Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Is there a problem with a system whereby a business already has clients phone numbers and uses them to send the client a temporary PIN when the client enters their phone number as a username on the business's website?


Yes: call/SMS forwarding. It depends on how good your first factor (e.g. password policies) are, and how your reset process works. Getting someone's phone number and setting up call forwarding doesn't require much social engineering savvy to pull off.

http://www.wired.com/gadgetlab/2012/08/apple-amazon-mat-hona...


Call forwarding doesn't forward SMS. I don't think you can do SMS forwarding (at least for any carrier I'm aware of). You'd need to social engineer the carrier to port your target's number to a different phone -- in which case the target is going to be exposed to a ton of trouble...


that is how liqpay.com works. you enter number, receive one time PIN via sms to login




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: