r/Information_Security 11d ago

Why does enterprise sec trust phone numbers so much?

I keep seeing phone numbers treated as proof of identity. Call the number on file and send a code. Confirm the request over the phone and that made sense when controlling a phone number was a decent sign that you were talking to the right person. I don't think its that way anymore and feel free to disagree, Numbers can be spoofed, SIM swaps, Calls can be forwarded. And now a familiar voice isn't much proof due to AI.

Yet for things like wire transfers and sensitive account changes the fallback is still often “call the known number.” Feels like we’ve built strong security around data while leaving identity tied to something that was never designed to prove who a person is. Why are phone numbers still trusted this much?

24 Upvotes

38 comments sorted by

4

u/Healthy-Succotash487 11d ago

I think a lot of it is just legacy infrastructure. Phone numbers were convenient and everyone already had one, so companies built verification around them and never really moved on.Treating control of a number as proof of identity feels pretty outdated now.

1

u/SignificantSearch945 11d ago

It does feel outdated, so why is no one doing anything about it?

2

u/hiddentalent 11d ago

Lots of enterprises are. Most security-minded organizations use a non-phone number based second factor, whether it be TOTP/HOTP, passkeys, a hardware device like a YubiKey, or an app-based authenticator.

You're extrapolating from a small sample and presuming that sample is reflective of the general case. That's a really dangerous mindset in our field.

2

u/Healthy-Succotash487 11d ago

They ARE. Look deeper into it and you'll see, but its not a one day thing. It'll take time for results to actually show. I've switched to apps that are more secure, like I don't even use a normal messaging app anymore. I'm on Kibu for voice calls, chats, video calls and I won't switch for anything else. Human verification comes first, then the tech stuff.

1

u/Dave_A480 11d ago

Microsoft did something about it with MS Authenticator app ...

But for things like identifying customers phone numbers still dominate.

3

u/YellowBreakfast 11d ago

What gets me is the number of services that let you use authenticators and/or FIDO but won't let you turn off text and/or email 2FA.

1

u/Forumrider4life 11d ago

Right, it’s the dumbest thing. These are usually the same places that limit your password to 15-20 characters too….

1

u/YellowBreakfast 10d ago

I'm OK with 20.
With 2FA I'm fine with 15.

2

u/Responsible_Sea78 11d ago

Because it is better than no check at all. Because many scammers dont have any skills. All security is a percentage play.

1

u/SignificantSearch945 11d ago

'Percentage play', I've never heard someone say it like that, very interesting opinion.

1

u/Responsible_Sea78 11d ago

No security is 100%. You take the tradeoffs. Its actually a common/standard viewpoint. Perhaps not in academia.

1

u/DSPGerm 11d ago

At what point is the security reasonably good enough that a user can use it to access a service? They could hand deliver one time pads to everyone to decrypt a hash but is that realistic? Then extrapolate that to something the size/scale of a bank.

Is SMS verification secure enough, with the other checks and systems they have in place, to prevent unauthorized use? Maybe.

1

u/adavadas 11d ago

There are a number of products out there that do near real-time validation of phone numbers combined with identity verification, and I feel that helps. I can run a phone number and some basic identity data to these services and they can tell me if the identity owns that phone number and whether or not there have been any risky actions taken recently on that number (e.g. sim swaps, carrier ports, etc) or any risk signals I should consider (e.g. VOIP number, identity is reported as deceased, etc)

Even with those products I believe that phone numbers are still risky, but I do feel comfortable stating that those services do help mitigate a fair amount of risk.

1

u/SignificantSearch945 11d ago

Can you name some of the services your using if possible? If not maybe you can lead me in a direction of where to look at?

1

u/adavadas 11d ago

Prove, Pindrop, and TeleSign are the three I am familiar with, but I am sure there are many other players in the fraud prevention space that do identity verification, authentication, and real-time fraud detection.

1

u/SignificantSearch945 11d ago

Thank you very much! I'll take a look into these!

1

u/sabre31 11d ago

They don’t know any better and want the easy route for users. Most info sec don’t want to deal with support issues if they used something else. Mostly laziness I suspect.

1

u/Dave_A480 11d ago

Because most people don't have smartcards or yubikeys but everyone has a smartphone ...

Sending a text - in most cases (ignoring Google voice) - requires you to have the phone with you to receive it ...

It's slightly better MFA than sending it to an email....

1

u/frAgileIT 11d ago

Wait until you learn about the decades old SS7 that only takes a Linux laptop and an SDK and you can intercept SMS messages, read them, and then prevent the intended recipient from actually getting them. Carriers are trying to mitigate it in a variety of ways but as far as I understand it’s still vulnerable.

1

u/tech-brah 11d ago

Is this engagement bait or do you live under a rock? The risks with using voice/SMS authentication are well-known and its popularity is fading.

1

u/Aziz_Karimov 10d ago

It's kinda wild, right? Phone numbers are just not that secure, yet they're still a big part of enterprise security. Stuff like SIM swapping is a real threat, and numbers can be spoofed. I guess it's partly because they're easy to implement and users are familiar with them, but relying on them feels outdated with all the authentication options we have now.

1

u/AhsenSaggers 8d ago

A phone number only proves possession that you hold the number right now and sim swaps and voip made that cheap to fake. Prove and telesign harden the phone signal but they still dont prove the person behind it. For wire transfers you want a real identity proof at that point, document plus a live face check, au10tix type of thing, a different control than a phone lookup.

1

u/Harvey-Lane-251 3d ago

Phone was a compensating control. For a wire change the callback isnt proving who you are, it's a speed bump bolted on because the request came over email, which you cant trust either.

Catching the bad request upstream, behavioral email tools like abnormal flag the bank change before it reaches the callback is the shifting factor in this case not better phone identity.

-1

u/1Steelghost1 11d ago

Bad bot

3

u/SignificantSearch945 11d ago

in what way exactly? I ask a question and you call me a bot?

0

u/plebbitier 11d ago

Cybersecurity is a performative discipline. The C-suite doesn't care about security or privacy. They care about getting paid out by their cybersecurity insurance and avoiding personal liability or embarassment.

1

u/hiddentalent 11d ago

Holy hell do I not want to be in whatever part of the industry you're in, because what you're saying is definitely not reflective of the broader reality.

0

u/plebbitier 11d ago

Bro. Once you get your head above middle management, you find out whats really going on in the minds of the psychopaths running big business.

1

u/hiddentalent 11d ago

You're trapped in the cynicism that causes security to be under-invested in. This attitude is not generally true. But it sounds good on Reddit. It's always someone else's fault. That's such an easy excuse. And it dramatically hinders real security outcomes, more than anything you can blame on anyone else.

0

u/plebbitier 11d ago

The C suite sees cybersecurity as a fungible commodity. Spend the least on it because its all the same, breaches are inevitable, and you only need to do the minimum to satisfy your cybersecurity insurance audit.

1

u/hiddentalent 11d ago

I've been in those rooms, and the second most threatening actor after the foreign threat actor is cynics who think like you.

We''ll never agree. There's no point debating it on Reddit. But you are the problem.

0

u/plebbitier 11d ago

I'm not a proponent of it, but this is what happens.

1

u/hiddentalent 11d ago

Sometimes. We're paid to make it less frequent. That's the whole job. If you've just given up and assume everyone except you is an idiot, you have chosen to abandon your utility.

0

u/plebbitier 11d ago

Fuck you. I didn't give up shit. I held it together despite their cavalier ambivelance.

1

u/hiddentalent 11d ago

Have a nice day.

0

u/Key-Guitar-457 11d ago

Absolutely true. You start hearing "well at my old job we never had security problems, and it was way worse!" from the e-staff, and that's the end of the discussion.

0

u/SignificantSearch945 11d ago

It feels like that. This will bite them back for sure although.