4 ms·
I checked the article to see if I could do exactly that. Why couldn't the second factor be another web service? Password resets shouldn't be possible with the s
by some1else 10y ago
I checked the article to see if I could do exactly that. Why couldn't the second factor be another web service? Password resets shouldn't be possible with the second factor alone anyway. What's the use-case for a publicly readable text service? I'm not familiar with any such services.
- patio11 10y agoWhat's the use-case for a publicly readable text service? Abuse, for one -- many services use "prove you control a phone number" as a first-pass filter for "An action which is easy to do once but hard to do 100,000 times" to authorize people to do a wide variety of things.
- some1else 10y agoApologies. I'm not a native English speaker. Still having a problem imagining in what sense an SMS service might be "publicly available", and how public availability helps in proving control of a phone number :-$
- bigbugbag 10y agoHave you visited one ? https://smsreceivefree.com/ https://smsreceivefree.com/ for example. you will understand what publicly available means: they provide a phone number, you use it for whatever and check the site page where all text sent to this number are displayed.
- rebuilder 10y agoWell, that was an interesting read. Judging by the received SMS people, for example, register Whatsapp accounts with those numbers!
- bigbugbag 10y agoThe use case is anything that requires you to provide a number to receive a confirmation text. From registration to a personal data hungry website (facebook, google, etc.) to two factor authentication. At some point in the past collecting user email addresses became the standard and using disposable email addresses was the answer. More recently the trend seems to have upped to collecting phone numbers to which the answer is those public text services.