Your Phone Number Is Going To Get A Reputation Score
forbes.com
forbes.com
I want my reputation to be "Never answers unrecognized numbers and never buys anything over the phone ever, so don't even try".
Give me the most deadbeat phone number rating, please.
To put the shoe on the other foot, if you wanted to create a startup that offered anonymizing VPNs to privacy-conscious techies, and offer a free trial, you'd have a spam/scam problem. That site would be very attractive to a large number of people wanting to do illegal things with it. You could filter a lot of them out by requiring a phone number on signup, verifying ownership of that number, and rejecting registration from any with a low reputation score. People using burner VOIP numbers or the same number to make accounts reported as fraudulent at other businesses would have a low score.
You probably don't want to have a bad reputation if you care about signing up for things online. Like they said, Telesign has a huge number of clients. Lots of other fraud detection systems, like MaxMind's which are recommended occasionally on HN, are built on top of Telesign's APIs as well.
The entire point of my phone number, or my email address, is to identify me. Email doesn't get sent "to whoever is interested", it gets sent to designated people. How are those not meant to be identifiers?
(Bonus: Yahoo! email addresses get reused too.)
That doesn't affect the fact that the email address exists to identify the person. You'd need to say "people often share email addresses in common", which they don't.
we have a shared email address between us that the kids use, and I use to sign up for some stuff.
My parents have 3 emails addresses between themselves, and use them pretty much interchangeably.
I worked at a distance education provider for a couple of years, and we commonly had entire families using the same email address.
It turns out that when you sign up with an ISP, they give you a single email address by default, and you can - if you wish to, and know how, add more of your own.
Outside of the tech industry, nobody knows how.
For business and organisation IPs, if we get vandalism from that IP, we'll stick it on a long-term block (usually a year) and renew that block if there's recurring vandalism when the block expires.
They are intended to be delivery points for messages, not identifiers for non-messaging uses. The fact that the two functions are similar does not mean they are identical. Treating them as if they are identical just creates all kinds of (often unexpected) failure modes where the two functions don't overlap.
Correct me if I'm wrong, but I presumed that was its one stated purpose?
Ok. So you have me on one thing: it wasn't originally intended to be used as a personal identifier. You learn something new every day.
But then according to your very own link, it has universally been used and repurposed for this exact thing for the last 45 years, without issues, and with duplicate SSNs no longer being a problem.
I'd say that sounds like a very proven form of identification. So what problem do you (OP / ams6110) have with people using it as such?
That's a stretch. Because:
> So what problem do you (OP / ams6110) have with people using it as such?
A SSN is the "secret" bit to a small amount of otherwise-public info (name, address, some other bits) to getting a loan or credit card or other credit-related actions in my name.
I went to a small two-year school that used SSNs as their personal identifier numbers. Someone broke in and stole student records. Now the school's poor identity choices has put thousands of students' financial identities at risk.
Not everyone in the US is eligible for an SSN (e.g., some non-residents living in the US). When I first came to the US as a student, I had difficulty doing things like signing up for a credit card or a cellphone for this reason.
There are other numbers that systems sometimes but do not consistently accept, for instance an ITIN, which is the tax ID number the IRS will issue you if you aren't eligible for a SSN.
As a consumer though, the risk score makes me a bit weary. These mechanisms are notoriously opaque and when they misfire, they do so spectacularly. I would hate to have the type of the phone number I use be tied to my credit worthiness or something...
My account at Western Union was literally banned. I spent 2 hours on the phone with the American Express fraud department after linking my Simple debit card and getting flagged.
This sort of reputation system usually works 98%+ of the time, but when you get a false positive, there is literally no recourse.
I hope they are forced to provide profile information and "correction" services to consumers in the same way credit reporting agencies have to.
That's the scary part.
Not even mentioning that the phone number reputation score won't really just be a phone number score. it's going your human score - just like your CC Credit score but worse. Scary much? Welcome to the future. Just as bad as predicted.
At that point, you might as well go back to measuring the distance between facial features.
We'll more facial recognition scariness soon enough. Right now its mostly just used for security cameras all around big cities, drones and in some databases at facebook and google.
Try to register an account with some websites using a Twilio number, and it will get blocked / stopped. Try the same with a Google Voice / Skype number and you might be OK. You'll also see challenges with land lines vs mobile numbers.
What I have seen is some airlines unable to text my GV number, because they are working with an SMS provider that is only integrated with the major US wireless carriers and cannot send outside of those (Verizon, ATT, Sprint, T-Mobile).
It doesn't sound like an end-run around around anonymity, but more like the way retail stores crunch data to predict personal purchase patterns.
It's a CAPTCHA for criminals.
If some site like Google would insist on the phone number, I'd buy a SIM card only for that purpose.
But now there is a push to even not accept such "for one purpose" phone uses. Bad, awful for privacy.
If you know SS7 signalling and MAP queries, you can probably guess how to do this.
I hate the precedent that this is becoming ok.
It's the same reason someone will have a bad experience and e-mail a company but get ignored. Once The Consumerist runs an article about it though, it gets fixed.
There should not be a penalty for not using social media.