Hacker News new | ask | show | jobs
by lxgr 1401 days ago
I haven‘t tried it, but I‘m willing to bet that at least one of these would claim that my primary phone number "is not a mobile phone number" (but I use it on a phone), "is not registered in my name" (it is, and how do you claim to know?), or "is a VoIP number, which is insecure and therefore not allowed".

Phone numbers are neither good user identifiers nor viable authentication factors.

1 comments

We do not verify any of your personal information. We neither have access to that nor store any of it on our system. Our PhoneCheck product simply returns a true or false. Is your phone number tied to this SIM Card. This is information the MNO already has, they know your phone number and your SIM Card. The request is made over a cellular data connection from your device to the MNO
What's the difference between these three tiers of authentication, then? And what makes it different from SMS-OTP (leaving aside SS7 security concerns and focusing on SIM swapping, which I believe is responsible for the majority of successful attacks so far)?