logoalt Hacker News

JaggedJax10/01/20243 repliesview on HN

This happened to me with a major bank. They were using the same number for 2FA and some other types of texts. I got locked out of my account for a while because I had unsubscribed from their marketing texts. What an unbelievably dumb way to send 2FA codes.


Replies

thebytefairy10/02/2024

Had a similar thing happen to me, but for Facebook. Account got locked, to unlock I needed to verify identity via text. Never received the text because I had disabled getting text fb notifications, which apparently included account recovery. Managed to find this on some obscure thread to text some number to resubscribe and get it to work - no mechanism from fb, no alternate way to verify, no indication that this was the issue.

grotorea10/01/2024

I think something similar happened to me, but I used the phone's block and report feature. I assume it was the number of some SMS sending service that had both legitimate and spam clients.

hypeatei10/01/2024

Yet another reason why SMS 2FA should not be used. Shameful.

show 2 replies