Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I have/had a Facebook account with a phone number. The account was left unused for a few years. Recently, I used my E-mail to reset its password, unfortunately, since the account was abandoned for a long time, the system flagged my activity as "suspicious" automatically, and asks me for confirmation using my phone number.

But I no longer own that number.

And from the customer Q&A forum, I realized I was not the only one - it is almost impossible to find an actual human from Facebook to solve this kind of verification problem.

All I wanted is to delete it, but I can't. Now, my account becomes a zombie, can't be used, can't be deleted, and has lots of personal information. All thanks to the falsehoods Facebook programmers believed about phone numbers, and its non-existent "customer [0]" service.

I've heard Google has similar issues [1], if the machine works, then everything is fine, until you need a human...

Repeat after me: fxxk Facebook.

[0] because I'm the product, not the customer?

[1] https://news.ycombinator.com/item?id=18886804,

and read this comment, https://news.ycombinator.com/item?id=18887548



Storytime: I bounce between Japan and Korea for work. I was in Seoul for about a year and a half and naturally had a Korean phone number. I used this number to sign up for Line (a popular chat service in the two countries), and I also linked my email address to the account. So when it was time to move back to Japan, I naturally canceled my Korean phone service.

Fast forward 6 months, and my Line account suddenly disappears. I contact customer service, and it seems someone else had registered for Line with my previous phone number -- which was of course release when I canceled my service with the telecom in Korea. I was informed that it's Line's policy to only allow one account per phone number, and thus they deleted my old account when the other person registered. There was no way to recover it. I even reached out to one of my engineering friends that worked for Line, at the time.

Some of my friends, I only knew and communicated with through Line, and I have no way to find or contact them again.

So yeah, fxxk using phone numbers as identification.


This is why I'm not a fan of mobile apps that force you to use your number. Sadly the most popular apps all the cool kids are using (your friends) are the most inconvenient in some regards. I wish Signal would let me use an email instead so I can use it from a tablet, but they insist on keeping my phone number instead. Signal made sense to use with phone numbers when they encrypted SMS but they no longer do messaging without data so it makes no sense to me.


Line is the worse violator of these principles. Last I used it, in order to install it on another device, you had to back up all that device's data (contacts, etc) to a computer, put your account on another device which then triggers a non negotiable wipe of the other device's data whenever it connects to the internet, then download the backup to your new device. Hell.


The first of the two bad thing about Line is that connection to a phone number. Wife got a new iPad, and, because of the other bad thing - that Line only works on a single device - it had to be 'moved' to the new iPad. Which needs a confirmation by phone message. And that phone was in Japan, unlike my wife, and wouldn't have worked for text messages even if she had brought it (phone plan didn't allow international calls or text). Contacted Line and got all kinds of useless advice - at least there are people in the other end - but nothing worked.

Had to create a new account.

The backing-up and restore is the easy part. Not much help if you can't move the account due to that silly phone number lock-in.


All these problems would be solved if they allowed us to use Google voice number. It is a number that's attached to my email and one that I won't discard (assuming I would lose it due to in activity). But no. Even Uber doesn't allow me to use a Google voice number.


you can get a Google Voice number only if you are in the US, at least when I tried to get one last year it was impossible from Italy.


Looks like I got lucky, I ran into this where a while after moving a switched to a new phone and couldn't activate line because I didn't have the old number anymore. However I managed to sort it out with the line customer service (even though some of the questions like "when did you first register your line account" I could only guestimate because it was so long ago).


Similar thing happened to me with LINE - didn't have anyone else registering with the same number AFAIK, but simply having lost my session and the registered number meant I lost that account and had to register a new one.


You should have move your number to Japanese number though.


I do have a Japanese number. Perhaps you meant I should have linked my account to my number here?

I'm sure there are things I could have done to prevent it from happening, but I had no reason to believe Line would simply delete my account, as it was linked to my email address. In fact, I only used the number for the initial registration. After that, I only used my email/password combo to log in.


What you would have to do is to have the Japanese and Korean phones/numbers available at the same time, from the same place, and then change the phone number. Which is not something that is always possible - re. my post above.

As you, I only used the number for the initial registration - and I suspect that what's everybody do. I have no idea what the phone number should be used for outside of that. I'm not sure why Line (well, Naver, the company) does it that way. Others, including Skype (which would need the same level of 'verification') manage it better.


No, as much as I hate Facebook: fuck phone numbers. The idea of using phone number as a personal identification tool is so bad, I'm struggling to believe this is not some kind of conspiracy designed for the solely purpose of mocking the user. It is bad enough that phone numbers exist at all in the eyes of the end user by the year 2019, 15 years after Skype with user-friendly logins appeared and when about a half of the planet uses the phone almost solely for the purpose of having a pocket-size internet access device anyway. But making phone numbers a passport of sorts (a proprietary, insecure, easy to lose passport, over which you have basically no control) is the worst, the most stupid/evil idea ever. And there's no way around it, it is used by (supposedly "secure") whatsapp, telegram, google, facebook, every fucking pizza delivery service and, well, basically everything else. And I hate every single person responsible for helping that happen.

