Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> My university is known to offer the option payment of tuition through a popular online system. This option is done by sending each student, at the start of the year, an SMS with a link to a payment option.

They don't email this information? They don't put it on an online notification system? I have no idea why SMS seems like the logical option for this.




Kids are more likely to text, less likely to email these days. I can understand why they’d use SMS for their target demographic.

That doesn’t justify the security implications of doing this...


Do kids still text or is that a generation or two removed from the current iMessages/WhatsApp/Signal/WhateverComesAfterSignalBecauseImOldAndDontKnow?


I'm sure they'd prefer to receive notifications from their university on WhateverComesAfterSignalBecauseImOldAndDontKnow, but I imagine that SMS is the 2nd best thing (and probably still generates eye-rolling about the university being old fashioned).


But then you're stuck logging into the payment portal and filling out the form information with your phone, which is my own personal hell.


Oh, I'm with you. I'd much prefer to pull this up on a real computer so I can efficiently fill things in. I've adapted to typing on glass with my thumbs, but I'm not very good at it.


I do not know why they do this. I really wish they would stop.

I have considered faking the SMS message, with the payment link saying "imagine this wasn't a warning message but an actual payment request, please tell the university this is unsafe". But sending that kind of mass SMS is not easy, nor is finding the correct phone numbers.


The email option is arguably an easier (cheaper) attack vector than the SMS messages would be.


Yeah, I thought of that after I wrote it. Send it to all the university accounts you can get your hand on, see who you catch. It's probably just personal preference showing through as well, as I wouldn't be comfortable paying with my phone. I also have no idea how people substitute their PC with an iPad or phone. Much harder to fill out a page of fields and navigate around, and I'm sure that Google Pay won't support $15,000 payments.




Consider applying for YC's Fall 2025 batch! Applications are open till Aug 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: