Phone number verification? I have an iPhone, which doesn't ever let apps read text messages, which actually would be nice sometimes when my banking app would like to verify it's running on my phone, as opposed to somebody else's phone.
Why would Facebook need to verify a phone number? It's a social network, used for jokes, farmville and whatnot. Most people I know that are on FB don't even use their 'real' name. IF someone provides a telephone number in his account details, FB can treat it like a string.
I understand why FB would like to 'verify a number', but why should we allow that to happen? Why is this a valid reason to ask for permissions on my phone?
If you don't let people use two factor auth, they bitch about your lack of security. If you let people use two factor auth, they bitch that you're collecting phone numbers. Can't win.
TFA is nice. Maybe mandatory when you're providing a service that passes a certain threshold?
But that permission obviously isn't the right answer. FB should ask for permissions to read _all_ SMS to make TFA via SMS a tiny bit more comfortable?
No. TFA solutions exist. Google Authenticator (I wouldn't trust Google with anything, but that's "open" as far as I know) or the Yubico aequivalent are perfectly fine choices for T/HOTP. If you want to send SMS instead (why??), let the user enjoy their platform's copy/paste support to give you the code.
There is not a single reasonable argument, why Facebook (or.. any. Seriously: I cannot think of ONE reason) should be able to read your text messages.
Bringing up TFA is probably (hey, not my native language, I certainly never joined a debating group or whatnot) a failure to argue the point and has a nice latin name or something. Maybe about a true of false Scotsman or what do I know..
If I say "FB shouldn't read texts" that has no relation to "FB should not implement TFA". Nor is it reasonable to imply that they cannot, without that permission.
> FB should ask for permissions to read _all_ SMS to make TFA via SMS a tiny bit more comfortable?
If Android had a permission called "Only read one text message to verify your phone number" maybe Facebook could use it.
Honestly, I don't know what Facebook is trying to do, but similar arguments come up frequently with Android apps. The permission model is IMO broken, because it requires upfront permission for everything the app may ever want to do. There's no way to install something, minus SMS permission.
Maybe Facebook is evil and does want to read all of your texts and upload them to advertisers. Maybe they don't. It's hard to determine that simply from the requested app permissions, given the poor granularity of those permissions.
What Facebook 2FA uses SMS and the app? All I know is either sending codes per SMS you enter on the web page or using a code generator app. Setting it up doesn't even require the Facebook app, let alone it reading SMS. Am I missing something? (I don't use Facebook much)
Not sure. I neither provided Facebook with my phone number, nor use Android, so I can't say whether it could verify for your phone number like that or not. But reading SMS codes seems like something an app could do instead of making the user enter it by hand.