OT

Feb 27, 2021 Last reply: 5 years ago 72 Replies

I simply don't bother with passwords at all. I wouldn't use an inherently insecure device like a mobile phone for anything important.

it's there to receive texts from couriers, banks the NHS and so on.

Likewise the gmail account it insists on is never used for anything private and whatever zoom/whatsapp/skype goes on is so boringly uninteresting even to me, let alone GCHQ, that I really don't care who reads it.

Mobile phones are toys. Ultimate consumerCrap?. Mine doesn?t respond to its touchscreen half the time except when I would rather it didnt.

Ergonomically it is a total disaster., Whoever thought of putting input where you cannot actually avoid getting fingers while holding the device?

Anyone doing anything important with a phone is a f****ng idiot

While it's /possible/ that Amazon have it in for you I still have 2FA by SMS and Amazon still state that's an option:

"You can receive this security code in a variety of ways depending on the option you select during sign up, including text message, voice call, or authenticator app."

formatting link
Allegedly you can turn off 2FA without contacting them - though that requires you to authenticate by...

formatting link

Does the SMS provide a number you can type in, or just a link you have to click on (as Tim Lamb implied above). Or is it yet another "configuration option" you have to know about?

If you have to (or choose to) click on a link on a smart phone, does that mean you have to continue your work on the smart phone, rather than the laptop or tablet you were using?

:-) I'm a cancel before prime locks in customer so I may be on a list of some sort. Anyway, I didn't agree 2FA. They already had my mobile number as part of my contact details.

Text is fine.

There are lots of alternative sources for Amazon stuff and I am not hugely supportive of their business model WRT taxation in the profit earning country.

Phone call to support sounds easier:-)

OK so I phoned Amazon. They can't turn it off! The only way this can be done is to put my sim card in a smart phone. Once logged in, all things are possible.

I do not believe they have no means to cater for people who lose a phone and cannot replace the SIM. I do believe first tier support don't want to know it exists.

The GDPR etc is all too difficult for me so this is not guaranteed to work (especially with Amazon - who wants to take on their lawyers?) but you could try (a) telling Amazon you are exercising your GDPR "right to be forgotten"[1] and then some time later (b) start again.

[1]
formatting link

Re-register an account? Anyway I can put my sim into a smart phone. I was just trying to avoid having to break it down to the smaller size needed.

>

I'm not sure what you did that required a Smartphone

my last order was made entirely on my laptop

and the delivery indication came as an SMS to my dumb phone

In message <s1j3fo$apt$ snipped-for-privacy@dont-email.me, tim... snipped-for-privacy@gmail.com writes

They already had my mobile number.

The general tone from the guy on their help line was invoking 2FA is an inertia action. A bit like prime.

He didn't say but the inference was you have to actively reject it or chose SMS / *click link*.

>

What make you think it is inherently insecure? Just the fact that it's small, portable and easily stolen?

Communications with it are secured to the same standard as those to a desktop or server class machine. It's running a Linux kernel, and has the option of biometric as well as conventional password restricted access.

I do know some folks have problems getting it to respond - particularly if they have very dry skin. "phone compatible" gloves usually solve the problem though.

Or alternatively you could argue it's a miracle of packaging, getting that sophistication of UI into such a small form factor.

Well confronted with such a thoughtfully reasoned augment, how could we doubt you :-)

Is it a case that you can't log into the Amazon site from a PC without using the 2FA?

If you receive the 2FA request via SMS (which I presume is the case with a feature phone), is it not just a web link that you could could type (possibly with great tedium!) manually into your browser on the desktop? (you would presumably only need do it once, to get signed in and then change the preference)

If it is rendered in such a way that the content is not "visible", what happens if you use the phone's companion software to copy your text messages to the desktop, and look at it there?

(I note on the "communications preferences" under Email alerts, messages, ads, and cookies section I can change SMS options).

Just so.

Indeed. Laziness comes with age:-( Also my phone has the attention span of a Gnat so reading and typing a relatively long link requires two hands. Not shopping with Amazon has not yet ended my world:-)

Visible. I don't think Alkatel considered *companion software* for the

*one touch*.

Yes. My plan: when I get back there:-)

Apple's email client, for one thing. It will allow mails to phone home (y'know, the 1x1 pixels jpegs to be downloaded when you read the mail). OK, you can tell it not to download *any* images, but there should be a subtler method than that.

On a smartphone, you have to take what you are given. No possibility to examine its innards in any way at all. No ability to organise anything to your own taste. Can't organise your documents, images, etc etc to suit yourself. All of which might be OK for simplistic usage but not for doing anything real.

Its inherently stealable, and it is pwned by google or apple depending

And Ive worked enough as a system admin to know how easy it is to access private data held on your employing companies servers, if you really want to

In order to access email at all, it has to store passwords. If it is stolen then bang goes that.

I don't believe that a screen lock will encrypt that data: you can probably pull the memory card and read it or root the phone if you nicked it:? My response = assume it will be stolen/lost and all data on it will be accessible to a third party and don't use it for anything critical

And even if that?s what he meant, he has got that completely wrong. With a mobile phone with the best fingerprint or facial recognition, the phone is in fact vastly more secure than anything else, even if it does get lost or stolen, just because no one else can use it.

Yep and the voice input works surprisingly well too.

Anyone who cant work out how to answer an incoming call has dementia.

You don?t have to use that email client, you are free to use any email client you like.

Bullshit.

More bullshit.

More bullshit.

More bullshit.

More bullshit, and you don?t have to do any of that when you use it to do your net banking more securely.

But trivial to ensure that is no use to the thief and impossible for the thief to do anything with your data or banking and the reality is that f*ck all of us have had their phone stolen.

That?s bullshit with apple.

But isnt with your phone.

More mindless bullshit with the best smartphone.

It does anyway with the best smartphones.

Nope, not with the best smartphones.

Nope, not with the best smartphones.

More fool you. You are 'living' in the past, as always.

More fool you. You are 'living' in the past, as always.

Change what preference? I suspect that once you activate 2FA you can't undo it. So far I've avoided it by clicking "not now" when they ask for my mobile number.

I think word has got round!

When I went to log in this evening, I got a *capcha* test followed by clicking a link in an e mail.

However, there seemed no understandable way of avoiding 2FA. or of choosing SMS ( you can select a no 2FA desk top but I suspect clearing cookies will wreck this) I suppose deleting the mobile number would work but it is helpful when the delivery driver needs to use it.

>

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required