Seriously, I would do everything I can to destroy fucking phone numbers, but I have no idea how can we stop this madness.


> a proprietary, insecure, easy to lose passport

> 15 years after Skype

I agree with your general sentiment, but the two phrases I picked out are where you have it backward. Phone numbers are not proprietary. They're difficult to move, but if you're a customer with one phone company you can call a customer of a different phone company using a phone number.

Skype is proprietary. It belongs to a single company. Customers of Skype or Facetime or Slack or Hangout cannot simply contact each other across services.

Yes, phone numbers need to be replaced. They need to be replaced by an open solution, not a proprietary solution like Skype.


You do not own the phone number, your phone company does, and the implementation is a chip that you can physically "own" but can't control or know what happens inside.


> conspiracy designed for the solely purpose of mocking the user

slightly paraphrasing Hanlon's razor: don't attribute to a conspiracy that which is adequately explained by stupidity

> Seriously, I would do everything I can to destroy fucking phone numbers, but I have no idea how can we stop this madness.

I assume throwing away your phone isn't a solution for most people who grew up with one. Works for me though. :)


Well, I don't have a phone - have never had a mobile phone. So..I have other problems instead I guess. But not that one.


As far as I can see the vast majority of "serious" registration schemes on the net have a phone number field which is mandatory to fill in. Mobile phone even, in some cases. You're not allowed to not have one. Soon you'll have men in black asking you what you're up to if you don't have one.


Before switching to Linux I thought it would be hard to live without Windows. it wasn't.

Before purging Facebook and Twitter from my life I thought it would be inconvenient to live without them, it isn't.

Living without a phone looks inconvenient, but I think I'm going to try it some time this year.


seconded :) .. it's the best you can do for your mental health and actually "stay connected" for real!


same, i don't have a phone number. my biggest issue is with one of my two banks, but the other one works just fine without any cellphone.


Hi there! I thought it was just me. I do have a couple of older friends aged 70+ without mobiles, but that's all I knew of. :-)


hi! indeed, i don't know many other people without a cellphone, but it's not like I ask every time. there should be dozens of us, dozens.

Do you know low tech magazine? https://www.lowtechmagazine.com/


Hehehe. No I didn't, thanks, looks fascinating.


anti-spam, they said... and you also have this (vomit),

https://news.ycombinator.com/item?id=18085580

Yes Facebook is using your 2FA phone number to target you with ads


> making phone numbers a passport of sorts (a proprietary, insecure, easy to lose passport, over which you have basically no control)

Phones are an imperfect solution for two-factor authentication but nothing else is as widely available.

There are also very well-supported ways to recover access to your phone number if the physical device is lost or stolen: Contact your phone company, present legal ID and get a new sim card.


pro tip: Telegram requires a phone number for registration, but then you don't need a phone to use it. You can link an account to a burner phone and then you can set up a password. With that password, even if the phone number get reassigned, they can't have access to your account.


> With that password, even if the phone number get reassigned, they can't have access to your account.

I wonder what happens if you acquire that phone number and decide to make it your main one. Hopefully support staff have a way of checking if the old user's active, and asking them to change their account to a number they actually have access to.


if security is a concern don't use Telegram :)


Telegram is way safer than using a cellphone :)

But yeah, Telegram shouldn't be used for really sensitive stuff.


What do you suggest? Give everyone their own domain name? Phone numbers are more portable than third-party emails or logins to proprietary services like Skype. They can be moved from provider-to-provider.


I mean, why not? Doesn't even have to be a full domain name, even just assigning everyone their individual IPv6 address would work.


Now, my account becomes a zombie, can't be used, can't be deleted, and has lots of personal information. All thanks to the falsehoods Facebook programmers believed about phone numbers, and its non-existent "customer [0]" service.

I think it's naive to think that this wasn't decided at the product level. This exact scenario was discussed, along with many others like it, and this is how they decided to handle it. "So they'll have a profile up with their personal information, maybe some embarrassing stuff they posted in college, and now they're adult and looking for a job and it'll be up forever looking like they intentionally left it that way?" "Yes." "Okay." "It's fine." "I mean...." "Do you have a solution that doesn't cost money?" "No, but...." "So you want to propose we spend money fixing this?" "...." "Okay, so we're agreed that this is fine. Moving on."


We're in an age where it's scary to lose access to an e-mail addresses or phone number are at the top of that list.

I don't mean to change it, I mean to lose access to it. If you change it, find a way to hold onto access to the last one.

I learned this lesson relatively easily. I had a vanity domain that also received my e-mail and I eventually replaced it with a different one. I ran the new domain and e-mail for a few years before allowing the domain registration on the old one to expire. I hadn't received (non-spam) e-mail on it in a couple years, seemed safe enough.

Turns out I've had a few websites over the year since that I wanted to login to and I needed to recover my password, either because I forgot or the site had forced a reset due to a breach. I hadn't updated my e-mail on a few of those sites.

I don't think I'll let go of a main e-mail address or phone number again.


This story seems perfectly relevant - "computers don't argue" https://www.atariarchives.org/bcc2/showpage.php?page=133


It's a perfect story! Hard to believe that the story was written in 1966, it resembles a common argument with your ISP. ;-) And we also have government employees who cannot pass the Turing test...

(to other readers: click "next page" to read the rest of the story)

The most absurd aspect of my Facebook verification problem is, despite my account has been frozen due to "suspicious activities", their system is still sending those automated mail notices to remind me returning to Facebook for those activities I've been missed on my timeline!

WTF.


> I've heard Google has similar issues, if the machine works, then everything is fine, until you need a human...

I have had great support via phone, chat, and email with google a number of times over the past 3 years, and I live on an island foreign to Google in the middle of the Pacific Ocean. My experience has been that if you're using a paid Google product, the support is excellent.


I have similar experience with most paid services online, so I think the point is clear - you have to be an actual customer with your payment, although it won't guarantee that you will be treated nicely as a customer, but otherwise, it's certain that you are almost always the product.


If the number has been reassigned you could ring the person, explain the situation and get them to forward you the code. (Also a way to crack other people's accounts!).

I wonder if phone companies couldn't [partially] solve this; probably any system would be too open to abuse?


That happened to me once. I declined to provide the code. Might have been legit but seemed too big a risk of getting my phone number tied to something scammy or even criminal.


Send a GPDR removal request?


> it is almost impossible to find an actual human from Facebook to solve this kind of verification problem.

I have come to realize that if you do not deal with a real person when signing up for some service, you will never get to deal with a real person when you need one. Customer service doesn't exist at FB, Google, etc. because they aren't customer oriented companies. They were not created to service you, they were created to use you.


I do wonder how EU's "right to be forgotten" comes into the play here. Could it be used in your case?


First, to my knowledge, there are two alternative ways to recover my account within the Facebook system.

1. Correctly identify some personal information about your Facebook friends, or ask them to provide some information about you. However, I have abandoned my account for years, and clearly I no longer have personal contact with most of them.

2. Provide your National-ID document to Facebook. Obviously, I'm not comfortable with it, but I assume my identity is already public information on Facebook so I may have to do it. Unfortunately, the bigger problem is that, personally, I'm in the middle of some tricky paperwork problem with the government bureaucracy, just like my Facebook account. I may need to go to the court to sort it out, but currently I don't have time to bother.

"Right to be forgotten" and GDPR seems to be a powerful tool to solve these kind of problems, but I'm not a EU citizen and I don't know much about its regulations, but I also want to know about it. Does anyone know something about it? Assuming I'm a EU citizen, how exactly, can I submit a request of information removal? If it's similar to DMCA takedowns, perhaps it can be used? Or it need a rigorous legal proof of identity like (2)? For non-EU citizens, is there a similar outlet to solve these kinds of problems?


Eu's GDPR defines several rights and obligations, one of which is :

Personal data shall be [...] accurate and, where necessary, kept up to date; every reasonable step must be taken to ensure that personal data that are inaccurate, having regard to the purposes for which they are processed, are erased or rectified without delay (‘accuracy’);

OP could contact Facebook's Data Protection Officer, that they are required to have, and demand that his data is fixed. A complaint can also be filed to the relevant country's Data Protection Authority if needed (I've done it with some success).


But how will he verify that he actually is the person who owns the account?

Well, in this case, he still owns the email so it should work.


Since you know the number, have you considered reaching out to its current owner to coordinate passing off the code?


That’s actually a pretty popular phishing method currently.


Good idea! I'll try. Thanks! The number may or may not be recycled, in case it's not recycled, it would simply be a NULL number. Wish me luck...


If its not recycled, perhaps you can find the company that has it ... "my lucky number is 441 743, any chance i can get a number that ends like that?". I guess it depends how much time/money you want to spend.


An old eBay account of mine is in the same zombie state because it's wanting to use an old phone number that I no longer control to "verify" me.


Currently facing the same problem with apple and icloud, their customer support is being excruciating about it


too big to be polite


The matter is more simple, Facebook users are not Facebook customers, hence no customer support. Same story with free Google accounts.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: