure for multi-factor authentication, when we have TOTP and other open standards that work with local-only password managers.


And not only that, most companies that involve SMS in their IDP make it a master key (a single-factor) -- if you can read one text, you can take over the whole account without even having the password. I keep waiting for this to change, but out of all my banks not one supports a proper TOTP.


It's really annoying, especially when they frequently then expect you to enable that cell number as not only a 2FA but really a 1FA (capable of resetting your password WITHOUT the password).

It's because it's super cheap and simple, though, and that's about it.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: