Yet again, having ported my phone number to Google Voice (GrandCentral back then), and never giving out whatever my current SIM's phone number is, pays off
Yet again, having ported my phone number to Google Voice (GrandCentral back then), and never giving out whatever my current SIM's phone number is, pays off
Agreed.
My phone number lives at twilio and I couldn't tell you the physical phone number on my SIM card ... I have no idea what it is without looking it up.
In addition to the obvious benefits of never caring whether you lose your phone or being vulnerable to a SIM swap there are other "telco superpowers" that come along with this arrangement:
- I can text you, from my number, from the command line (curl API)
- I can lose my phone and still send and receive SMS (again, curl API)
- I can "sanitize" incoming text messages to ascii-256, block attachments, block or alert on silent SMS, etc.
- block lists for incoming voice and SMS
- CC incoming texts to a mailspool which allows me to browse my SMS history as if it were email (this one is particularly nice).
Finally, I cannot participate in a discussion of hosted/VOIP vs. physical SIM numbers without reminding readers that a "2FA Mule" solves the problems of providers not supporting VOIP numbers for 2A:
For SMS, Google Vooice both sends to and receives from email. I have a cronjob set up to `mail` a TextNow number that needs activity every 28 days to stay alive.
>- CC incoming texts to a mailspool which allows me to browse my SMS history as if it were email (this one is particularly nice).
Oh, I like this. I tend to delete most of my SMS-via-email, and the texts are always searchable in my Google Voice account, but can definitely see the appeal of always archiving all incoming texts with my mail so that I can use `mairix` for search.
>Finally, I cannot participate in a discussion of hosted/VOIP vs. physical SIM numbers without reminding readers that a "2FA Mule" solves the problems of providers not supporting VOIP numbers for 2A:
Nice. I do use my phone's SIM (now eSIM) number when (and only when) 2FA won't take Google Voice, but if I decide that is a meaningful security flaw, your approach would work.
Speaking of telco superpowers, I don't know if Twilio lets you do this but Google Voice has always supported voice calls by browser. The only time I make or answer a phone call on my phone is when I am away from my computer. When iOS 8 appeared, I'd enjoyed the equivalent of Continuity for years.
Source: GV user since Grand Central days.
Everything else (including paypal, fidelity, schwab, sofi, discover, capital one, to name a handful) work fine.
The Internet is more harsh than telco backend infrastructure.
Sorry, I still don't get it. Telco's backend is a mess. It has a profusion of processes and frontend systems for customer service teams to interface with user records, which creates all sort of loopholes. Any sufficiently motivated attacker can pull a SIM swap attack, as it happens frequently, and the weak link is always a variation of: a clueless agent somewhere trying to help a poor "customer" who dropped their phone in the toilet, and needs to urgently to recover the number.
Or are you suggesting that Google's GV backend is riskier than the carriers?