skip to content

Why is a one-time code sent to a phone number only as strong as the carrier's recovery desk?

level: middleimportance: nice to knowfreq 38%

answer

  1. address, not possession
  2. who is allowed to re-issue it
  3. port-out and replacement SIM are normal operations
  4. a third party's service desk, not yours
  5. numbers get recycled to new subscribers

basics

~10 s

Because a phone number is an address a carrier assigns, not a possession the user holds. Whoever talks the carrier's own recovery process into re-issuing that number receives every code routed to it.

solid answer

~60 s

A factor delivered to a phone number is bound to a **routable address**, and that address is administered by a third party you do not control. Re-issuing it is a normal carrier operation: a port-out to another provider, or a replacement SIM for a customer who says their phone was lost. Both are completed by the carrier's own recovery process, over the phone, on facts about the subscriber — which is the same no-gateway technique aimed at a different service desk, one your policies and your staff briefing do not reach. Two consequences matter. First, "we called back the number on record" is not verification of a person when the number is precisely what moved. Second, numbers are also **recycled**: a disconnected number is reassigned to a new subscriber later, so a stale recovery number can hand an account away with no social engineering at all. The control class is to bind the factor to a key held on an enrolled device rather than to an address, and where a number must stay in the flow, to lock it against porting.

go deeper

for a junior

Know that a texted code is delivered to a phone number, and that a number is assigned by a mobile carrier rather than owned by the user, so the carrier can move it to different equipment.

for a middle

Explain both mechanisms — port-out and SIM replacement — as ordinary carrier operations completed on knowledge checks, and state precisely what a delivered code proves and what it does not.

for a senior

Show judgment on the control class: bind the factor to a device-held key, remove the number from recovery as well as login, and reject callback-to-number-of-record as identity verification.

for a principal

Own the dependency: part of your authentication assurance is administered by carriers you have no contract with. Be ready to say which account tiers may never depend on it and what that migration costs.

## Address versus possession The whole answer turns on one distinction. A hardware or platform authenticator holds a private key that never leaves the device; proving the factor means the device performed an operation it alone could perform. A code texted to a phone number proves something much weaker: that whatever equipment the number currently routes to received a message, and that whoever was holding it typed the digits back. A phone number is not a thing anyone owns. It is an entry in a carrier's routing tables, leased to a subscriber and changeable by the carrier at any time. That makes the factor's real security boundary the carrier's account-administration process — a boundary that sits inside a company you have no relationship with, staffed by people who have never heard of your organisation. ## The two ways a number moves **Port-out.** Number portability is a regulated consumer right: subscribers may take their number to a competing provider. The receiving carrier requests the port using subscriber details — name, address, account number, sometimes a PIN — and the losing carrier releases it. An operator who gathers or is told those details can initiate the port, and the legitimate subscriber's handset goes dark at the moment of cutover, often the first sign anything happened. **SIM replacement.** A subscriber whose phone was lost or damaged asks for the number to be provisioned onto a new SIM or eSIM. This is completed over a phone call or in a shop, on identity checks that are usually knowledge-based, and it exists precisely because losing a phone is normal. Both are the technique this leaf is about, pointed somewhere unexpected: a phone call to a service desk, no gateway anywhere on the path, and an ask — *my phone was replaced* — that only a live conversation can make credibly. The target of the pretext is not your employee at all. It is a carrier agent whose job is to keep customers connected. ## Recycling, which needs no adversary at all Carriers reclaim disconnected numbers and reassign them to new subscribers after a holding period. If an account's recovery address is a number the user gave up two years ago, the codes now go to a stranger. No pretext, no call, no crew — just an account whose second factor quietly belongs to someone else. This is a good detail to raise, because it shows you understand the factor is an address with a lifecycle, not a possession. ## Getting the direction of the claim right A delivered code proves that the number is currently routed to equipment somebody answered. It does not prove: - that the enrolled account owner is holding that equipment; - that the SIM behind it is the one enrolled; - that the number has not changed hands since enrolment. The same correction applies to a very common recovery design: *call the number on record to confirm the request.* If the attack moved the number, the number on record is answered by the operator, and the callback confirms the compromise rather than detecting it. Out-of-band means a channel the organisation binds to the account — a challenge to an enrolled device, or an approval submitted through an authenticated internal workflow — not a telephone number that a third party can re-point. ## The control classes that change the precondition Rank them by what they remove: 1. **Bind the factor to a device-held key.** FIDO2/WebAuthn credentials, or an authenticator registration tied to a specific device, cannot be re-issued by a carrier because no carrier is involved. Re-pointing a number gains nothing. This removes the precondition rather than raising its cost. 2. **Take the number out of recovery, not just out of login.** Organisations frequently move users to an authenticator app and leave SMS enabled as the fallback, which preserves the weakness exactly. 3. **Lock the number where it must remain a factor.** Most carriers offer a port-freeze, number-lock or transfer PIN on the subscriber account. It is a control at the third party, so it has to be asked for. 4. **Add friction on number changes.** Treating a change of registered mobile number as a security-sensitive event, with a delay and notification on the account's other channels, costs the operator the tempo this technique depends on. What does **not** help: longer codes, shorter validity windows, or sending the code by automated voice call instead of text. All three keep the factor bound to the same address, and it is the address that moved. ## What a strong answer sounds like "A number is an address a third party assigns, so the factor inherits that third party's recovery process. Porting or re-issuing the number is a normal customer operation done on knowledge checks, and it delivers every code to the operator. So the fix is to bind the factor to something the device holds, and to stop treating a callback to the number of record as proof of who is on the line."

  • Your recovery flow calls the number on file to confirm the request. Is that verification?
    Of the number's current holder, yes. Of the person, no. Reaching the number proves the number is answered, and if the number is what was moved, the confirming call reaches the operator. Out-of-band has to mean a channel the organisation binds to the account — a challenge to an enrolled device, or an approval through an authenticated workflow — not a routable address a third party can re-point.
  • Does a code-generating app on the same phone have the same weakness?
    Not this one. The secret lives on the device and nothing is routed to a number, so re-issuing the number gains the operator nothing. The exposure shifts to the enrolment path instead: whoever can get a fresh registration onto a new device inherits the factor, which is why the process for re-enrolling a lost authenticator becomes the thing worth hardening.
  • Why do organisations keep SMS codes despite knowing this?
    Because it works on any handset with no software and no enrolment, which matters for contractors, shared-shift staff and customers. The defensible position is not blanket removal but tiering: device-bound credentials mandatory for privileged and administrative accounts, and the number removed from the recovery path even where it survives as a convenience factor elsewhere.

A phone number is a mailbox the post office can re-key for anyone who convinces them a key was lost. A device-held credential is a lock whose only key is in your pocket.

saying these in an interview costs you the question

  • Treats a phone number as something the user possesses
  • Says a callback to the number of record proves identity
  • Assumes only a bribed carrier insider can move a number
  • Believes any second factor is equivalent to any other
  • Fixes it by lengthening the code or shortening its validity

context