3 ms·
The more I read about phones and texting, the more I realize that they were never intended to be used as security verification. It just was not one of the desi
by Gunax 4y ago
The more I read about phones and texting, the more I realize that they were never intended to be used as security verification.
It just was not one of the design goals. My understanding of caller id is that anyone can put anything there--it was made decades ago to serve as convenience--not to verify.
Likewise with the sender id in SMS.
It's a good lesson on how protocols are hijacked. Someone thought it was a good idea to send text messages. Another person decided to leverage it for security. Ét voila, we have a security apparatus that isn't very secure.
- pwg 4y ago> it [caller id] was made decades ago to serve as convenience It was made decades ago as a profit center when the telephone network was a monopoly company operating an isolated network. Because only the monopoly phone company operated and had access to the isolated telephone network, there was no need for any authentication or verification because all caller ID data came from "themselves" and they were not going to start trying to scam themselves. It (caller id) was a profit center because when it first rolled out it cost somewhere in the range of $20 to $30 per month. The phone company was already tracking which number called which other number for billing purposes, and they found a way to monetize that tracking by allowing the call receiver a tiny sliver of visibility into their billing tracking data, all for a nice sum per month. It rolled out circa 1985 or so and factoring for inflation that $20/month fee at the time was the equivalent today of paying $54.33/month. All for data that was effectively free to the phone company because they were already tracking it for long distance billing purposes and/or for local toll purposes if one was on a "local toll plan" instead of an "unlimited" plan.