The amount of cruft involved in SMS delivery is unbelievable, and phone numbers are neither particularly stable, nor particularly well protected against takeovers.
The amount of cruft involved in SMS delivery is unbelievable, and phone numbers are neither particularly stable, nor particularly well protected against takeovers.
This can work against you of course, so a good strategy is to get a burner phone and port that number to your VoIP provider.
https://www.npac.com/canadian-number-portability/the-npac-ne...
Would love to know how to maintain a US SMS presence without sketchy obviously for spammers products.
Canadian telcos are basically a scam (and Virgin is now my top hated one, assholes).
2FA using phone numbers is idiotic.
I think in the end she put one of the numbers down in the application after a little pursuasion.
Mentioned this to a friend who works at Google on their messaging products. His take: "Yup. It's a mess"
I also have to wonder how Google Voice has survived Google's ax all these years.
The infinite surveillance capacity of an monitored voice line?
Millennia of training data for AI speech synthesis and recognition?
After porting a second number into Google Voice (and involving Google Fi) I lost access to the first. A 50+ year old phone number that everyone important to me already had memorized.
If you call the number now, it’s answered by a Google voice subscriber message. So I know the number is still with Google. I just can’t access it anymore.
I'll be here all week.
Also relying on something from a commercial entity that's so easy to fake is weird.
There's this weird thing that de facto you need state residency and a permanent address to live "normally," have government ID, etc. but there's not AFAIK any actual specific legal requirement to have same.
Instagram and Facebook will quickly disable your account and demand a real phone number. I recently had a delivery app inform me at signup that it's not even a real phone number (it happily slurped up the submitted Voice number and later sent me ads about pizza anyway)
But that doesn’t work for 2FA. I ended up locked out of my online banking accounts for my whole trip and it was a huge headache. My recommendation would be to port your number over to Google Fi and then just use that in whatever country you’re going to. It’s a bit more expensive that local cell service in many countries, but there’s nothing like having your phone just work wherever you go.
Start from first principles, what do we really need to know about a person? What could we build? On the other hand, maybe if it's too good it'll be bad for privacy, and escaping into the shadows, should that become necessary for someone.
I'm not necessarily saying this is a good idea. It's just an interesting potential solution.
I've paid the $20 Google charges to make a number "permanent" once for myself and a couple of times for organizations.
For myself, it's a highly secure phone number. I still only use a phone number when I absolutely have to, like with Twitter, preferring to use a hardware key or Authy.
For organizations, it's like an answering machine. My kids' soccer club had a cell phone that was supposed to be answered by the VP when parents or coaches had messages. It was much easier to port the number into Google Voice, put it into Do Not Disturb mode permanently, and have the transcriptions forwarded to the VP on the extremely rare occasions that there were any.
I'm not paying $450/month to roam...
That's cheap. My Austrian provider charges 1 Euro per 100 KB when roaming in Canada (no - that's not a typo). So for 10 GB that's a cheap 100k Euros.
I currently have plan for 22€ that gives me unlimited everything in my country (maybe there is cap to minutes but I don't call much) including unlimited data + 10gb data in EU.
I remember that in Canada I was paying through the nose for some basic pathetic plan though.
- SMS delivery is not always very reliable when roaming.
- Prepaid SIMs usually expire after a while of not topping them up.
- Good luck losing one of these SIMs and getting a replacement abroad. (eSIMs make this both better and worse.)
Never had missed SMS while roaming and I don't use prepaid as primary number. Have had same number for 20 years now.
There is a guide or something to help you with that?
I know that is just a simple task, but it is a really long chain of stuff to do and prevent yourself being at the other side of your services
My best advice is to find alternatives and don't depend on anything that depends on a phone number. Things can ALWAYS turn wrong.
Should be obvious but you will lose your phone service, so you want to time it close to when you are leaving.
So for me 2fa is pretty much the only thing I still use SMS for. Which makes a suspicious sms stand out a lot more.
I wish we'd stop using it for 2fa though because it was never meant to be hardened for this.
What happened was that the networks were capitalising on that. SMS was historically quite expensive so it became a big cash cow. SMS bits must have been made of gold because they were hundreds of times more expensive than other bits.
WhatsApp completely killed SMS usage here however. Leading to some carriers wanting to charge extra for WhatsApp usage to recuperate some of the 'lost' revenue. This sparked a big discussion about net neutrality which was then enshrined in EU law, so the discussion was finished. By this time, SMS became practically free but it was too late.
This is only partially true. There are also countries like France where WhatsApp only has a Market share of about 22%. Switzerland is very split too, I personally know more people using signal or telegram than 'still using' WhatsApp.
Most people I know use WhatsApp (I refuse, and since I run Lineage OS without Google services I simply tell people my phone doesn't support it), Signal, or Telegram.
Reality is if you ask someone 'do you have whatsapp' or just message them a lot more than 22% will have WhatsApp in a way or another I guess. Buts it's not what they choose if someone asks which app they prefer.
Just as nearly everyone I know has telegram but I highly doubt it's their main way of communicating for most.
One of the things I like about it is group messaging. The seamless images/files, the encryptuon...
And I don't think most mainstream users feel this as a lockin. After all whatever phone they can buy they can install whatsapp on it (and soon even import their hitory!).
Personally I prefer Matrix. Not a fan of Signal either due to the ban on 3rd party apps.
At least Germany and Austria heavily rely on SMS-OTP for all kinds of services, banking and otherwise. I've never received an OTP via WhatsApp.
Austria even has an eIDAS-compatible e-signature scheme based on SMS-OTP that allows people to create a legally binding PDF signature using SMS-OTP and a static password...
SMS is actually easier, with email I have to go into the outlook app.
I was of course in a different country in Europe. Since it’s a mini-continent and all that.
Ironically, my email inbox is much better protected than my SIM/phone number.
That said, my phone number is significantly easier to take over than my email address and mailbox.
By forcing the users to validate with a phone number, they're essentially pushing their spam problems upstream and out of their hands. More sophisticated actors know it's possible to automate SMS verification, but it does stop a lot of spam at the door.
Google does this very well: They require a phone number of spam account creation prevention – once. After that, I can delete the phone number from my account and use a FIDO key, TOTP or any other 2FA method.
Uber's screw-up has given Lyft a few thousand dollars.
Come up with a good alternative and make yourself a billionaire.
Difficulty: Good alternative.
Not as simple: stuff arrive in the spam folder. Some providers just reject your valid mail (my main email tld is exotic, it causes lots of troubles). People receive so much junk they lose your message in 1000 of unread mails or are afraid of checking them.
Not as interoperable: there are new kids that just don't have emails setup on their phone. They check them once a month at home on the computer. Email is for old people (although text is getting there too).
Plus email is almost as easy to spoof and intercept, so the gain would be minimal.
I'm sure there are a few people without email on their phones but I don't think the number is dramatically different than those without SMS right now. If I have cell signal I have email, but I can have email without SMS access.
In the US populated area, maybe.
In the French country side, definitely not.
E.G: last week, my brother wanted to try one of my service account on his ipad (we set it up only on his computer). He tried to connect with my password, but any new device requires a 2FA. So he calls me, and I gave it to him.
Now, in this particular example, I was at home, so I had access to internet.
But I'm often traveling to places where I don't.
In fact, I lived in Mali for 2 year where this has been a big trouble for all administrative stuff. Nowadays, I would assume a lot of Malian people have a phone numbers, but no emails, anyway.
But without going that far, the French country sides have plenty of places where you get text but not internet. And being in a car or train is often enough for that.
I don't think SMS is a good 2FA. I have 3 yukikeys at home.
But I believe any geek should first spend a month working in a call center before making a comment about 2FA.
There is a looooong tail of things getting wrong, and there is a reason corporations chose SMS: they tried all the rest, and it was worse.
Now thing are getting better with in app 2FA notifications, but of course it assumes you have a smartphone.
> I'm sometimes in zones without internet but my mum call me and ask me to give her some confirmation code I receive.
We're talking about multifactor authentication here. Where/how are you authenticating without internet access?
> Email is for old people
I guess that makes me old. Does that disqualify me from using multifactor authentication?
> Not as simple: stuff arrive in the spam folder. Some providers just reject your valid mail (my main email tld is exotic, it causes lots of troubles).
All of this happens to me with SMS much more often than it does with email.
> Plus email is almost as easy to spoof and intercept,
Agreed on spoofing, but that's not a problem for OTP authentication. Complete disagree on interception – I believe SMS is much easier to intercept, on average.