Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

As others have said, the protocols are kind of crap, but it sounds like your concern is more about account takeover through customer service.

Maybe Project Fi? I don't know that they're better, but Google takes security pretty seriously, and you can probably lock down your Google account.

There's still a risk with phone number portability where someone tricks another carrier into porting your number somewhere else, and I kind of doubt that even Fi does anything here.



I was looking into Fi. It's true the number portability can be exploited as well. It's too bad many of these financial institutions that I'm required to used only do their 2FA via SMS.

Someone should try and create a secured layer on top of SS7.




Consider applying for YC's Fall 2025 batch! Applications are open till Aug 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: