Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

No, park your 2FA number on a 2FA mule[1] and forward the sms anywhere you like.

This solves the “voip number” problem.

[1] https://kozubik.com/items/2famule/



> [1] https://kozubik.com/items/2famule/

"Expired: Monday, July 17, 2023 at 13:21:09 Eastern Daylight Saving Time" per Safari.

* https://www.ssllabs.com/ssltest/analyze.html?d=kozubik.com


Yes but what to do ?

I had a nice acme.sh toolchain and process and then this silliness:

https://news.ycombinator.com/item?id=36252310

... all for a simple site that never needed SSL in the first place.

(luckily I only ran acme.sh in a stripped down jail)


I foresee way too many risks with this approach to do it myself. I have a phone that I could plug in this way and leave in my apartment. But what happens when I'm abroad and it breaks for some reason, some update or power cycle or unforeseen crash, and then I'm stuck abroad with no way to confirm my identity. Plus it doesn't eliminate the need to pay for a phone plan.


I've had mild success using Any desk to remote control a phone, but that only works for app issues and not random power or reboot issues. you could slightly help that with a smart power strip to power cycle.. but only if you had a phone with no battery that still ran when plugged in. maybe if you even could remove all security so it doesn't require a pin on reboot ... but then you can't trust it for 2fa stuff


It's been 2 years since I read your initial comment on using an SMS mule [1], and I'm curious how's it going, you know, that phone you have plugged in at your office in a corner :)

No battery swelling?

I copied the idea and did the same, it's essentially free of cost to do so where I live, thanks to having operators that offer a pay-what-you-use tier with no fixed monthly cost. The line is just to act as a 2FA mule, so it means it costs nothing (save causing any kind of expense once every 6 months, but sending a single SMS does it, so I guess it actually costs something like 20cts per year)

Apart from the SMS Forwarder app [2] you suggested, an HN commenter [3] provided links to some FOSS alternative which I didn't get to try but should work fine and is ad-free.

[1]: https://news.ycombinator.com/item?id=28251107

[2]: https://play.google.com/store/apps/details?id=com.frzinapps....

[3]: https://news.ycombinator.com/item?id=29711030


No, no battery swelling.

The only minor hiccup I have had is that at some point the devices decide that enough time has passed that there must be a software update available ... and I ignore the prompts to do so ... which is fine ...

... but then there was a power outage and when they powered back on they were in some update status where they weren't online until I clicked something ? I forget ... might have been an updated google legal agreement with the update ?

They are google pixel devices with stock OS load and no apps added (other than that SMSForwarder) but even still, had some logic for software update that produced a minor annoyance.


Good to know! Indeed some hiccups are expected. I don't need 2FA mule most of the time, but when I do, mine is an old phone flashed with LineageOS, no Google services at all, only F-Droid and otherwise manually installed apps.

Working well, albeit the Google login tends to give more problems than it should, in smaller and independent apps like these.

But I definitely observed that the one time that I left the phone plugged in for the most part of 3 months, the battery never was the same. It lost like a third of its capacity.


Futhermore, you can then install ACCA and set it to reduce the risks of battery issues.

https://f-droid.org/packages/mattecarra.accapp/


That's interesting, thanks.

Have you used it? Do you know if it's only the GUI for ACC (i.e. that ACC must be installed independently), or if it already embeds ACC?


Not the parent, but I've used some app from F-Droid to fwd SMS to email. What I didn't thought about is what Samsung SW would aggressivly suffocate the app of any chance to wake up on the receive. Which led for it to be quite useless as a 2FA mule (delay is too long) and it requires a reboot every couple of months. It not that seriuous in ghis case, but if I would be in the need of replicating the setup I would do it with the Moto phone.


I use a 4g device connected via usb with smstools to call a python script that logs the message and sends a push notification.. :D


2fa mule? Kagi isn't finding anything for that term.


It means "to a dumb second phone that you'd use only for 2 factor authentication"





Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: