6 ms·
Top Sites to Receive SMS Online Without a Phone
- bigiain 10y ago<evil hat>What an awesome way to collect SMS 2FA tokens. Plug this into a database of password breaches (an evil version of Have I Been Pwned that stores hashes and passwords, for example) and as soon as you see token-looking-things, hit Paypal/banksites/Amazon with any reversed passwords you have and try the token...
- kingbirdy 10y agoSomeone would have to be pretty dumb to go to the trouble of setting up 2FA, but using a publicly readable text service instead of their phone
- marak830 10y agoWhich means it will happen most likely. Even techies make stupid mistakes, such as me not changing my Skype password the other day, and had the account breeched. Sigh
- patio11 10y agoDo not underestimate the capabilities of a non-technical user wanting to be helpful giving another non-technical user seemingly authoritative advice on an Internet message board. (If it is not obvious, I am not speaking hypothetically here; I have watched this happen.) And if you think "Gah, only an idiot would...", read HN threads about law sometime.
- some1else 10y agoI checked the article to see if I could do exactly that. Why couldn't the second factor be another web service? Password resets shouldn't be possible with the second factor alone anyway. What's the use-case for a publicly readable text service? I'm not familiar with any such services.
- patio11 10y agoWhat's the use-case for a publicly readable text service? Abuse, for one -- many services use "prove you control a phone number" as a first-pass filter for "An action which is easy to do once but hard to do 100,000 times" to authorize people to do a wide variety of things.
- some1else 10y agoApologies. I'm not a native English speaker. Still having a problem imagining in what sense an SMS service might be "publicly available", and how public availability helps in proving control of a phone number :-$
- bigbugbag 10y agoHave you visited one ? https://smsreceivefree.com/ https://smsreceivefree.com/ for example. you will understand what publicly available means: they provide a phone number, you use it for whatever and check the site page where all text sent to this number are displayed.
- rebuilder 10y agoWell, that was an interesting read. Judging by the received SMS people, for example, register Whatsapp accounts with those numbers!
- bigbugbag 10y agoThe use case is anything that requires you to provide a number to receive a confirmation text. From registration to a personal data hungry website (facebook, google, etc.) to two factor authentication. At some point in the past collecting user email addresses became the standard and using disposable email addresses was the answer. More recently the trend seems to have upped to collecting phone numbers to which the answer is those public text services.
- bigbugbag 10y agoIt really depends. Not so long ago the humble bundle forced 2FA on me and I had the choice of forfeit my 100 games library or set 2FA. I don't care at all that steam gives them heat about how some steam keys are used, and I care enough about my phone number not to give it away. Then there was the time when I was traveling and verification SMS would not reach me because my carrier plan does not include receiving SMS internationally. Then there was a few other times and cases where not using your phone (provided you have one and carrier plan) but a public text service instead. To me phone based 2FA is mostly a scheme to collect users' phone numbers as there were in the past to collect email addresses. It introduces a pretty serious point of failure by relying on mobile number (no battery, no signal, no phone, changed number, prepaid card, etc.) while only being helpful in fringe cases such as when my password has been stolen. Moreover it promotes bad security practices instead of fixing security issues, just slap some 2FA on top of whatever exists and now it is secure. Then there is the question of how do I change my associated number when I change phone number, then what prevents a social engineering pro from changing the number too ? I'm not sure using a publicly readable text service is so wrong, it mitigates the relying on phone point of failure, protects your privacy better, someone else reading the code may not be a problem as the code alone is useless. As usual this really depends on what is the threat model you trying to protect from. Neither option will be able to protect you from a nation state targeted attack.
- Freak_NL 10y ago> Not so long ago the humble bundle forced 2FA on me Never had that request from them, and I'm an active user of the Humble Bundle and Humble Store. What triggered that request?
- curun1r 10y agoA lot of these services won't be able to receive a lot of those 2FA text messages. Short code SMS isn't universally able to reach all SMS capable services/providers. I found this out the hard way when I ported my number to Twilio and stopped getting commercial SMS messages. I've since ported to Google Fi and many of those SMS messages still don't work.
- bluesign 10y agoisnt the order wrong here? - You hit paypal etc - wait for token in this public lists should be the correct way.
- dorianm 10y ago> Ironically, Twilio gives you a private phone number for free in the trial account if you provide them with your phone number to receive a verification code. Fortunately you can use any of the temporary phone numbers from the sites above to receive the verification code to activate Twilio trial account.
- smcl 10y agoBtw if you have a Thinkpad X250 or other laptop based on a Sierra em73xx modem I wrote a python library to send/receive SMS using that: https://github.com/smcl/py-em73xx https://github.com/smcl/py-em73xx
- smcl 10y agoOops maybe I should remember to check before sharing things like this - I forgot that I have "(TODO, haha!)" in the "Documentation" section of the README. Check the Examples section for how this should work. It's very simple, but admittedly my docs should be better. You can also pick it up from pypi: https://pypi.python.org/pypi/em73xx https://pypi.python.org/pypi/em73xx
- Mathnerd314 10y agoDoesn't even mention Google Voice? Site author in Malaysia? Maybe it's useful information for someone, but it seems more like an SEO content trap than a blog.
- seszett 10y ago> Doesn't even mention Google Voice? Well, you need a phone number to sign up for a Google account, so Google Voice isn't an option if you don't already have a phone.
- manarth 10y agoisn't an option if you don't already have a phone Despite the article's headline, I believe their use-case if for people who have a phone, but don't wish to give their real phone number to any arbitrary website, hence the comparison in the intro with temporary email addresses, and the line "If for some reason you need to receive text messages online from your computer rather than your phone".
- jakobegger 10y agoOhhh, this is wonderful. I'm eternally grateful for whoever runs yopmail.com; I didn't know that something similar exists for text messages as well! It sounds like something that should be an open source crowd-sourced service! It imagine it could work like this: 1) Generous people donate a phone number by putting a cheap prepaid SIM into an old smartphone with a special app on it. 2) Everyone else can now use this number to receive messages! 3) The service could end up having hundreds of phone numbers available, with stats (eg. last message received, number of messages received, downtime, etc.) Just like generous people today run TOR exit nodes, generous people could run an "SMS entry node". (not sure if that term makes sense) Disadvantage: like TOR, it can and will be abused by spammers. Advantage: Companies need to come up with better anti-spam measures instead of "give us all your personal data".
- kmfrk 10y agoYouTube's authentication system is extremely annoying; you can't attach your phone number to more than two accounts. Does anyone know if you can select a Twilio trial number from a different country than your own?
- jstanley 10y ago(Shameless plug coming up) Not listed in the article: I run https://smsprivacy.org/ https://smsprivacy.org/ We don't require any identifying information for signup (not even an email address). We take payment in Bitcoin. We have cheap virtual numbers available where our upstream provider blocks signup verification codes, and more expensive "physical numbers" available to receive verification codes. Featured on Indie Hackers here: https://www.indiehackers.com/businesses/sms-privacy https://www.indiehackers.com/businesses/sms-privacy Revenue has now grown to nearly $1200/mo. Ask me Anything!
- gyey 10y agoHow are physical numbers different from virtual numbers? What would be the advantage of using a physical number? Why do they cost 120 times as much as a virtual number? How is this better than using Twilio? (Virtual number is $5 a month and physical number is $20 a day)
- jstanley 10y agoGood questions. Ideally the website would make this clearer upfront. Our upstream provider of virtual numbers filters out verification codes from services like Google, Facebook, and Twitter. The advantage of using a physical number is that no messages are filtered out. They are more expensive because they are more expensive to me. And the typical customer only uses a physical number for one day, where the minimum purchase time for a virtual number is one month, so the effective price to the customer is "only" 4 times as much. It's better than Twilio because Twilio filter out verification code messages, and because Twilio don't allow anonymous signup or Bitcoin payment.
- gyey 10y agoThanks for the detailed reply.
- marmshallow 10y agoIs Twilio your upstream provider?
- wfunction 10y agoWhile we're on the topic, could someone explain the following? 1. Is there any free way to send an SMS "from" a different phone number that you verifiably own, without actually sending it from that number? (e.g. if your service provider charges you for messages sent through them, but the phone number is yours) 2. Beyond that... how do VoIP services go about sending & receiving SMSs themselves? Why can't I do the same thing and bypass them?
- jstanley 10y agoMy admittedly very limited understanding is that it works basically the same as the Internet. Anybody who wants to be a serious player needs to have sufficient peering agreements that they can route traffic to every other player. So yes you could do it yourself, the same as you could setup your own ISP. It's just easier and cheaper not to.
- wfunction 10y agoDo traditional lines work the same way basically too, in this respect? Or is there a fundamental difference between traditional lines and VoIP lines in this aspect?
- jstanley 10y agoI would assume so, although traditional lines were a lot more nationalised. So it would be the same thing, but (international) agreements between national carries rather than private companies.
- csomar 10y agoProbably they have expensive contracts with carriers?
- MichaelGG 10y agoIt's an honour based system. There are companies that'll activate SMS on any number. They verify your access to a number, then they have a contract that lets them assert they are allowed to do SMS for you. The owner of the number (the carrier) has to agree to this system so it's not available for every possible number.
- formula_ninguna 10y agois there any way to dynamically create such a number or numbers in my Twillio account? how many?
- nbrempel 10y agoI needed something like this a few months back so I whipped up a tool over the weekend to do this. Feel free to use it! https://sms-scope.com/ https://sms-scope.com/
- camoby 10y agoAs someone who's sick of giving out my mobile number to sites and services, does anyone happen to know which of these might work with Skype, if they've curiously decided to lock you out of your account since they don't have a mobile number for you?
- inevitable2 10y agoWhy pay when you can receive sms online free on a huge number of sites? The best service for me is https://freephonenumber.online https://freephonenumber.online