3 ms·
"... but if I'm spending money to verify you control a number, I feel better when you (or someone else) has spent $5 ..." This is exactly it. All of these aut
by rsync 2y ago
"... but if I'm spending money to verify you control a number, I feel better when you (or someone else) has spent $5 ..."
This is exactly it.
All of these auth mechanisms that tie back to "real" phone numbers and other aspects of "real identity" are not for you - they are not for your security.
These companies have a brutal, unrelenting scam/spam problem that they have no idea how to solve and so the best they can do is just throw sand in the gears.
So, when twilio (for instance) refuses to let you 2FA with anything other than tracing back to a real mobile SIM[1] (how ironic ...) it is not to help you - it is designed to slow down abusers.
[1] The "authy" workflow is still backstopped by a mobile SIM.
- dghlsakjg 2y agohttps://www.bitsaboutmoney.com/archive/optimal-amount-of-fraud/ https://www.bitsaboutmoney.com/archive/optimal-amount-of-fra... Relevant reading. Basically comes down to: the costs of acceptable levels of fraud < the cost of eliminating all fraud. There are processes that would more or less eliminate all fraud, but they are such a pain in the ass that we just deal with the fraud instead.
- zahlman 2y ago>All of these auth mechanisms that tie back to "real" phone numbers and other aspects of "real identity" are not for you - they are not for your security. >These companies have a brutal, unrelenting scam/spam problem that they have no idea how to solve and so the best they can do is just throw sand in the gears. Sure does a great job for all the various online social media places that ostensibly have nothing to do with transacting money, still want my phone number, and still get overrun with spam and (promotion of) scams....
- toast0 2y agoIt's a whole bunch of tradeoffs; requiring a working, non-voip phone number does raise the cost for abusers, but it's not enough to make spam unprofitable. Requiring a deposit would be more direct, but administration of deposits would be a lot of work, and you have an uphill battle to convince users to pay anything, and even if they want to pay, accepting money is hard. And then after all that, some abusers will use your service to check their stolen credit cards.
- nixosbestos 2y agoOkay. So let me just pay an "application fee" or some such instead of making me jump through hoops. I don't care. I know it's a numbers game. I know they don't care about me. But companies absolutely lose my business because of this bullshit.