LOG-033 ·
My Phone Number Is a Rented Address
Sixty-one accounts treat ten digits I do not own as proof that I am me. I audited every one, and the number of places a SIM swap could hurt me is now down from 34 to 6.
- Words
- 734
- Est. read
- 3.2 min
- Confidence
- 0.90
- Topics
- identity, telecom, audit
I have held the same mobile number since 2009. I have never owned it for a single day. It is leased from a carrier, administered by employees I will never meet, and transferable to a stranger who tells a support representative a convincing story. Yet somewhere along the way, half the internet decided those ten digits are me.
This month's audit: every account that uses my phone number for authentication or recovery, counted, categorized, and where possible, evicted.
The census
Method: I exported the login-item list from the password manager (247 entries), then checked each active account's security settings by hand. 19 minutes a night for two weeks, 4 hours 26 minutes total. Tedious is the price of true.
| Category | Accounts |
|---|---|
| Number stored, unused for auth | 27 |
| SMS as optional second factor | 21 |
| SMS as the only second factor | 9 |
| SMS can reset the password alone (recovery) | 4 |
| Total accounts touching the number | 61 |
The last two rows are the ones that matter. For 13 accounts, control of my phone number meant control of the account, full stop. Two of those were financial. One was the email address that everything else recovers through, which is the kind of dependency loop this log exists to find.
What a SIM swap actually costs
The attack is not exotic. A 2020 Princeton study ran five port-out attempts against each of five US prepaid carriers and succeeded 39 times out of 50. The FBI's IC3 logged $48 million in reported SIM-swap losses in 2023, and reported is the floor, not the ceiling.
The defense on the carrier side is a port-out PIN, which I set in 2021 and which my carrier's own support flow has asked me to read aloud over an unauthenticated call twice since. The PIN is a speed bump administered by the same institution that constitutes the vulnerability. I keep it set. I do not count it.
The eviction
Over the two weeks I moved every account that allowed it to TOTP codes from an app I control, with hardware keys on the eight accounts I classify as load-bearing (primary email, password manager, domain registrar, two financial, cloud infrastructure, and the two social accounts that could be used to impersonate me to people I know).
Results:
| State | Before | After |
|---|---|---|
| SMS-only second factor | 9 | 3 |
| SMS password recovery enabled | 4 | 1 |
| TOTP or hardware key | 14 | 43 |
| Number removed from account entirely | n/a | 22 |
The stubborn residue: three accounts, all financial institutions, that offer no second factor except SMS. One is my county's property tax portal. Regulation apparently froze these institutions in 2012. The one remaining SMS-recovery account is an airline whose security page returned a 500 error on four separate days, which I am choosing to read as an answer.
For those six, the mitigation is a second number: a VoIP line, paid annually, port-locked, used for nothing else, stored nowhere else. Attack surface is not eliminated. It is relocated to a number that does not appear in any breach dump tied to my name (I checked the usual corpora) and that no carrier store employee can port with a sad story.
The general principle
A phone number fails every test I apply to infrastructure I rely on. I cannot self-host it. I cannot verify its integrity. Its failure mode is silent and total. And its administrative perimeter is staffed by the lowest-paid people in the chain, targeted by the most motivated attackers in the chain.
The number is an address, and addresses are for reaching me, not for being me. Anything that treats reachability as identity has confused the envelope with the signature.
The audit surfaced one more thing worth stating plainly: I had 27 accounts holding the number for no functional reason at all, pure data sediment, each one a future breach-dump row linking my name to my number. Twenty-two of them let me delete it. That alone was worth the four hours.
Confidence 0.90 that my exposure to a SIM-swap attack is now limited to accounts whose combined blast radius I could absorb without losing a night's sleep. The 0.10 is the property tax portal, which holds my home address and accepts ten rented digits as proof of ownership of the one asset I actually hold title to. I have written to the county. I will report back with their reply, or in the more likely branch, with the absence of one.