Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> Supposedly, using the QR code on the smartphone triggers an SMS sent from your phone to Google in order to verify your phone number.

Does anyone have a better source of information than this one forum comment from someone who thinks scanning a QR code is enough to get your phone to send a text message?

EDIT: It’s just an SMS URI. It doesn’t automatically send anything, just opens a text message for you to send.

This is just the old phone number verification with a QR code convenience method.



What happens when your phone can't do that? I use a flip phone. It can't scan QR codes despite having a camera


Apparently it’s just an SMS URI.

It’s not something specific to a phone. It’s just a convenient method to enter your phone number.


To enter their phone number because you sent an SMS to them.

So if there are any costs for sending this SMS it’s on you.


> So if there are any costs for sending this SMS it’s on you.

It's a $0/month e-mail service.

If the price of entry is a single text message, I think that's fair.


We both know they harvest the data and still they are too cheap to pay for the SMS


There weren’t any infrastructure costs to sending the first SMS ever,

there shouldn’t be any remaining for the consumer today

unless you’re a real unfortunate soul.


    There weren’t any infrastructure costs to sending the first SMS ever,
Hah. Someone wasn't alive for the 90s.


Someone didn’t read all of the words ^_^

Infrastructure costs were marginal, near 0,

because SMS was just 140 bytes of text stuffed into already-occurring network traffic

between phone<->telco.


I did some work with Verizon and an IoT customer was asking about SMS pricing and the VZ guys laughed and said it cost less than a penny for every 1M SMS.


    the VZ guys laughed and said it cost less than a penny for every 1M SMS.
Didn't stop them from charging $0.10 per text message in the 2000s and earning a fortune.


Yep, bastards!


and that’s only because an accountant demanded a cost of goods sold!

Continuing that behavior until everybody’s grandma had iMessage, is a large portion of why I don’t trust a telco!

(Not building out the full range of rural etc network they promised to, while cashing all of the government subsidies, struck me wrong as well.)


Exchanging SMS messages with any sort of reliability (like not losing your messages when you go through a tunnel) requires running an SMSC. That costs money.

Furthermore, carriers still charge each other for exchanging SMS traffic, though many of them just charge the difference rather than sending each other bills.

This approach is quite costly if you're out of the country, though. Sending an SMS is hit and miss when roaming in foreign enough networks, and each SMS can cost you a significant amount for exchanging 10 characters. Even receiving SMS messages far away from home can cost you money, which is a pain if you have a relative that could never get used to modern messaging services.


Are you one of the unfortunate souls I mentioned?!

PS Has the bio trap snared any robots yet?!


Technically if you can copy paste the qr code into any qr reader website and manually do it, I think it's possible? Assuming it doesn't change the code very rapidly every few seconds.


Would be a bit silly for it to rapidly change given that manual action must be taken after scanning even on well supported devices.


My S24 Ultra no longer has rear cameras, they no longer work after the phone fell from a table. I can not scan QR codes either.

So many companies - such as electric car charging stations - require this without considering failure modes and alternative workflows.


They properly do, but then conclude that it would be more costly to implement and create those workarounds than not getting the extra 0.01% of users.


The elder gods have declared that you have been unpersoned... until you buy a new phone.

Also try squeezing the phone at various points to see if it pops the internal connector back in. You can find a repair video to see where the connector is.


Interesting. Each of the rear cameras has a separate connector. It's not like the older Samsung phones where all the cameras on on a separate daughterboard with a single connector.

I wonder if I could find a camera app that lets me select a different camera at app startup. The built in app closes with an error, unless I long click it and select "Take a selfie".

Ha, it worked! After opening in selfie mode, I can select manual mode in the stock camera app and use a different rear camera. But if I accidentally use the wrong settings, the whole app closes with an error.


then google has decided that you no longer should be able to use GMail (for now) and the internet (in the future)


eh, they gave up on trying to control usenet and haven't touched gopher so I'll just go there


The old method was for you to receive an SMS. Because it's easy to pay a phone farm 30 cents to receive an SMS now, they're changing it to sending. Phone farms will also adapt.


Can't you spoof or hide the "from" number in SMSs in a lot of countries?

Like email, I'd expect recieving to be more secure since it uses hardware the user isn't in control of.

There are free sites offering recieve-only SMS numbers, but they're almost universally at their rate limit for most services.



It probably opens a prefilled text message and the user still has to hit send. That's the only API I know on iOS anyway.


Can confirm this is what scanning the QR code does. I just went through this to get my Google dev account verified.


I think it's probably enough to get your phone to open your texting app with a pre populated number and message body, then all the user needs to do is hit send.


But isn't phone number verification usually works like... Google sends you a SMS, not the other way around?


you see, in that case google has to pay, but flipping it like this makes the customers.. oh wait the product pay.


Regarding how easy simswap is in 2026, it's dangerously stupid from Google to rely on SMS


I wish it was. I've looked everywhere for several years for anyone offering this service so I can get into my 2004 Google account that they enabled SMS 2FA on one day, without any notice, but it has the wrong phone number. I have the username, password and the recovery email address is set to another I own too, but without the SMS code I'm hosed.


You should just determine which carrier hosts the phone number and then go get a job there as a customer service agent or store employee. You'll get full permissions to change accounts, so you'll be able to make the change, fix your gmail, then change it back.

You probably risk some legal fallout though, so be cautious.


This reminds me of the women who sleep with Meta employees to get their accounts unlocked. It's 2026, we gotta do what we gotta do to get our digital lives back.


I don't know why verizon etc.. don't charge like $0.25 cents per sms. Then these provider would stop sending too many sms.


I recall reading that twitter was getting "scammed" because there were some phone services that cost money to receive texts (and possibly some of it was being passed on to the customer of said phone service) and they were getting spammed with phone verifications to get the payouts. I guess when twitter extorts your phone number out of you under false security pretenses and then uses it for advertising that's legit but if some one tries to a get a cut for themselves it's a big problem.

It occurs to me this "force you to send the sms" might be a way to avoid exactly this sort of thing.


They used to do just that, though people could pay about $25-30 (in like, 2008 dollars! So that’s closer to $47 today) for ‘unlimited text plans’.

I know you mean charge just these bulk senders, but if they didn’t charge consumers a similar rate too, whoever wants to spam SMS can just set up farms of consumer SIMs and dump them onto the network that way. In fact, they already do this.


That clarification matters, but I don't think it makes the privacy concern disappear




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: