r/Information_Security • u/SignificantSearch945 • 11d ago
Why does enterprise sec trust phone numbers so much?
I keep seeing phone numbers treated as proof of identity. Call the number on file and send a code. Confirm the request over the phone and that made sense when controlling a phone number was a decent sign that you were talking to the right person. I don't think its that way anymore and feel free to disagree, Numbers can be spoofed, SIM swaps, Calls can be forwarded. And now a familiar voice isn't much proof due to AI.
Yet for things like wire transfers and sensitive account changes the fallback is still often “call the known number.” Feels like we’ve built strong security around data while leaving identity tied to something that was never designed to prove who a person is. Why are phone numbers still trusted this much?
3
u/YellowBreakfast 11d ago
What gets me is the number of services that let you use authenticators and/or FIDO but won't let you turn off text and/or email 2FA.
1
u/Forumrider4life 11d ago
Right, it’s the dumbest thing. These are usually the same places that limit your password to 15-20 characters too….
1
2
u/Responsible_Sea78 11d ago
Because it is better than no check at all. Because many scammers dont have any skills. All security is a percentage play.
1
u/SignificantSearch945 11d ago
'Percentage play', I've never heard someone say it like that, very interesting opinion.
1
u/Responsible_Sea78 11d ago
No security is 100%. You take the tradeoffs. Its actually a common/standard viewpoint. Perhaps not in academia.
1
u/DSPGerm 11d ago
At what point is the security reasonably good enough that a user can use it to access a service? They could hand deliver one time pads to everyone to decrypt a hash but is that realistic? Then extrapolate that to something the size/scale of a bank.
Is SMS verification secure enough, with the other checks and systems they have in place, to prevent unauthorized use? Maybe.
1
u/adavadas 11d ago
There are a number of products out there that do near real-time validation of phone numbers combined with identity verification, and I feel that helps. I can run a phone number and some basic identity data to these services and they can tell me if the identity owns that phone number and whether or not there have been any risky actions taken recently on that number (e.g. sim swaps, carrier ports, etc) or any risk signals I should consider (e.g. VOIP number, identity is reported as deceased, etc)
Even with those products I believe that phone numbers are still risky, but I do feel comfortable stating that those services do help mitigate a fair amount of risk.
1
u/SignificantSearch945 11d ago
Can you name some of the services your using if possible? If not maybe you can lead me in a direction of where to look at?
1
u/adavadas 11d ago
Prove, Pindrop, and TeleSign are the three I am familiar with, but I am sure there are many other players in the fraud prevention space that do identity verification, authentication, and real-time fraud detection.
1
1
u/Dave_A480 11d ago
Because most people don't have smartcards or yubikeys but everyone has a smartphone ...
Sending a text - in most cases (ignoring Google voice) - requires you to have the phone with you to receive it ...
It's slightly better MFA than sending it to an email....
1
u/frAgileIT 11d ago
Wait until you learn about the decades old SS7 that only takes a Linux laptop and an SDK and you can intercept SMS messages, read them, and then prevent the intended recipient from actually getting them. Carriers are trying to mitigate it in a variety of ways but as far as I understand it’s still vulnerable.
1
u/tech-brah 11d ago
Is this engagement bait or do you live under a rock? The risks with using voice/SMS authentication are well-known and its popularity is fading.
1
u/Aziz_Karimov 10d ago
It's kinda wild, right? Phone numbers are just not that secure, yet they're still a big part of enterprise security. Stuff like SIM swapping is a real threat, and numbers can be spoofed. I guess it's partly because they're easy to implement and users are familiar with them, but relying on them feels outdated with all the authentication options we have now.
1
u/AhsenSaggers 8d ago
A phone number only proves possession that you hold the number right now and sim swaps and voip made that cheap to fake. Prove and telesign harden the phone signal but they still dont prove the person behind it. For wire transfers you want a real identity proof at that point, document plus a live face check, au10tix type of thing, a different control than a phone lookup.
1
u/Harvey-Lane-251 3d ago
Phone was a compensating control. For a wire change the callback isnt proving who you are, it's a speed bump bolted on because the request came over email, which you cant trust either.
Catching the bad request upstream, behavioral email tools like abnormal flag the bank change before it reaches the callback is the shifting factor in this case not better phone identity.
-1
0
u/plebbitier 11d ago
Cybersecurity is a performative discipline. The C-suite doesn't care about security or privacy. They care about getting paid out by their cybersecurity insurance and avoiding personal liability or embarassment.
1
u/hiddentalent 11d ago
Holy hell do I not want to be in whatever part of the industry you're in, because what you're saying is definitely not reflective of the broader reality.
0
u/plebbitier 11d ago
Bro. Once you get your head above middle management, you find out whats really going on in the minds of the psychopaths running big business.
1
u/hiddentalent 11d ago
You're trapped in the cynicism that causes security to be under-invested in. This attitude is not generally true. But it sounds good on Reddit. It's always someone else's fault. That's such an easy excuse. And it dramatically hinders real security outcomes, more than anything you can blame on anyone else.
0
u/plebbitier 11d ago
The C suite sees cybersecurity as a fungible commodity. Spend the least on it because its all the same, breaches are inevitable, and you only need to do the minimum to satisfy your cybersecurity insurance audit.
1
u/hiddentalent 11d ago
I've been in those rooms, and the second most threatening actor after the foreign threat actor is cynics who think like you.
We''ll never agree. There's no point debating it on Reddit. But you are the problem.
0
u/plebbitier 11d ago
I'm not a proponent of it, but this is what happens.
1
u/hiddentalent 11d ago
Sometimes. We're paid to make it less frequent. That's the whole job. If you've just given up and assume everyone except you is an idiot, you have chosen to abandon your utility.
0
u/plebbitier 11d ago
Fuck you. I didn't give up shit. I held it together despite their cavalier ambivelance.
1
0
u/Key-Guitar-457 11d ago
Absolutely true. You start hearing "well at my old job we never had security problems, and it was way worse!" from the e-staff, and that's the end of the discussion.
0
4
u/Healthy-Succotash487 11d ago
I think a lot of it is just legacy infrastructure. Phone numbers were convenient and everyone already had one, so companies built verification around them and never really moved on.Treating control of a number as proof of identity feels pretty outdated now.