Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Couple of factors lead to companies "embracing" SMS:

1. A phone number is a useful piece of information to have on a customer (to sell to someone or whatever).

2. Some (most?) people are too dumb to manage passwords/TOTP and shouldn't be allowed to use a computer. As a result, everyone suffers and is forced to use broken SMS 2FA that can be SIM-swapped.

3. Companies want to stop bots and use phone numbers for that, even if it's a non-issue for bot operators in practice. A little inconvenience, sure, but it doesn't change the bigger picture in any way.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: