Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Another thing to keep in mind is that most phones will display the content of SMS messages on the lock screen, even if the phone is locked. That means that if your phone is stolen, hackers can easily take control of accounts such as PayPal that use SMS verification as the only way of establishing one's identity.

This exact scenario happened last week to a friend of mine, I wrote a little article about it: http://gregschlom.com/misc/2017/01/29/hacking-paypal-account...



That's one of the first things I setup on my Android phones. You can see that I have notifications, but not their content.


I would guess a surprisingly large percentage of smartphone users aren't aware this is an option.


Exactly the same here and I am sure any privacy-aware person will do the same.


That really needs to be the default.


On Android, it asks you when you set your passcode for the first time.

Super fragmented, but Nexus 5X had it.


My Sony Xperia also asked me at lock screen configuration. I could choose either way, but could not ignore the question.


Galaxy S7 asks you too. I remember now that you said it.


Agreed. It's usually buried in the device settings and also in Messenger and Hangouts. Signal gives you a few different options as well. But it should be more visible to all users, not just those of us that dig through settings.


But if you have the phone can't you just put the sim in another phone and read texts?


In countries outside the US, SIM cards generally require an unlock code when inserted into a new device.


I've had SIM cards in 10+ countries outside North America. None of them came set to require a PIN on startup. I had to enable it.


FWIW, I'm in the UK and this is the first I've heard of this.


True, but possession per se, even if unauthorized, is what a "something you have" factor is all about. Adding a knowledge or biometric factor on top (your phone's unlock mechanism) is a bonus.

Granted, the unauthorized porting issue makes it a faulty possession factor in the first place.




Consider applying for YC's Summer 2026 batch! Applications are open till May 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: