Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I've been considering getting a second, secret SIM card exclusively for use with services where SMS 2FA is the only option.


I've been using Google Voice for that purpose for years, and it has been perfect. The phone number that is for 2FA only, shouldn't be as easy to social engineer your typical telcom, since it is all controlled from within my Google account, and I get immediate security notifications if something fishy is up.


That's a great plan, and it definitely reduces your risk to being exposed to SIM hijacking. Unfortunately, I suspect services that enforce poor security standards are probably not following best practices in their backend either. This means your secret number stops being secret if their database ever leaks.

It's still better than using the same number as you use for everything else, but it's important to understand the caveats.


This is standard practice for public figures like YouTubers who often get griefed




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: