Why Every App Suddenly Wants Your Phone Number

Apps ask for your number in the name of security. But SMS is a lousy lock and an excellent label — and the industry knows exactly which one it’s collecting.

You download an app to look at someone’s sourdough, and before you’ve seen a single loaf it wants your phone number. Not your email — you could hand over a throwaway for that, and both of you know it. Your number. The prompt says it’s “for your security,” with a little padlock icon, the way a hotel says the resort fee is for your convenience.

Here is the thing the padlock is hiding: a phone number is a genuinely mediocre security device and a nearly perfect identity device, and the industry collects it for the second reason while telling you the first.

Consider what makes the number valuable. You probably have several email addresses and can mint a new one in thirty seconds, which makes email a terrible way to know that today’s user is yesterday’s user. A phone number is different. Most people carry exactly one, keep it for years through job changes and apartment moves, and got it by showing up in the physical world and opening an account with a carrier. It is, in effect, a government-adjacent ID that nobody had to legislate into existence. In database terms it’s the join column — the one field that lets a company connect your account here to your account there, to your contact list, to data brokers’ files, and ultimately to a person who pays a monthly bill. An email identifies an inbox. A phone number identifies a body.

Now consider the security claim on its own merits. NIST, the U.S. standards body whose digital identity guidelines effectively set the baseline for the industry, downgraded SMS as an out-of-band authenticator back in 2017, in Special Publication 800-63B, on the grounds that text messages can be intercepted or redirected — the draft even used the word “deprecated” before the final version softened it to a restriction. The guidance has since been revised again, but the skepticism toward SMS has survived every round. The failure mode has a name, SIM swapping: an attacker convinces or bribes a carrier to move your number to their phone, and your “second factor” arrives in their pocket. As Jeremy Grant of the Better Identity Coalition put it to WIRED, a phone number is only an identifier, and in most cases a public one — “if it’s not a secret, then you can’t use it as an authenticator.”

So the same property that makes your number a bad secret makes it a great label. It is public, stable, unique, and attached to you. That is not a coincidence the industry has failed to notice; it is the entire point. The padlock framing is not exactly a lie — SMS codes do raise the cost of some attacks — but it is a misdirection about which benefit is doing the collecting. Security is the reason given at the door. Identity is what gets filed away.

Once you see the number as a join column, other small frictions snap into focus. Why apps that have no plausible reason to text you still insist on “verifying” a number at signup. Why losing your number — moving countries, missing a carrier payment — can quietly lock you out of years of accounts, as if your lease on your own identity had lapsed. Why “log in with your phone” spread so much faster than any genuinely more secure alternative. Each of these is odd if the number is a lock. Each is obvious if the number is a key — not the kind that opens a door, but the kind a database uses to make sure every record with your name on it points at the same person.

The honest prompt would read: “Give us the one identifier you can’t change, so we can recognize you everywhere. As a bonus, we’ll text you a code that the standards bodies have been side-eyeing for years.” Nobody would tap agree. So we get the padlock instead — a security story told about an identity harvest, one verification code at a time.