Hacker News new | ask | show | jobs
by rvz 135 days ago
Phone number login in 2026 is really just asking for someone to do a SIM swap attack on the victim's account to steal their identity.

Surely a list of services that allow phone number logins exists so that one can avoid signing up in the first place and we would then see it in another connecting breach.

2 comments

Most banks and credit cards, as far as I’ve seen.

For example, I tried to set up another form of 2FA on Chase, but it still defaults to phone. I can’t disable or change it.

PayPal :(