13 ms·
I constantly run into this problem, I've used my google voice number for everything for years (yeah it's not a great move but very hard to migrate away from) an
by errantspark 5y ago
I constantly run into this problem, I've used my google voice number for everything for years (yeah it's not a great move but very hard to migrate away from) and a frustrating number of services recently have been rejecting it for verification. I end up having to take the sim out of my laptop and put it in my PinePhone. It's such a hassle. This whole "you're not a human unless you have a phone number" thing sucks. Same thing with having a credit score. You're just assumed to participate in these systems even though there's no mandate to do so or protection for you if you don't.
- perryizgr8 5y agoUsing SMS as a login verification thing is just so irritating. My bank asks me to enter an SMS OTP every time I login to the website. I know my username and password! Let me into my bank account!
- Plasmoid 5y agoThey're trying to do that to break 3rd party financial integrations. Not for your security but because they think they deserve to get paid for your data and these other people haven't paid up.
- Zak 5y agoCredential stuffing is a widespread problem. Im sure everyone on HN uses a password manager and different passwords for every service, but many people don't. It's makes a lot of sense for a high-value target like banking to require 2FA, but SMS is the worst way to do it.
- giancarlostoro 5y agoWait what? You literally put a sim card into a phone for it to be treated as a cell number? Thats odd and interesting to me how does that work?
- kreeben 5y agoInstead of "phone" do you actually mean "laptop"? Interfacing with a SIM through a computer seems pretty Futuramaistic to me. How does _that_ work?
- errantspark 5y agoMy laptop has a built in cellular modem, I find that being connected to the internet constantly is much more useful in a laptop form factor. Phones mostly just try to serve me ads in invasive ways and I'm not here for it.
- mindslight 5y agoAFAIK cell modems generally have functionality to send/receive SMSs, and you should be able to do that with the right software. Completely agree about the walls of commercial surveillance closing in though.
- errantspark 5y agoYeah, I'm sure it's possible to do so, but unfortunately my BIOS locks me into the OEM modem, there is no linux driver for it and the windows one is not documented so no luck for me in that regard. At some point I'll pour some more sweat into it and try to unlock the bios or something but sadly for now this functionality that my computer absolutely has is unavailable to me. Same with getting NMEA sentences off the GPS, I have to use windows' idiotic location API for that. 9600 baud serial worked just fucking fine, I don't understand why that isn't available as well. It's so annoying that I have to fight this hard for functionality my hardware already has.
- kingcharles 5y agoI tried to log into the IRS.gov portal, but it says I can't because I don't have any credit score. (I don't have any credit because I'm an immigrant)
- jedberg 5y agoYeah same. ETrade recently changed their phone verification system and can no longer send me a text message to verify my identity. I'm actually ok with that because it forces them to use the security token instead, which they should be doing anyway! And often I'll run into problems with silently failed messages because they don't accept the number.
- KennyBlanken 5y agoYep, the latest example was my credit card company rejecting my GV number. They easily have the means to see that I've been using it for 10+ years and it's definitely me. Luckily they wanted my business more than they cared about that policy; a CS droid was able to "force" the system to allow it. Requiring cell phone numbers isn't about anti-spam or 2FA or anything else these services and sites claim. It's about linking your account to a real person identity, so they can sell that to someone - either live, or later when they get bought out (privacy policies almost always have a clause that allows them to just fork over all your info to whoever buys the company.) "Where was phone number 111-555-1212 at any point in time" is really valuable these days. SMS for 2FA is less secure because cellular accounts are almost trivial to take over. Carriers never intended for their accounts to become so important to security. These days you can get a second password added to prevent shipping out a new SIM or transferring the account, but that's bypassable by a cellular store on the corner, and poorly implemented (my carrier just adds it as a CUSTOMER VISIBLE AND EDITABLE comment on my profile. WTF?) If you get someone's unlocked cell phone or a SIM card, you can get access to their email account, their bank and credit cards...damn near everything. How fast can you lock and wipe your phone if it was ripped out of your hands while you were using it in a public place?
- est31 5y ago> It's about linking your account to a real person identity, so they can sell that to someone - either live, or later when they get bought out Yeah, this can't be emphasized enough. Phone numbers are established as universal identifiers. Discord is sitting on a giant heap of personal information including DMs from millions of young people. It is all centralized, both in terms of data, and in terms of accounts (instead of them having to correlate an account between multiple forums, most of which volunteer run and they don't turn over non-public data for money), and also associated with phone numbers. Making multiple accounts for different areas of life is made hard. Beautiful for whoever has access to the data.
