Skip to content

Comment on Gemini Users: We're Going to Look at Your Texts Whether You Like It or Notparent

Comments

"Financial security" ? Don't you think you're overstating that a bit? We're talking about bank accounts bound by Regulation E, not bearer tokens like cryptocurrency.

Traditional bank accounts are quite close to an open ledger - the only thing one really needs to initiate a transaction against an account is the account number, which is printed on every check. As I said, the biggest fraud risk is not checking your accounts every ~30 days. Do this, and your liability is basically capped at having to fill out some paperwork and change account numbers.

The "Rube Goldberg contraption" is to mitigate the nonconsensual SMS nag by making it as easy as possible. My login security relies on my passwords. If someone can get those passwords, it means they've pwned my computing infrastructure and I have got much bigger problems than cleaning up unauthorized bank account activity.

As for GVoice, I chose to start using it because I saw Google and AT&T as similar attackers. I've stuck with it because it works for more of these types of things than other VOIP providers. With "AI" that original calculus might be changing, and if (when?) I decide to jump away from that then I'll probably move towards something like @rsync's "2FA Mule".

Which banks support 2FA mules?

I would think all of them, because it's just another prepaid SIM like many people's actual phones. On that front, Ally SMS stopped working with GVoice (I just do the voice call when they want to nag, that still works). And way back I experienced some random issues with Cap1 - it seemed like they were trying to grab the subscriber record as a form of verification (sigh).

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.