4 ms·
of course - but aren't there valid voip users out there? or should we just consider all voip users as not worth serving?
by electric_muse 1y ago
of course - but aren't there valid voip users out there? or should we just consider all voip users as not worth serving?
- toomuchtodo 1y agoI run security at a fintech, we reject voip phone numbers due to proven fraud activity. The org has made the business decision based on historical fraud data, what others do is a risk management decision. Lots of customers out there, not a lot who will leave if you reject voip numbers, in my experience. The goal is not serving as many customers as possible, it’s about operating at the intersection of risk appetite and profitability. We can’t have nice things because of humans in the aggregate. My apologies. It’s certainly not personal.
- electric_muse 1y agoI have a side project that uses Twilio. Probably going to have to face this dragon at some point and go down the same risk assessment. What values for Twilio line type intel do you block? (or equivalent values if you don't use Twilio) For example, is it just `nonFixedVoip` that should get the boot? Or are `fixedVoip` also spammy?
- toomuchtodo 1y agohttps://risk.lexisnexis.com/products/phone-intelligence https://risk.lexisnexis.com/products/phone-intelligence https://ekata.com/solutions/phone-intelligence-api/ https://ekata.com/solutions/phone-intelligence-api/
- electric_muse 1y agoThanks! I’ll look into these. Thought it was simpler lookup of metadata, but these seem like robust offerings that make sense for even more protection.
- mathiaspoint 1y agoWe'd all be better off with no phones at all.
- onetokeoverthe 1y ago[dead]
- SilverElfin 1y agoWhat if someone wants to have different phone numbers for security or privacy purposes. What options are there that wouldn’t get caught up in this?
- petralithic 1y agoThat is a vanishingly small percentage of the market that it is not worth catering to when the vast majority of such numbers are used for fraud rather than by users who want security and privacy.
- electric_muse 1y agoHard-line answers like that are why we're all building our own cages from a privacy perspective.
- robcohen 1y agoTrue, but the original sin was using phone numbers as proof of identity. The fundamental problem is average users cannot use passkeys, manage their own crypto keys, or understand that for identity to work, there cannot be an authority based recovery method. The market simply does not care, and businesses are acting accordingly and picking the lowest friction option with acceptable levels of fraud. What’s odd to me is that they dont even have a method for more advanced users to not use numbers. I think perhaps Digital Credit Union may be the only bank in the US using passkeys.
- petralithic 1y agoI have an idea, let's just use the other number we all have, perhaps the one for social benefits?
- petralithic 1y agoWho is "we all?" Most people outside of HN don't care.
- ratelimitsteve 1y agoit's a calculation - how much exposure to fraud does google voice net you, and how much additional revenue. if the math maths such that supporting google voice loses money, you don't support google voice. this idea that it somehow reflects on the value or character of voip customers in general is expanding beyond the factors that actually influence the decision.
- jas0n 1y agoSame as VPNs. Sure, there are plenty of legit reasons to use one (just line a VoIP line) but there are enough people using them for illicit reasons that companies will ban traffic.