Phone numbers as identifiers: The problem with SMS-based authentication
I recently heard about a Facebook user who encountered a very concerning login experience. After entering a password recovery code he had received via SMS, the user was accidentally logged into someone else's Facebook account.
The phone number the user had used to receive the SMS...