23 ms·
Ask HN: Why did smartphones become a single point of failure?
i can't log in to any of my banks without my phone. Most of the systems in my workplace also require phone app authentication. I can't do any of those things with just a PC or laptop. Smartphones being the smallest and portable are surely the most lost and stolen. If someone got a hold of my PC or laptop - they would be able to do some damage, but not even close to if they were able to access my phone. Everything everywhere nowadays requires some app.
- deleted 4y ago[deleted]
- jasode 4y ago>i can't log in to any of my banks without my phone. Don't know about banks in Europe but in USA, I can log into Bank Of America and JP Morgan Chase without any phone authentication. If I reformat my harddrive or buy a new computer and the bank doesn't recognize the web browser because no previous cookie has been found, the website will generate a one-time code and send it to my email address. I then enter that security code and the web browser is "recognized" without further issue. The smartphone was not needed in any step. EDIT ADD: I did open my bank accounts before 2007 and thus before the smartphone era. Because of that, there may be a possibility that my logins are "grandfathered in" to not require any smartphone app authentication. It's possible that opening new accounts today with BofA/Chase require smartphones but somebody else would have to confirm/deny that.
- Dr_ReD 4y agoIn Italy it's a disaster. You need the phone /and/ their specific app, for mostly everything. From burgers, to banks and everything in between...
- jesprenj 4y agoThe biggest bank in Slovenia also requires an app, but I wrote a webapp that implements the reverse engineered protocol the bank uses in the mobile app (the protocol is basically a TOTP implementation brought from a private company).
- NaughtyShiba 4y agoIn Europe we have it in few countries. In my case - You enter your unique ID (6 numbers), then I’ve to type 4-number PIN on my phone. There’s also verification-number shown on both sides, to compare authenticity . When approving payments, it also shows details and requires longer PIN code. Much easier than earlier versions. And authentication provider can be used at Insurancy, e-government, e-signing and other services.
- bryanrasmussen 4y agoI can log into my bank without my phone in Denmark, but they are pretty much getting rid of that capability. Supposedly more 'secure'
- Freak_NL 4y agoThat's code for 'cheaper'. Banks in the Netherlands are constantly trying to push all their customers to their apps, some (like ING) are actively trying to get rid of their alternative (but keep getting somewhat forced to offer it), and some (like BUNQ and KNAB) are 'smartphone only' from the start. Cryptographically, the idea of a discrete piece of hardware that uses the chip in your debit card to generate secure responses is fairly sound. And if smartphones didn't exist, it would be an unquestioned piece of technology that might even be commodified to the point that any such device could be used by all banks in the country. But smartphones exist, and having the customer loan the banks their hardware (which is often replaced within five years, so free updates too!) is quite attractive. No more hardware to support!
- daneel_w 4y agoMy Swedish bank offers two methods. One is the nationwide e-identification system called BankID - used for loads of commerce/governmental/identification/authentication in Sweden - which requires Internet access and works on computers as well as smartphones. The other method uses a discrete HOTP-type device (with a personalized login card) which accepts a challenge code from the bank login page and outputs a digested authentication response. As far as I know, all major banks in Sweden offer both or at least one of these two methods. In the past a lot of banks here used OTP scratch cards, and would automatically send you a new one in the mail when you used one of the 10 last codes or so on the card.
- nonamesleft 4y agoA bank in Finland: they try to push their authenticator which doesn't work on my phone (de-googleized android and too old),but they have retained the option of using an OTP code list + sms, previously it was just OTP code list, but due to some silly directives they added sms. Authenticating with bank OTP also work for government and other stuff. (Common here as there is no state authentication system other than some failed id cards afaik.)
- Ekaros 4y agoI really never got the point of the SMS. If I was deciding it I would have mandated that authentication can't be on the same device payment happens. Just to see how they solve that issue...
- duxup 4y agoSimilar experience in the US with the banks I’ve used. I can simply use the PC without involving my phone. Also if all else fails I can go in to the bank and take care of things.
- PaulDavisThe1st 4y agoI had a Chase account and for some years was able to use email for 2FA. Somewhere around 2019, they changed their requirements and forced SMS for 2FA. Since I don't use a (SIM-ed) phone and since my wife's phone number was already known to them, I had to pull all of my liquid savings out of the account and move it elsewhere. I will never bank with an institution that requires SMS for 2FA.
- jasode 4y ago> Somewhere around 2019, they changed their requirements and forced SMS for 2FA. I just logged into Chase via desktop web browser and there's not a 2FA requirement. I also deliberately used a different computer and got the familiar security prompt of "We don't recognize this device": https://imgur.com/a/jKM4MPq https://imgur.com/a/jKM4MPq I see that sending the challenge code via email is not in the list but there's an option to call them for it. It's more inconvenient but it looks like neither SMS text nor a mandatory Chase smartphone authenticator app is required.
- kome 4y agoIndeed it's incredibly stupid development. Fuck smartphones, really. I don't own one and I feel happy overall, but life is complicated because nowadays some sort of stupid app is required (most of the time, for no good reason) and dealing with those requirements always cost so much thinking. I don't want a micro-computer in my pocket, I stay at the computer all day anyway, a better one. Why can't I do with a real computer what it is possible to be done with a phone? A smartphone is just a tracking device, and it is terrible for privacy - but great for advertisers and similar industries. Otherwise, a computer should be able to do everything a smartphone does.
- rr808 4y agoMe too in my ideal world I wouldn't have a phone, but now I need for transport, food, financial services, nearly everything.
- kome 4y agoI don't know where you live, but in Europe you can still live without a smartphone. But I live in a city with good public transport (no need of ubers); banks still works without smartphone (but you need a burner phone for SMS, unfortunately), etc.
- dagw 4y ago"Europe" is big and diverse. So while there exists places in "Europe" where that is true, in many other parts of "Europe" it is getting harder and harder.
- Dr_ReD 4y agoOh, I don't know about the rest of Europe, but here in Italy you either have to deal with it, or restrict yourself oh, so very much. (to the very few services that still work without a phone). Here most everything, even state portals such as, medicare, tax, national motorists services, pensions services, etc. are nigh impossible to access without a phone. And it's so sad.
- Dr_ReD 4y ago
- NaughtyShiba 4y agoBut that’s kinda convinient [1]. The problem is, that there’s no real proper fallback/backup-plan. [1] not only it’s convinient, it’s also similar to what all the future predictions regarding technology said. Some small gadget or bracelet connecting over air and doing stuff.
- cassianoleal 4y agoThere is a backup plan. For corporate systems, contact the IT department. For banking, call the bank or go to a branch. TOTP-based schemes can be backed up and used on multiple devices. So on and so forth. It just so happens that most of these backup plans are incredibly inconvenient and might take a long time and effort to get through them.
- NaughtyShiba 4y agoSomething like that, ain’t a plan in my eyes. But yeah, what’s exactly what’s wrong with plan. God forbid you have to book appointment and arive somewhere to get it resolved…
- lotsofpulp 4y agoBecause using phone numbers to decide if human or bot is cheap, easy, and effective. Politically, there is no will for a national identity verification type service as infrastructure. And this way, all the work gets outsourced to ATT/Verizon/T-Mobile, and politicians get to say “it is not our fault” and telecoms get to say “it is not our job”.
- dusted 4y agoAnd scamming yourself to another persons phone number to entirely take over their digital life is also cheap, easy and effective.
- lotsofpulp 4y agoAnd that is a problem for a sufficiently small population that it is not yet a political priority. Crazy, since the federal government already does passports, and the infrastructure is basically in place with USPS offices.
- Spooky23 4y agoID is an issue that both extremes of the political system are against. Super conservative types are worried about mark of the beast, etc. Super progressive types are worried about folks on the margins of society being able to get ID.
- cassianoleal 4y agoYou don't need a smartphone to have and use a phone number. I suspect the OP is about smartphone app authentication.
- lotsofpulp 4y agoOh, yes, I think I misread. In that case, I guess the spam/bot reduction efforts are outsourced to Apple and Google’s App Store and mobile OSs.
- 4y ago
- sybercecurity 4y agoProbably because I've heard the statement: "Everyone has a smartphone these days, so..." for the description of every app you describe. It makes some sense: single purpose devices for authentication tend to be set aside and misplaced. So it's the union of ubiquity and ease of use.
- daneel_w 4y agoAre you saying all of these systems enforce SMS-based 2FA rather than the sane choice of TOTP? That's unwise and unfortunate.
- nicbou 4y agoMany enforce 2FA through their own app, so TOTP is not an option.
- daneel_w 4y agoIt's the same plague, whether SMS or their own homebaked authentication scheme.
- izacus 4y agoNo, they enforce through their own crappy app which only works on few platforms. To make things worse, if I install the app for my swiss bank on a different phone, I need to wait for snail mail to get the activation code.
- alsobrsp 4y agoAll my OTPs are in Bitwarden and FreeOTP. The only thing I currently need my phone for is Google's new device login and even that goes to my tablet too.
- arenaninja 4y agoCan you use Bitwarden for TOTP? I already use it for my passwords but for TOTP I have multiple apps and I hate it
- masklinn 4y agoYes. There’s an “Authenticator Key (TOTP)” field. Been there for several years. It also supports SteamGuard TOTP.
- lillecarl 4y agoBut steam really doesn't want you to get the key, I soft-failed when I tried. Fuck custom authentication apps, totp is good enough for me thanks
- subhro 4y agoYou can.
- nicoburns 4y agoYes. You have to pay for the premium version for TOTP, but it's only $10/YEAR.
- fallenhitokiri 4y agoYes you can[1]. If you want to store TOTPs together with your username and password is something you have to figure out for yourself. Browser integration works nice, but not as smooth as Apples Keychain autofill. If you go hosted you will need a premium subscription. If you are okay self hosting vaultwarden[2] supports TOTP as well. [1] https://bitwarden.com/help/authenticator-keys/ https://bitwarden.com/help/authenticator-keys/ [2] https://github.com/dani-garcia/vaultwarden https://github.com/dani-garcia/vaultwarden
- alldayeveryday 4y agoWhy did gasoline become a single point of failure in automobiles? Why did the strings on my guitar become a single point of failure? Creating redundancy for every dependency is not always practical or economical.
- cassianoleal 4y agoTerrible comparison. If you don't have gasoline you can still walk, get a cab or take the bus to wherever you're going. It's not gatekeeping anything, it's just a convenience. Strings on your guitar can be readily replaced, and again, it's not gatekeeping you from your finances or your employment (unless you're a musician, but in this case I'm sure you'll have spare strings and instruments so that if one breaks you can carry on without much thought).
- alldayeveryday 4y ago> If you don't have gasoline you can still walk, get a cab or take the bus to wherever you're going. Not all of us live in an area where those options are available. But I can transport your arguments back to the OP post. You can still call your bank from someone else's phone. You can still walk into a bank branch or use an ATM. Using their website is just a convenience. If you lose your phone you can just get a new one and carry on without thought (replace it).
- Double_a_92 4y agoIf you don't have you banks app, you can still go to the actual bank and tell them to do your transactions.
- Dr_ReD 4y agoThat's not so easy nowadays. Firstly with covid-19 many banks don't accept walk-ins and have a long waiting list for appointments. Secondly, what if the bank or other service i'm using has no physical offices at all? Or what if they're simply too far away and I'm an octogenarian, perhaps with no driving license? Eh? Am I supposed to take an uber to somewhere 100/200 miles away just because morons are given decision-making power and myopic online-apologists on HN even make excuses for them?
- nicbou 4y agoThis is a big problem for me as a traveller. If I travel long distance and I lose my phone, I lose access to both my personal and business bank. I once dropped my phone in a lake (I'm clumsy) and was locked out of most things for a few weeks. I prefer TOTP for most things. Keepass supports them across platforms, but Aegis has a better experience on mobiles.
- kovacs_x 4y agoThe eSim's are available these days so you don't have to wait for new SIM to arrive... if your provider & phone supports this feature.
- dataflow 4y agoDon't eSIMs have an even worse failure mode? If the phone itself dies then there's no SIM for you to take out and put into a new phone immediately right? As I understand it you have to first find another phone (with a working line!) to call your provider with, hope that it's within their business hours, and wait on hold for who knows how long, until you finally get it set up? Because of course you don't have anything urgent you need to take care of in the meantime while you wait for your carrier to give you back the keys to your digital life right?
- loyukfai 4y agoPhone companies don't let you apply for replacement esim through a website?
- deleted 4y ago[deleted]
- dataflow 4y agoMaybe some do? I've seen ones that don't.
- withinboredom 4y ago
- dsr_ 4y agoGo through the whole list and figure out which of these services really requires your phone, and which you have set up on your phone because that seemed the easiest path. Tell your workplace you're about to switch from carrying a phone to a landline: what is their fallback option? (It's about 50/50 whether they have one, but they definitely should.)
- ulfw 4y agoWhy should they have a landline fallback?
- orev 4y agoBecause in Operations you need to cover all the scenarios, regardless of what the Developers think is the “only way” to do something.
- adamjb 4y agoMy workplace's solution was to simply turn off 2FA for my account
- theandrewbailey 4y agoGood 2 factor auth systems will provide the option to be called on the number on your account.
- Spooky23 4y agoPhone isn’t a secure factor in 2022.
- BLKNSLVR 4y agoIf this is due to the vulnerabilities in the SS7 protocol, then it hasn't been secure since 1975. Or at least 2008 when a set of vulnerabilities were published. https://en.m.wikipedia.org/wiki/Signalling_System_No._7 https://en.m.wikipedia.org/wiki/Signalling_System_No._7
- beebeepka 4y agoI hate it. They have been phasing out web for years in the EU. Banks mostly but these days employers too. Getting a separate device, or multiple, seems like the least horrible options to me. Turns out everyone wants a piece of my data I in the name of convenience. Only, it's their convenience, not mine.
- kome 4y ago"They have been phasing out web for years in the EU." This is such a perfect summary of the situation; thank you for formulating it so clearly. To me is insane that we are switching to a perfectly open and interoperable standard to the walled gardens of iOS and Androids.
- fsflover 4y agoThis is why I ordered both GNU/Linux phones, Librem 5 and Pinephone, to support the alternative. Of course, I have problems with the apps now, and I refuse to install them as much as possible. Every time someone tells me about an app, I'm asking whether they have an app for my Linux smartphone.
- throwaway787544 4y agoI use Google Voice, and the number that I use for PINs I can login to with just a password. That way I can always access text messages even if my phone is gone. You need it when traveling and your shit gets jacked. I haven't tried it but an Android emulator should allow you to use apps without a smartphone.
- nisegami 4y ago>I can login to with just a password If you can, so can anyone. Although using a unique/rare password (globally, not just among your accounts) is probably enough to make this a non-issue.
- whywhywhywhy 4y agoIf the banking software lets you log in via an Android emulator I'd say it's a pretty badly written piece of banking software. I understand why HN readers would want to maybe use an emulator to avoid having a phone but really what other use case is there than that or a scammer trying to spoof you.
- Jaruzel 4y agoIs running an app inside an Android Emulator (i.e. the ones that come with Android Studio) something the app can detect then ?
- Dr_ReD 4y agoSome apps will. But most "secure" apps would refuse to run on the virtual device.
- cube00 4y ago> I can login to with just a password You're logging in with a Google Account and when the account gets locked it's game over with no chance of appeal. https://news.ycombinator.com/item?id=31070914 https://news.ycombinator.com/item?id=31070914
- throwaway787544 4y ago
- blfr 4y agoOnly banks do that. All other services accept TOTP (which you can have on multiple devices) or YubiKeys/webauthn/U2F (where you can add multiple hardware keys). And even here, my bank accepts two (or more) devices with an active instance of their app. So the solution to this spof is the same as always: redundancy. You need a second phone. Your old one is probably good enough.
- gommm 4y agoI've never seen a bank accepting more than a single device with an active instance of their app.. I would be over the moon if they did but they don't. So, last time I broke my phone, it took quite a while to get access to my bank accounts again.
- blfr 4y agoMy bank (Polish mBank) even have a section in the webUI to manage these devices along with other access channels.
- dont__panic 4y ago> Your old one is probably good enough. Some of us use the same phone for years, until it loses OS/security updates. My current phone is 6 years old. By the time I upgrade, my current phone will not be able to run current authenticator or bank apps, which will target an iOS version above the last one supported by my phone. So no, my old one is not "good enough" unless I upgrade more often than I'm comfortable with.
- deleted 4y ago[deleted]
- blfr 4y agoFunnily enough, I just had a meeting with a client asking why they would need two (and then likely more) servers doing the very same thing. Wouldn't that increase the price? Well, yeah.
- megraf 4y agoI don't have the same view, in my mind you have created a single point of failure for _yourself_. I use Authy for MFA, which comes with a desktop app. Phones dead / missing? No problem, I can get OTP's from my laptop. What about text messages? Google voice. Which of course has a desktop interface. I've been doing this for years. It's nice not to have to rely on a watch, or phone entirely - although they do make my life easier.
- noSyncCloud 4y ago>Google Voice Anecdotally, my bank (Wells Fargo) will not accept VOIP numbers for 2FA.
- Spooky23 4y agoYup. Chase does the same thing. They blackhole SMS to Google voice.
- mindslight 4y agoYet another push to get a better bank, in addition to all their ridiculous fees. Ally blackholes Gvoice (messages just disappear), but gives you an email option to login. When calling customer service, they can do the challenge with a phone call rather than SMS. Capital One, Discover, and Alliant all seem to accept Gvoice just fine. There of course is a major problem that Gvoice seems to be special, in that many places will accept Gvoice but not standards-based VOIP competitors. I even had a problem with someone on "Comcast mobile" not being able to text a Voip.ms number of mine.
- 1123581321 4y agoProbably Comcast Voice. Comcast/Xfinity Mobile is a Verizon MVNO
- Spooky23 4y agoOh agreed, Chase is an awful bank in any dimension. I use a credit union for most things. Chase owns the Amazon card, and 5% rebates on Amazon are worth dealing with the drama.
- throwaway98797 4y agoif only that was a way to prove who you are through some kind of system oh I don’t know like private/ public key infrastructure that works well in crypto solutions are clear
- dogleash 4y agoNobody knows how to do a failure analysis. I used to work in r&d, now that I’m building websites and mobile apps the culture doesn’t care. Pointing out obvious design limitations will, more often that not, make me the asshole. Not even trying to delay ship or get future rework scheduled, just having it documented is too much. Out of sight out of mind.
- Dr_ReD 4y agoIt's not that they don't know how to. It's that there's an economic incentive to not care. So they don't.
- pif 4y agoExactly, and the incentive is that customers do not care. Build quality, keep redundancy, and in the next pandemic your business will flourish... unless you'll have had to close it before 'cause of people buying cheap and not good!
- falcolas 4y agoI assert that customers do care. Customers were quite annoyed that they couldn't buy vehicles, regardless of the price. Or do you just not remember the complaints? On the business side, Toyota - the progenator of JIT manufacturing who still warehoused chips to deal with a shortage exactly like what happened - flourished at a time where others floundered. As an added bonus, they were still able to remain profitable prior to the shortage, despite having warehoused chips. I think the "buy cheap not good" is more of a proactive excuse from companies who want to sell cheap goods to maximize their profit. Kind of an extension of the "never ask customers what they want, they'd just want better horses" or "they can have it in any color so long as it's black" tropes.
- pif 4y ago> I assert that customers do care. Customers were quite annoyed that they couldn't buy vehicles This is not what I meant. Customers did not care, before the pandemic.
- BoredPuffin 4y ago
- pdntspa 4y agoDude, what? How many services require SMS 2FA again? Your phone is indeed a SPOF. If you lose your phone, you're fucked in a variety of scenarios. To say nothing of services that require a custom app and accept nothing else.
- Dr_ReD 4y agoYep! I have all of the things above (yubikeys, many PCs, a couple voip numbers with SMS, ability to emulate Android on PC, a host of old smarphones...) still, if I lose the one smartphone on which -that- custom app is installed, I'm hosed. And I can't even install the app on a second phone, because: ah, ha! Only one at a time! There is no installing two, Luke. Only one there will be. (There you go... quotation inception.)
- BoredPuffin 4y agoThanks for addressing me as "Dude" and using the f-word! 1. OP is asking smartphone; SMS 2FA does not require a "smartphone", but "mobile phone". 2. Alternative options mentioned above should you be in the misfortune of losing your... "phone"
- Dr_ReD 4y ago> Thanks for addressing me as "Dude" and using the f-word! Sensitive, ha? > 1. OP is asking smartphone; SMS 2FA does not require a "smartphone", but "mobile phone". Nitpicking and strawman argument. They're both part of, and compounding, the same problem. > 2. Alternative options mentioned above should you be in the misfortune of losing your... "phone" Sure they "should", but they're often not offered... even if you insist. And more often than not, the alternative options available take weeks of phone calls and visits to the local (if you're lucky to have one) branch office of your /whatever service failed you/.
- pdntspa 4y ago
- rodolphoarruda 4y agoThis has been my point for the last 5 or 10 years. That's why I have a "home phone" with banking apps, 2FA and important stuff installed. It has no SIM card and never leaves home. For everything else I have my "street phone".
- closewith 4y agoMany banking apps require a phone number/SIM card to operate, but assuming you can copy codes, etc, what happens when you want to use those apps out and about (or abroad) if the phone never leaves home?
- Dr_ReD 4y agoThis too... :(
- rodolphoarruda 4y ago> when you want to use those apps out and about Fortunately, my lifestyle places me out of that use case.
- Dr_ReD 4y agoYes, but then again, I'm looking at seven older smartphones —right now— on my desk, and only one is even capable of running /all/ those apps. I had to buy it just because of that. 'cause even my Huawei P-Smart 2021 (currently in my pocket and not among the others on my desk) can't run some of those pesky apps.
- tiborsaas 4y agoWhat if you go on a vacation?
- rodolphoarruda 4y agoI can use my credit card.
- coffee33go 4y agoThen change the bank you deal with. At least in EU, this 2FA was due to PSD. Please also note that any changes will impact some people. How often do you lose your smartphone? If every month then it is sad. You need to find a bank that still uses cheques etc. No point in whinging. If something works for 90 % people then get used to it. For example, I did not like joining facebook for my children's school nor whatsapp groups but did it as most of them did it.
- pipeline_peak 4y agoPart of the point he's trying to make is that eventually there probably won't be a bank that isn't like this.
- activitat 4y agoDid not world survive the ATM, pin, card revolution? Yes. Did 100% population like them. No. Did people lose cards ? Yes. Yet we are here.
- pipeline_peak 4y agoA phone is a lot more than an ATM or a plastic card. Some people don't want an expensive device that tracks you, potentially sucks you into distractions, and just flat out has a lot of undesired complexity. You shouldn't need one to do basic finances. Also ATM's and credit cards didn't replace traditional methods, they're modern alternatives.
- Dr_ReD 4y agoFurthermore a phone is the single one thing whose loss will cut you out of tens of services —at best—. Cards are one-per-service. So if lose one, you lose access to one service. Cards, you don't take 'em out of your wallet unless you have to use 'em. Your wallet too, you don't leave it out on the table all the time while eating. You don't take it out willy nilly to take selfies and panoramas, or to check the stupid notifications that you get every 3 seconds. And when you do, it's only because you have to do wallet-y things, which you do —carefully—, perhaps even looking out for possible pickpockets and thieves. All of the above don't need to be charged twice a day... in fact, not at all... and will still work as new, after a trip into the toilet, a drop from any height, a full blown stampede, or even a few cycles in the washing machine. Your phone? Not so much. And those slabs of glass and metal are often eye watering expensive. Enough to be more interesting to a thief, than even your wallet... All this, while we're continuously waving them around, in front of everybody... So, do you really need to know how may times people "lose" their phones nowadays?
- douglee650 4y agoIt’s a physical device with access control that is unique to a single human, three nines
- yokoprime 4y agoNot true at all. If they are able to log into your e-mail, then things will start to fall apart. But just getting your phone will not allow anyone to break into your MFA secured accounts. Your phone is something you own, but they still need something you know (i.e. your password). I feel like you might get a more nuanced perspective by looking into security related topics, specifically around authentication.
- actually_a_dog 4y agoThe "nuanced perspective" here is that regular people don't use MFA authenticator apps. They use SMS 2FA, if anything. Once you accept that, you're right back to "smartphones as a SPOF."
- rjh29 4y agoPhones are encrypted and protected by a lock screen, or am I being naive?
- game-of-throws 4y agoI'd bet almost everyone is logged into email on their phone. If you can trigger a password reset over email, and can access the 2FA (SMS or TOTP app), you can get into just about anything.
- aikinai 4y agoWhat country are you in? I’ve lived in a few, and I don’t have any services that require my phone. Many have two-factor auth, but I just save the keys in my password manager which I can access from any of my devices.
- f6v 4y agoIt’s a trade-off. It’s very convenient for me to pay with ApplePay. But there’s a risk I won’t be able to pay for groceries if my iPhone is out of juice.
- jerryzh 4y agoBecause it is indeed the thing every one carries almost all the time. Can you do these things without your passport/ID/driving license before smartphone appears?
- Dr_ReD 4y agoWe've been perfectly able to do all of the above, for at least a couple of decades, using any computer and even smartphones of our choosing, until they started forcing those stupid phone-apps down our throat, as if we where in a galaxy far, far away and... "This is the way!"
- discreditable 4y agoNext time you upgrade, keep the old phone. Have both phones set up so they can do mfa. If you are doing OTP, make sure to use an app that allows you to backup/export. AndOTP is very good if you're an Android guy.
- durnygbur 4y ago> i can't log in to any of my banks without my phone Glad it's not only my problem. Force banks to support TOTP. They will not do it voluntarily, they have too many "experts" selling dedicated app to the managements because "securitay".
- lajosbacs 4y agoI have two smartphones for 2FA, one never leaves the house. But it would still losing one while traveling.
- fsflover 4y agohttps://news.ycombinator.com/item?id=32397332 https://news.ycombinator.com/item?id=32397332
- unreal37 4y agoSo let's say you change phone numbers and FORGET to change one of the important websites that use that number for authentication? Or you change phones, wiping the old one before selling it to your friend and setting up the new one from scratch? Some websites are terrible/impossible at letting you recover your account when you've lost access to the phone number or the exact instance of the phone used for authentication.
- fuckcensorship 4y agoThis is why I stopped using authenticator apps tied to my phone and started using Bitwarden’s TOTP feature.
- BLKNSLVR 4y agoI always have a backup Android device setup as per my standard operating environment for this very reason. I'm actually due to setup another one as my previous backup went to my daughter for her birthday recently (but it still has my SOE hidden on it). But also, I don't use my phone for banking because I still don't trust mobile ecosystems. I use a dedicated VM that requires a decryption password to boot up. But yeah, banks are pushing for app usage rather than web interface, which is ironic given that my bank still only has SMS 2FA, not token-based. So why would I trust their app to be anywhere near secure in an insecure ecosystem if they can't even support proper multi-factor authentication that's been standard for, what, 5 years already?
- _int3_ 4y agoSomeone , somewhere decided: your digital life is going to be tracked and recorded to 3rd party cloud. (We are increasingly getting to that point) To accomplish that you were given central device ( a smartphone ) on which you ought to do everything related to your digital life. So how to remedy this? Easy, just don't do that.
- hypertele-Xii 4y agoYour choice of banks. I still have my bank's physical code-slip and can sign in using it just fine. My fiance's bank provided her with a small, calculator-looking battery-powered code device.
- RockyMcNuts 4y agoit's crazy when museums don't give out paper maps and expect you to use your smartphone - https://twitter.com/austinkleon/status/1556466475354963968 https://twitter.com/austinkleon/status/1556466475354963968 there are old folks who aren't that tech-savvy, and smartphones + plans are not that cheap or free in the US, we still have some extreme poverty, penetration is not 100%, if you're going to make smartphone a requirement to participate in society there really need to be super-cheap smartphone options.
- jjk166 4y agoThere are low end phone plans in the range of $10-15/mo. You can get a prepaid smartphone for like $40, and if you aren't using cellular data, you can get the smartphone itself for around $20.
- sockaddr 4y agoYeah, so I can wait in the lobby for 17 minutes while some 1.8 star museum app downloads to my phone over a crappy network that my provider lied about the performance of instead of someone just handing me a paper map.
- jjk166 4y agoOr you use wifi like a normal person. We call them phones because that's what they evolved from but smartphones are fully functional computers that we can use anywhere with ease, and using cellular data to make phone calls is only one small facet of their usage. For the overwhelming majority of people, being able to just pull up a map on their phone is the more convenient and preferred option. "Just handing you a paper map" is not so simple when you don't have paper maps because getting custom paper maps printed is expensive.
- bdougherty 4y agoAmusement parks are doing this now too and it's even crazier because many of them will not allow you to have your phone anywhere on your person while on the rides.
- miav 4y agoI haven't lost my phone yet, but it's only a matter of time before I get unlucky enough. I'm prepared for it by using ProtonMail for my main email with (strong, memorized) password only, no 2FA and Starling for my bank, which allows you to log in with password + video of yourself.
- achow 4y agoDoesn't 2FA include emails? I always get my OTP verification codes (banking, corp login etc.) both on mobile and at my email id.
- theonemind 4y agoI didn't have a cell phone until work issued me one around 2018 or so. (I never really liked the idea.) Generally, I don't have many single points of failure tied to the phone not tied to work...certainly nothing related to my banking. You can still live in 2022 without one, although the assumption that you have one gets more annoyingly entrenched year-by-year. I don't quite know what these single points of failure are, but they must tend not to exist when you have a "hard no--I have no such device" in your back pocket...you can choose services that don't require it, use hardware token 2FA, or something. Somehow, it does still work out to simply not have one, but it seems hard to avoid reliance on it once you've got it, since you don't see a service and think "well, I guess I just can't sign up for that one", but instead whip out the cell phone and comply.
- didip 4y agoHow is this possible? Are you from an older generation? Do you live so far away from the city?
- dsr_ 4y agoHow is this possible? It's easy. Let's pretend you have a smartphone and a computer. Take the phone, and look at every application that you actually use. Make sure that application can be used on a web browser and you have the credentials stored in a password manager. Transfer your cell number to a VOIP service. Find your carrier and cancel your contract or autopay or whatever. Now shut off the phone, and leave it in a drawer. If you can take out the battery, that's good, but you probably can't without breaking the case. Put some cash in your pocket if you weren't in the habit of doing that before. That's it, you're done. Remember to check your mail and messages on the VOIP line from time to time. If you ask the VOIP people to send voice mail to email, that makes it just one thing to check.
- Dr_ReD 4y agoThen you discover your bank, your credit card, your shopping mall, watsapp, gmail, facebook and grinder, all have blacklisted sms to VOIP numbers and also, they're phasing out SMS support anyway... So you'll need all their own specific apps anyway... And both your neighbourhood burger king or the whole airport in which you just landed, won't let you order food without a phone, an app and a qr-code... And then you live in Italy where you can't ever buy stuff over 1000€ with cash... And where you need an app to access the nation's many exclusively online services. No. You can't avoid it. All you can do, with this kind of passive resistance, is delay it for a bit. :/ We (the people) need to push back and be vocal about the stupidity of this trend.
- pessimizer 4y agoBecause they're the thing in your life that you have the least control over. Businesses and governments can lower all kinds of costs by using your phone to manage you. If kings had the ability to distribute smartphones when feudalism was in full swing, feudalism never would have ended. They watch you while you watch them, and there's nothing you can do about it. What I really wonder is whether we're 10 years away from police being dispatched if your phone is turned off (which, of course, would have started as opt-in, and ended as getting a ticket for letting your battery die), if we're 50 years away, or if there will be some sort of Butlerian Jihad before it happens. edit: we can pretend this is just about authentication, but the reason smartphones work for authentication is because you have no control over them. If you root your phone, it becomes useless for authentication.
- winternett 4y agoYour phone is leveraged so much because it provides companies with deeper tracking capabilities. Most laptops and PCs only geo locate based on their connection points, phones have accelerometers and more accurate location and ID info in them, so many app makers hobble browser-based app iterations to encourage mostly phone use. They also know users are engaged and focused on content more when they are on phones because browsing in multiple tabs is less possible than on desktop PCs. It's ridiculous that we are manipulated in this way, but fandom for certain devices and apps has created powerful companies that dictate how the Internet works, rather than a better world where companies work to provide value and function to consumers first. The customer is no longer right, whatever the company dictates is what is right now, unfortunately so for us.
- freshhawk 4y agoDon't forget your phone is much more deeply tied to your identity through your cell company contract and the OS account information is more likely to be closely tied to your identity. It's also much rarer for someone to have multiple phones and the need to detect that connection. So there are deeper tracking capabilities and it is easier to connect that tracking data with an official person in order to cross-reference.
- s1artibartfast 4y agoFor reddit- sure, but why banks? Surely managing hundreds of thousands of my money is worth more than some geo data.
- Hackbraten 4y agoBanks are in the smartphone game for a few more reasons other than tracking: 1. They tend to trust a locked-down, reasonably secured environment more than a hackable, general-purpose operating system, especially for 2FA. 2. They’re under pressure from fintech, so they have to focus more on things customers want.
- winternett 4y agoThey could be using it to verify your phone number is being spoofed overseas. If location data on your device indicates you are currently in Texas, but suddenly a charge is made originating in Malaysia, it would trigger an alert based on a geo-location mis-match... They can also use it against you to find out where you go when you are paying in just cash, or for other nosy reasons. That's why the overreach is bad. When you consider other companies in insurance, the IRS, THE ENTIRE HEALTH CARE INDUSTRY, and even CVS tracking you through apps, the harmful secret data they could compile on us to better fleece and police us is potentially outrageous.
- jolmg 4y ago> i can't log in to any of my banks without my phone. What country is this? Are you sure they're not just heavily pushing for the use of the apps while still having an alternative? What happens if when you open an account you tell them that you have neither an Android nor Apple phone? There's probably still plenty of options for such phones, and it's hard to think they'd refuse to open an account unless you buy a phone of their choice.
- deleted 4y ago[deleted]
- Helikentio 4y agoI have a few yubikeys. I have a folder with recovery codes. I have a fully encrypted phone. I can afford a cheap backup phone. I never felt as secure as I do currently. Partially thanks to Google and the effort they put in 2fa. I'm happy to have that than needing to drive to my bank for a paper printout.
- 2-718-281-828 4y agoThat's why I have three phones fully set up (two would be sufficient, but I just happen to have an iPhone and two OPs). Technically you can also set up an additional Authenticator on your computer. But my bank authorization are either app based or phone number dependent - so one main phone featuring both and additional phone having the app set up. I don't like it either.
- malepoon 4y agoThis is why I love (WebAuthn) security keys: it's completely separate from your phone (and easy to register a second/third key as backup for in a safe location) so you eliminate this whole class of issues.
- jesprenj 4y agoI had a similar problem very recently with OVH. Though it's not related to smartphones. I migrated my personal domain (nameserver and email) to a different IP address. After migrating the server, I wanted to change the glue record on OVH.ie. They detected some suspicious activity and prompted me to enter the code that was sent to my email, email on the domain that has unreachable namesevers because I couldn't log in to their dashboard. I had no 2FA enabled. The interesting part about this is that I knew it might cause problems, so I also added a secondary email address to OVH, the one from our national academic research network. But OVH only sends codes to the primary mail! How useful ...
- emj 4y ago> only sends codes to the primary mail One should be able to login with multiple methods. E.g. with 2FA you should always be able to connect two devices, and if you choose to login with a third party like Google/Facebook you should be able to add a password for login as well.
- waspight 4y agoHow do I backup all my 2fa that I have on my phone? I would like to have a backup at home in case of the phone being stolen.
- in9 4y agoAlso interested in this. In Brazil, whenever you get your phone stolen, the robbers will screw you over by getting access to accounts and issuing pre approved loans to other accounts. I'd love for my 2FA to be tied elsewhere instead of the same device where I do transactions.
- DarkwingDuckFan 4y agoAsk your bank and other to give you a different way for authentication. You will get a other tool for that. There are serval hardware-authenticators and other tools out there and each bank or service offers this to you. Its yourself who create this single point of failure. I have a second (old) phone at home, ready for reactivation if needed. I am teaching my kids to not use the same Mailadress / mobile number for each service and to be sure to have a good backup for really important accounts (really important for my kid means: for Steam and other games). Try to find different way to get the authentication. They exist. The only disadvantage is: you have to ask and it isn't as simple as an mobile.
- EVa5I7bHFq9mnYK 4y agoI have a virtual phone number to receive SMS from all my banks and other services. Funny thing, their phone app doesn't work reliably, but their Windows app does. So I use desktop to log into all my accounts. If I lose both phone and notebook, it's easy to recover, I only need virtual phone username and password.
- unethical_ban 4y agoI agree, mostly because of the lack of self-managed MFA mobility. The ideal situation is for a site using 2FA to allow me to choose the 2FA application: Google Authenticator, Authy, OneAuth(I think), etc. Tools like Okta Verify, RSA, Symantec, or SMS based 2FA make the phone a true SPOF. You can't have backup codes, you can't migrate installations. In other words, I hate forcing my phone to be an irreplaceable hard token lest I drop it in the river and have to do a bunch of resets.
- seydor 4y agoIt's a temporary phase, next generation phones will be surgically implanted under the skin so no fear of ever losing them.
- AnimalMuppet 4y agoNo. An attacker could still, um, hack people (in a very literal way). Once you've stolen their implant, who knows what would be possible?
- SergeAx 4y agoIt is not a smartphone, it is your phone number most of the time. It is binded to the SIM-card. You may switch the card to another smartphone if yours is broken, or order a replacement SIM-card of you lost it. The latter is done by your cell provider with your identity confirmation.
- wizofaus 4y agoI'm definitely not a fan of forcing anyone to use their (personal) phone for MFA for accessing company resources - I wouldn't really consider it a single point of failure though unless it was so poorly set up that there was literally no alternative log in method in the case of a lost/forgotten/broken phone. And if that happens it's the company's loss not mine - yes I enjoy my work and don't like letting my team members down but I can happily find other things to do if I can't access the systems I need to work (and they're going to pay me either way).
- travisporter 4y agoOthers have brought up 2FA. I've been looking for a simple (RSA SecurID FOB style) display device that only provides OTP codes. Does such a thing exist? I'm not even above buying a dozen of those old FOBs if it gets the job done
- eternityforest 4y agoThey're more reliable than any other affordable device capable of filling thr "Your whole life in a box, I've ever seen, at least subjectively. Nearly no moving parts(The few remaining ones seem to be the #1 failure mode), a general purpose OS that's truly designed for what it does, etc. On top of that, they have some built in safety features like the ability to remotely disable, wipe, and track them, plus, normal bank transactions can be reversed. I would much rather have a phone-linked account than go back to cash, and people used to carry that all the time. Plus, for all the horror screen addiction causes, it does make losing your phone less likely, because you notice fast. And on top of that, we used to (and still do) have MANY single points of failure ranging from debit card to notebook with meeting notes that could get you fired if you lose it to cash to house keys, any individual one of which could, if lost at the wrong time, cause a similar scale of damage to a lost phone, sometimes more. Now, if you lose your credit card, you use your phone to disable it. If you lose your keys, you use your phone to uber. If you leave your wallet at home, you sign up for Kroger pay while standing in line, using the card number you stored in a notes file for exactly that kind of thing(true story). It might slightly increase the risk of some pretty big disasters for some people, but for most of us, I think overall it removes a lot of common failure modes from life, so we accept the downsides.
- deleted 4y ago[deleted]
- simonblack 4y agoi can't log in to any of my banks without my phone. Check with your bank. Most banks have another capability of verifying who you are on login. That usually consists of a random-number generator that is in lockstep with a similar one within the bank's system. The random-number supplied by your 'token' should be the same as the one generated by the bank that is associated with your account or login. We have three of these. One for each of the banks we deal with. https://pic.pimg.tw/abcwithyou/1348639177-1831387207.jpg https://pic.pimg.tw/abcwithyou/1348639177-1831387207.jpg We don't use any of the bank smartphone apps. I dislike intensely trying to do broadsheet work on tiny phone screens. It's akin to trying to do 'keyhole surgery'. I much prefer my 3840x2160 view and at a non-microscopic scale on my computer screen.
- childintime 4y agoBy chance I saw this: https://support.google.com/fi/answer/6330195?hl=en It allows the data to be used on a second device, on the same SIM/number. Not SMS though, so this is going to be a limited solution. I also don't know how this works across the globe.