← Back to context

Comment by dylan604

5 months ago

Yeah, companies are not dumb, and they know when you have VoIP number vs a full account with an "accepted" company.

I can kind of see why not allowing 2FA to a number that could be easier to loose, but that's weak argument. Of course they don't want someone from .ru to get a US number with all of the baggage that would entail

There are flaws to their methodology. For half the companies, to change your number from A to B, you first must verify a NONCE with A, then verify a NONCE with B. This just means you have to possess two phone numbers for a period of time — Weeks, or in reality, months — while you change the long list of services over to the new phone number.

There is a simpler/better way and that is to verify you have your email address before allowing you to do a NONCE with B.