Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Still not secure.


Why ?


Because you can keep dialing customer service with various stories. ”A shark ate my phone”. ”It’s my husbands account. A shark ate him and I want to post a funeral invitation on his page”.

Just keep dialing, and you’ll find a compassionate and helpful person at some point


For that reason I'm very happy I'm with Giffgaff in the UK - they literally don't have any telephone based support. If you need support you need to message them.....from your account online. Oh and any request to transfer the number takes at least a few days to go through, and you get notification that it's happening - same if you are being sent a replacement SIM. I imagine a number takeover attack would be very difficult due to this.


This assuming you know my SMS 2FA number, it not not that expensive to have second phone number and second sim on a phone.


Just start the phone tour from the Instagram support line. ”My son was abducted by sharks, and I need to dial my wife. Which of her phones did she use for her Instagram?”

Again, the kindness, compassion and flexibility of humans is the weak link in security.

I bet that’s why Google has all but eliminated the support staff!



That is SMS hijacking. That’s why @epitom3 says 2FA with an app.


All SMS 2FA is insecure by design / default


With one big assumption attacker know you 2FA SMS number, it is not hard to have second number.




Consider applying for YC's Winter 2026 batch! Applications are open till Nov 10

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: