TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

I'll always setup an authenticator app and put SMS just as a backup

13 pointsby omidfiover 7 years ago
I spent three days on emailing and calling Amazon UK, to be able to get into my account.<p>I have 2 phone numbers registered in the account, and none of them recieved the text messages that had the security code!<p>Amazon support was funny, it took me sometime to see clearly that they are just sending me different message templates. It was a loop:<p>1. I sent them an email. 2. They asked me to call. 3. I called and they sent me the security code to my phone, which I still didn&#x27;t recieve. 4. They asked me to send an email. 5. They replied with: please call us!<p>I&#x27;ll always install an authenticator app instead of relying on text messages from now on.

5 comments

j_sover 7 years ago
For the record, phone numbers and SMS are a security vulnerability. Current recommended best practice once a U2F token and authentiator app are setup is to remove the phone number from the account (which may not be an option for many services).<p><a href="https:&#x2F;&#x2F;techsolidarity.org&#x2F;resources&#x2F;security_key_faq.htm" rel="nofollow">https:&#x2F;&#x2F;techsolidarity.org&#x2F;resources&#x2F;security_key_faq.htm</a><p><i>there are at least three reasons why you should avoid using text messages for two-factor authentication.<p>· Your phone number can be easily hijacked by someone who calls the phone company and pretends to be you.<p>· The text message can be viewed or redirected while en route to your phone.<p>· Many phones are configured to display text messages on the lock screen.<p>If text messages are the only way to add two-factor authentication to your account, they are better than nothing. But if you can use an alternative method, like an authenticator app or a security key, use that instead.</i><p><a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=14106578" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=14106578</a><p>&gt; tptacek: <i>The real answer for &quot;why not SMS&quot; is &quot;because both teenagers and intelligence services can get a phone number redirected; your phone number is not your phone.&quot;</i>
bartoszhernasover 7 years ago
1Password has build-in authenticator app, and it works great. I highly recommend it instead of Google Authenticator.
评论 #15382951 未加载
评论 #15383587 未加载
forzoover 7 years ago
Recently I faced same issue with SMS for my Digital Ocean account. Fortunately I have my backup code to restore an account. Finally I moved to authenticator based code. By the way, Digital Ocean support is much more better than Amazon.
CodeWriter23over 7 years ago
Just remember to copy the TOTPs to your new phone or use a password manager that stores them for you.
segmondyover 7 years ago
Are you using a virtual number? Some companies don&#x27;t send text to virtual numbers such as Google numbers.
评论 #15415936 未加载