- deleted 5y ago[deleted]
- 5y ago
- thaumasiotes 5y agoJust a couple of days ago, I signed in to a gmail account using the correct username and password. Gmail intercepted me and claimed to be worried that they couldn't recognize the device I was using. According to the flow, they wanted me to verify my identity in one of three ways: (1) I could verify the backup email address associated with the account; (2) if unable to do that, I could provide the 2FA code sent to that same backup email address (how would I be able to know this without being able to know what the address was?); or (3) I could provide a phone number -- previously unknown to Google -- on the spot, and then provide the 2FA code sent to that brand-new phone number. (How is this supposed to help them verify my identity?) I went for option (2), the email 2FA code. After providing the code, I was informed that, before signing in to my existing gmail account, I must also provide a phone number and enter the 2FA code sent to my new phone number. So I went back and went for option (1), typing in my backup email address. Same thing happened. Because Google "couldn't recognize the device I was using", I was not allowed to sign in to an account I obviously controlled without providing a phone number with absolutely zero authentication value. I did find a workaround. If you attempt to sign in to an account afflicted in this way in an incognito browser window, Google will, for the moment, allow it. "Don't be evil" is long gone.
- jiggunjer 5y agoI seem to recall fb doing similar. It's similar to banks or telecom providers requiring a persons home address (or worse: to prove it using a utility bill).
- zippergz 5y agoI had this problem this week too. I have a secondary Gmail account that is forwarded to my main one. I tried to login to it, they demanded a phone number (even though I do have access to the backup email), and wouldn't let me in because the only number I have is one that's already in use on my main account. I guess now you need one unique fully-functional phone number for ever Google account you have?!
- geektips 5y agoI think you can verify 6 Google accounts with a single number.
- Buttons840 5y agoMeanwhile the community is having a big debate over the CoC, deciding what exact wording they should use to say "be nice and include everyone".
- imwillofficial 5y agoWhy just communities be forced to accept everyone? Or even be nice? When in a group of friends we can often times not “be nice” however because we know each other, we understand it comes from a place of love. Perhaps it’s a military background thing, but exclusivity has its benefits.
- deleted 5y ago[deleted]
- tomc1985 5y agoBut that goes against the current zeitgeist where you absolutely must love everyone (except your political and ideological opponents)... or else!!!
- kiklion 5y agoI think this is completely different than having a credit score. I’ve never ‘needed’ a credit score unless I was requesting a line of credit. I’m which case a credit score is better than the alternative where I need to personally know someone that the lender already trusts and trusts their ability to trust other people. You don’t ‘need’ a credit score but if you want a line of credit then it’s good to have. Otherwise you get the products that they offer to high risk individuals which costs a pretty penny.
- errantspark 5y agoA credit score is used as a trustworthiness analog in arenas other than lending. For example renting a house or car, and some phone companies won't give you access to a post-paid plan, all of which can have a stratifying effect. The idea that because I don't take on debt that I am not trustworthy is wrong. I can pay a larger security deposit to offset risk, but often times that's not an option. I've also heard tell of employers using credit checks to evaluate potential employees though I haven't researched that.
- true_religion 5y agoPost paid plans are credit. It’s allowing you to consume goods, then pay for them after the fact. Sure, it’s short term credit (sub 30 days), but it’s still credit.
- acka 5y agoI believe that grandparents point was that by not taking on any debt they don't have a credit score which can be verified. You can't verify something that doesn't exist in the first place.
- true_religion 5y agoI thought their complaint was that without a credit score, businesses don't see them as 'trustworthy'. The OP separated 'trust' from 'credit score', and says they shouldn't be conflated. However since all of the OP's examples involved credit (car rental post-pay, phone usage post-pay, etc.) then in those cases trust===credit score. Without a credit score, you're basically asking someone to trust blindly that you'll pay back a debt since there's no track record of your ever paying back debts.
- zamadatix 5y agoHow does this work for Fi users? I've had a Google Voice number for so long it's the only voice number I have these days. I can't say it's a recent experience that it doesn't work with certain things though it has been a recent experience the things are aware it doesn't work and will alert you. Overall though I've yet to run into anything I couldn't use an alternative method for authentication be it luck (e.g. got into Discord before they required phone numbers) or email or calls being a thing (and working when text doesn't). Ironically the biggest PITA I had was when I decided to migrate my primary cell number to Google Voice it was my fallback contact number. Thankfully I only ran into that as an issue once and was able to get back in to set up Google Authenticator (which was also new and hip at the time).
- govg 5y agoI'm not sure if there are any issues on Google Fi, since they're an MVNO, so identical to any other cellular network.
- mdaniel 5y agoAs one point of anecdata, the IRS refused to honor my Fi phone plan because it didn't have my name and mailing address registered on it (or at least to their satisfaction). I don't know if they still require a post-paid cell phone plan for their auth scheme or not, because I gave up trying to make it through after about 6 months of requesting magic codes through the USPS Anyway, that's a lot of words to say "MVNO" is for sure not identical to "any other cellular network" for a certain class of interested parties, in the same way that pre-paid credit cards are not the same as other credit cards
- thewebcount 5y ago> This whole "you're not a human unless you have a phone number" thing sucks. Oh it’s even worse than that. I have a land line that I use exclusively for when I’m forced to give a phone number (and also for faxing doctors and lawyers which is apparently still a thing). Many internet forms reject it because it can’t accept text messages. Yeah, that’s the fucking point. I don’t want text messages from your shitty service. It’s still a legitimate phone number you can call. Don’t ask for a phone number if you won’t actually accept a valid phone number! FFS!
- nindalf 5y agoI’m sorry you ran into that problem. I ran into the opposite problem, of thousands of fake accounts a day using VoIP phone numbers to create accounts. Almost all of them were fake/abusive when they were investigated manually. Blocking these numbers felt like the sensible thing to do, because it made the abusive account creators spend more time, money and energy creating their accounts. I’m sorry it impacted you.
- njarboe 5y agoEvery one used to use your social security number instead to uniquely identify people but that was made illegal because of the many problems this caused. But company's want a unique identifier for people. Now that everyone has cell phones people never change their phone number so it is a great unique identifier that is legal to use. Not enough edge cases, yet, like yours too worry about. Maybe it will be made illegal in the future.
- b3morales 5y agoIt's never been made illegal to use, or even ask for, an SSN. You can refuse to provide it (unless it's required for tax/employment purposes) but whoever's asking can then just refuse to transact with you.
- njarboe 5y agoThanks for the info. I guess I remembered when companies stopped printing out social security numbers on everything (badges, informational letters, etc.) and using them generally due to, probably, this California law[1]. [1]https://www.kmm.com/articles-195.html https://www.kmm.com/articles-195.html
- TonyTrapp 5y ago> I end up having to take the sim out of my laptop and put it in my PinePhone Just in case you are not aware, you can receive verification SMS on your laptop as well! On Windows 10 there is a built-in app simply called "Messaging" which shows you all the SMS received on that number. I'm sure something different exists for other OSes. This is what I do when asked for a verification number and there is absolutely no way around it, I just put the phone number of my laptop's SIM card, that way I don't have to worry too much about spam too because I will never use that number in a real phone.
- glenneroo 5y agoThere are laptops with SIM card slots?
- TonyTrapp 5y agoSure, WWAN modems are not only a thing that exists inside mobile phones. ThinkPads (and I'm sure other business-oriented brands as well) often (always?) have optional slots for WWAN modems, so you can use them for a mobile internet connection without tethering. I've been using that feature for over ten years now.
- Symbiote 5y agoI had one around 2009. It even came with Linux. They seem less common nowadays, since a tablet or tethered phone covers most use cases.
- GoblinSlayer 5y agoIt looks like this: https://www.amazon.com/Huawei-E3372h-153-Unlocked-External-Antenna/dp/B013UURTL4/ https://www.amazon.com/Huawei-E3372h-153-Unlocked-External-A...
- glenneroo 5y agoAh yes, thanks! I have used a similar USB dongle. I was wondering if it was a special built-in tray or slot in the laptop.
- dopamean 5y agoI had been using my gv number for 9 years for everything as well. I recently ported it out of gv into my mobile carrier since no one knew my carrier number and I was running into too many annoying voip restrictions. So far I don’t miss gv.
- jrootabega 5y agoIsn't it a shame how the world got Google Voice backwards? The savvy among us saw it as a way to present our one true phone number/identity to the world, and have options for different back end phones and services we could use. Cell phones, land lines, Hangouts, computer voicemail, all that. But the average schmoe sees Google Voice as a way to get multiple disposable numbers to sacrifice to spammers and bar hookups and commit minor fraud. So it became useless for its main purpose: being your phone identity.