logoalt Hacker News

mproudtoday at 6:39 AM3 repliesview on HN

I get phone calls for a guy named Randy about his business. I can’t for the life of me figure out how to make the phone calls stop.

The simplest solution is to change my phone number. But

a) why should I have to? it’s my number, dammit!

b) how many accounts have 2FA? if I changed my number, what if I miss updating one that’s important?

c) it could happen again

If I change my number, however, that is the simplest way to solve the problem. It’s just, do I want to?


Replies

s_devtoday at 9:39 AM

>I get phone calls for a guy named Randy about his business. I can’t for the life of me figure out how to make the phone calls stop.

By taking advantage of Randy's business in a way that will send a message to Randy to let him sort it out.

Once had a client who though they were being clever using a competitors email domain in order to sent a signal of quality and fool prospective customers. The competitor who owned the domain just spun up the associated email addresses and then proceeded to login to all their services and delete them using password resets and email auth.

You used to see it a lot with hotlinking images back in the day, you'd ask a service to stop using a URL and they wouldn't. You then update the image to something offensive and the URL is suddenly removed from their site.

basilikumtoday at 9:42 AM

2FA over SMS is stupidly bad. It's worse than TOTP in every aspect including this reason. It is also much less secure. You could start switching accounts to TOTP regardless of this and then decide if you want to switch your number later when you have the option.

TOTP is portable and can be backed up.

I went a little bit off on a tangent, the stupidity of SMS 2FA is a pet peeve of mine.

show 1 reply
nephihahatoday at 8:56 AM

We managed to get given a drug dealer's former landline, and had to get it changed after strange calls in the middle of the night. Then our neighbours got the same number after about a year and had the same issue.