7 ms·
A month ago I had a call with Twilio sales / onboarding to consider switching to them from our current IP phone provider. Ironically, I was unable to complete t
by pete5x5 4y ago
A month ago I had a call with Twilio sales / onboarding to consider switching to them from our current IP phone provider. Ironically, I was unable to complete the process because my current work number, which is IP based, would not pass their "put in your number so we can make sure you're a human" verification test because IP numbers are not supported.
I do [edit: NOT] use my personal cell number for anything for security reasons, so even after their insistence that it was safe to use I refused and therefore I was unable to get past the first step of the signup process and went with another provider. After reading this I am feeling validated that I didn't cave.
- daniel-cussen 4y agoYou mean you do not use your personal cell for those things. Good for you. Your refusal and my refusal protect one another, refusing collectively is stronger than refusing alone.
- pete5x5 4y agoGood catch, edited in the *not*. I agree, if everyone refused then it would change. I asked them what would happen if I tried to use a Twilio number to verify, but they did not seem amused by the irony.
- b112 4y agoI refuse to give my mobile number, or use my mobile number for anything. SMS auth, main contact, anything. My SMS spam is almost non-existent, compared to others. But one thing, beyond my desire to not give out my number... it is pointless regardless. When I worked in office, I had mobile access. At home, a bit rural, my access is nil via 4g/5g. I just have no access. My mobile forwards after 6 rings to my voip, so that works well. But for SMS auth? Hello! I cannot do that! I have been an ebay customer for 21, yes 21 years. I can no longer log in, as they now insist I enter a mobile number to continue. Gee thanks ebay. (No, SMS won't work via voip, they check numbers, even ported numbers) 21 years. Years of thousands, even >10k spent reliably per year. Gone as a customer. Calling paypal support, results in people literally unable to understand ... anything. They repeat a mantra off their screen without deviation. Many cuatomer support people I spoke to, were barely paying attention. I really don't get it. SMS is barely secure to begin with. They are willing to throw away accounts, just for pennies on tracking. 21 years.
- mynameisvlad 4y agovoip.ms have SMS support: https://wiki.voip.ms/article/SMS https://wiki.voip.ms/article/SMS It does say that short number support is not guaranteed, though.
- ev1 4y agoeBay and etc all ban these. It's not a "supported" issue.
- mynameisvlad 4y agoAnd you know this for a fact? Because you tried it out yourself? Right? Somehow, even though you say they ban them, I was able to submit it and get a verification message. Funny how that works, when someone just parrots the same thing without actually trying it out. Proof: https://imgur.com/a/75yKkFl https://imgur.com/a/75yKkFl
- ev1 4y agoYes. I had to close my eBay account last year. They would not take my Google Fi or non-voip.ms VOIP number. Using my VOIP number also immediately got my Twitter account banned before making a single post. It's annoying as hell because I would very much like to sell a thing or two and don't have many platform choices. > The process to close the account may take up to 30 days from this notice. eBay will send a message to the email address registered on file, confirming that the account has been closed and, unless on hold, restricted, or suspended, that data associated with the account has been deleted. I am curious if it is because they care slightly less if it's a CA VOIP number, if it came from a decent pool of numbers, or something else. Or if they will lock you out later and force you to contact the "risk assessment" team and use this as a datapoint.
- skrtskrt 4y agoSee my sibling comment about having a mobile number without a mobile phone
- kibwen 4y agoRecently I got an email receipt for event tickets that I didn't purchase. Looking at my credit card showed no transaction, so it was probably just a case of someone entering the wrong email address while checking out. The receipt happened to include a phone number, and I was about to text this person to tell them about the mistake when I realized that this would be a great way to insidiously associate an email address with a phone number. The iMessage hacks demonstrate that this would be a great vector for someone in possession of some 0days. Realistically, was I being targeted? No. But it's a sad state of affairs that I have to even think about such things. I ended up looking up the company online and finding their contact email address to let them know about the mistake, so they could contact the person directly (which they did, and thanked me).
- rndgermandude 4y agoJust ask twitter about it... They will tell you you're a bot unless you pony up a "real" phone number, and then they get breached and tell people: sorry you will get doxed now because we lost your data, but you shouldn't have used your real phone number[1]. [1] "If you operate a pseudonymous Twitter account, we understand the risks an incident like this can introduce and deeply regret that this happened. To keep your identity as veiled as possible, we recommend not adding a publicly known phone number or email address to your Twitter account." https://privacy.twitter.com/en/blog/2022/an-issue-affecting-some-anonymous-accounts https://privacy.twitter.com/en/blog/2022/an-issue-affecting-...
- rsync 4y ago"They will tell you you're a bot unless you pony up a "real" phone number ..." This is my 2FA mule: https://kozubik.com/items/2famule/ https://kozubik.com/items/2famule/ There are others like it, but this one is mine.
- Cockbrand 4y agoWhile I consider this a very elegant solution, I find it hard to justify paying $8/month for a cellphone plan because others don't do their homework.
- dylan604 4y agoYes, but because so many others don't do their homework, you have to take it upon yourself to protect yourself. $8/month does seem like a stupid fee to pay, but for those willing to do it, it isn't that much. Those kinds of companies may even have a pay for 12 months in advance and it get a lower rate.
- jamal-kumar 4y agoWhat I suggest if you have the opportunity to go anywhere south of the USA is buying a 2$ claro SIM chip and putting 2$ on it at least once every 3 months or so in order to maintain it (Can even maintain payments over the internet as long as you can understand the Spanish website). This makes the monthly cost around 66 cents a month/$7.92 a year for an SMS verification mule, and it will receive texts anywhere that has GSM band 1 without having to activate roaming or anything expensive like that.
- blfr 4y agoWhile I fully approve not using your phone, the company should issue you one, what is the security benefit of not using a personal phone? It's not really different from a company phone.
- AlotOfReading 4y agoYou can treat a company phone as adversarial (e.g. leaving it at home or on airplane mode) without impacting your normal life. An MDM solution can usually get real-time location information, not to mention potentially access other personal information. And your real number should not be associated with work things as a matter of course, in my opinion.
- Semaphor 4y ago> After reading this I am feeling validated that I didn't cave. The /r/twitch subreddit is full of people who think you should absolutely give twitch your phone number for verification (fun fact: Twitch doesn’t even allow you to turn on 2FA until you give them your phone number). Even when a few days later, twitch got their data leaked, they’ll reaffirm that you are an idiot for caring. And those are users, not even companies.
- aendruk 4y agoSimilar experience when Twilio started requiring SMS 2FA. I offered to use U2F or TOTP, but no, it must be SMS. I don’t have a work number and this is an absurd reason to get one, so we just canceled the account.
- elric 4y agoThat's strange. I have TOTP 2FA on my Twilio account. AFAIK there is no requirement for it to be SMS.
- aendruk 4y agoTwilio Support: > We're aware that some users would much rather prefer not to use SMS for 2FA usage […] this is a known issue > Please be noted that as of right now, you can only access [TOTP] after submitting a valid phone number. If possible, we'd recommend you just provide a personal phone number as a workaround I’d already borrowed a coworker’s phone once for the initial account verification, but requiring it multiple times crossed a line.
- dublinben 4y agoThey've even started requiring this for their subsidiaries, like Sendgrid. It's very offputting.