Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

How would that be exploitable?


If you're exploring the phone system and want to know what circuit you've happened to sneak your way onto. It's very useful if you can have the phone company just tell you what part of their systems you're calling from :)


Why would it not suffice to call yourself on your own cell phone and look at the caller id?


Probably for the same reason you wouldn't want to ping your personal webpage from a remote computer you just hacked.


OK, so get yourself a burner and call that. One way or another, this does not seem like a hard problem.


If they're relying on such information for security, they aren't secure in the first place.


They don't have to be "relying" on it to use it.

If you treat security like a mathematical problem [1] with no grey areas, you are going to reject almost every security measure and say "that would only give users a false sense of security."

Just about all security measures can be worked around by a determined attacker. That doesn't mean you stop using them.

The linked page says to hide your whois information. This is surely security through obscurity. Yet it can vastly reduce the number of reset emails you get.

[1] You should treat crypto like a mathematical problem.


Also known as "defense in depth" in the security field.


To be picky, if you're treating it mathematically the phrase "sense of security" has no meaning.


I think that the idea is to not help out a potential attacker rather than to use this as an absolute security method. I think that we can agree that relying on any single security method is foolish. Maybe we shouldn't jump to conclusions that this is their only security measure in place.


If they're relying on multiple weak pieces of information like this for security, they still aren't secure, and now they just created a huge pain in the ass for any user of their system, as they have to somehow know all the pieces of information which are supposed to be secret. Huge-pain-in-the-ass security doesn't tend to work very well...




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: