6 ms·
Show HN: Phone verification at no cost
- jldugger 10y agoSo... Twilio adjusts their pricing in 3... 2... 1...
- BinaryIdiot 10y agoNa though I wouldn't be surprised if they add an API to verify phone numbers.
- rizwank 10y agoTwilio likes makes revenue on inbound, or enough breakage on the $1 to not have it be an issue. This is a perfectly legit usage of the number.
- ntauthority 10y agoWould 'rejecting' the call result in the calling user's operator billing them, though? This is a major concern with international usage, given phone providers' tendency to... overcharge for what's technically VoIP usage. The classical text message verification schemes barely have this issue in most of the world as the recipient pays nothing, but of course the sender gets billed instead.
- DDickson 10y agoSo you can only verify, at best, one user every 90 seconds? Also, I have to assume Twilio would look at this as a form of abuse.
- ntauthority 10y agoThis doesn't reserve the incoming number for just that user (given that one has to enter their phone number beforehand), but while the user is using the line, other users most likely wouldn't be able to call either (though it might be Twilio handles this as well and sends a status message anyway - as even cell carriers seem able to notify users of incoming calls while being in a call already).
- gst 10y agoIt's relatively easy to change/fake the caller ID of phone calls so unfortunately this approach isn't really secure. That's why phone number verification usually places an outgoing call, to verify that you're actually able to receive calls on that number.
- wfunction 10y agoAt the risk of sounding like I'm actually going to abuse this capability... if it's done "relatively easily", how is this done?
- lucaspiller 10y agoI switched to a different SIP provider as they were cheaper, but my number was still held at the old SIP provider and couldn't be ported. I explained the story and asked if they could 'virtually' add that number to my account so outgoing calls would come from that number. They just switched on the feature to enable me to set the caller id to anything as it was easier for them.
- MichaelGG 10y agoThis is also a fun attack. Find a provider that does this. Request to port a target number (a bank or an escort service or whatever). Port will stall for a bit, in the mean time, the service provider activates your number internally, so their own dialers route to their "version" of the number. Now you get all the calls from that provider to that number. Forward them to the actual destination (using an unrelated provider) and no one will notice for a while. Except, you get all the calls and media.
- kevindeasis 10y agoHi, there's a free phone verification using facebook. It's account kit. https://developers.facebook.com/docs/accountkit/overview https://developers.facebook.com/docs/accountkit/overview What do you guys think?
- h43k3r 10y agoThis seems interesting. Do you know of any app currently using this. I would like to quickly try it out before the hassle of setting it up myself.
- kevindeasis 10y agoSorry, I don't recall businesses using account kit. However, it's pretty easy to do a basic setup.
- jaxondu 10y agoIts free up to 100K SMS per month. Can find any pricing detail from Facebook.
- kevindeasis 10y agoSorry, I forgot there was a limit.Good catch though!
- chambo622 10y agoSimilar to Twitter's Digits, which has been around for a while and seems quite popular. https://get.digits.com https://get.digits.com
- everfree 10y agoWhy is it free?
- kevindeasis 10y agoTwitter built fabric and it's free because they say "they want more developers using their platform" to help them with building apps
- subinsebastien 10y agoAgain, nothing new. I have already implemented this on my app here : https://play.google.com/store/apps/details?id=in.xtel.quitq.app https://play.google.com/store/apps/details?id=in.xtel.quitq.... using Twilio alone. But, twilio is not completely free.
- OJFord 10y agoWell done. But you didn't blog about it, or release that part of your app as a standalone library. You also didn't (couldn't) patent it - it doesn't need to be new to be interesting and valuable to HN readers.
- therealidiot 10y agoCan people just stop with this whole verify-by-phone thing?
- beefhash 10y agoCan people just stop with this whole spam-every-website-to-death thing? They can't, that's why there's an ever-increasing amount of verification.
- neil_s 10y agoHaha, this is the digital version of the Indian phenomenon of 'missed calls', used as 1-bit 0-cost notification mechanism. It's become such a cultural artifact, that big companies are now advertising numbers you can 'missed call' and get a callback from. https://gigaom.com/2011/12/13/indias-missed-call-mobile-ecosystem-2/ https://gigaom.com/2011/12/13/indias-missed-call-mobile-ecos...
- koolba 10y agoIt's not Indian specific either. I've seen it in a number of places throughout the world. It works anywhere that does not charge to receive calls (i.e. any sane place outside of the U.S.A.) as long as the caller doesn't get billed for cancelling. You can get more than 1-bit of information as well if you sync the clock on your phone with the recipient. That gives you approximately 3.3 bits of information if you use the minute modula 10. This only works if you previously agree upon a meaning for values (Mod 0: Yes, Mod 5: No, etc).
- jdeibele 10y agoThose of us old enough to remember AT&T before the breakup probably had a similar system with our parents. Call, let it ring once and hang up. Repeat. Wait for mom to call you on the family phone.
- cia48621793 10y agoHowever isn't it considered a kind of exploit? Twilio never intended users to waste their VoIP traffic. Could we also do phone verification at no cost, however instead by outbound call? Is there any free/paid host providing such service?
- Matt3o12_ 10y agoAre you willing to make international users pay up to 80¢ per verification? If someone cancels a call, I still have to pay for one minute (it's only free if I cancel the call). So if I were to call any American number that hung up on me, I have to pay 80¢ (USD dollar cents of course). Just pay the 0.02¢ or whatever phone services charge these days. If your business is actually big enough to have to worry about phone verification, do it right. Users don't like to call your number since they don't know the costs associated with it (especially international users). Furthermore, it makes number spoofing much harder.
- faizmokhtar 10y agoThis is pretty cool hack. Great job OP!
- deleted 10y ago[deleted]
- patcheudor 10y agoI may get down voted for this and so be it, this must be said. This is a prime example of creating what was intended to be a security feature without understanding the threat landscape. I just tested it, and it's 100% vulnerable to caller ID spoofing. In 2016, caller ID spoofing is as simple as downloading an iPhone app and spending $30 for a bunch of minutes. The problem is, a lot of people will find this cool and will also not evaluate the threat landscape. In fact, it's even worse. They will assume the threat landscape has already been evaluated. The code is out there, so it must be good. They will then implement this into some "super duper secure" service which should require a far more security for user authentication. It will then take me 15 minutes of pulling my hair out in a security review to explain to whomever implemented it that it offers no security. The team will walk away from our meeting wondering if I was just trolling them and ask how their entire team could have made this mistake. They will then come to the conclusion they are smart and I must be wrong. They'll then call me back to explain again, at which point I'll take them through a full video demonstration with their VP of operations on the call. This time they will actually "get it" because they saw it exploited on video. Their VP of operations will then fire the project manager and lead developer and I'll feel like shit for being responsible for the termination of two careers.
- bpchaps 10y agoNot to mention that it's incredibly inconvenient if you don't carry a phone, or if you lost it. I tried to signup for airbnb this weekend while traveling, but wasn't even able to go through the verification process without a physical phone. Zero alternatives for verification and even trying google voice (my main 'phone' provider) wasn't good enough. Sure, I could've borrowed someone's phone for a second, but isn't that the sort of thing these systems are supposed to guard against? I don't get it. Another example - you can't use uber on a desktop without going to m.uber.com last I checked. There's no way to order trasnportation without that m. (why!) Another - gmail. You either need another email or a phone, and at the time, neither were possible. (why!!) For tons of reasons, I just don't like having a phone in my pocket 24/7/365. Mostly, I just enjoy the peace of mind of being unreachable. I've been oncall for years, but that oncall vibe is extending more and more into social situations, for the worse. I hate it. Devs - PLEASE account for those like me! I'm really tired of people telling me (accurately :(.) "You wouldn't have these issues if you had a phone." on account of your laziness or lack of awareness for sensible security.