Skip to content

Comment on No password required: Mobile carrier exposes data for millions of accountsparent

Comments

I like OTP. But I fear when I change phone number or leave country, the next owner could literally login to any of my online accounts using OTP on my previous number. That's why I always remove it from every account when I update, but can't keep track of all my accounts or emails.

Don’t give up your main number. 10 years ago I changed phone numbers and ported my old one to a super cheap SIP line. 3 years later I grabbed it back and it’s been that’s my main number since.

I use SMS OTP for a lot of services which would have little consequence if hacked.. and leave things like email and other sensitive stuff to the apps generating tokens.

That's true. My UK number seems to be completely fine after many years, even if I don't top it up. But some other country, after few months of inactivity they seem to be automatically sold to a new user.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.