Hacker News new | ask | show | jobs
by djb_hackernews 4083 days ago
This might be a stupid question but does this mean that if I have a phone emulator and configure it to have some number and download one of these apps that use the # for account lookup that I could essentially hijack peoples accounts like this?

EDIT: no that doesn't seem to be the case. When you login to Lyft they send a text to the registered number.

2 comments

I think Lyft login/auth would require you to be able to _receive_ messages sent to that number.
It might send an SMS to re-verify account ownership.