Manav.id
Vertical · 5 min read

Selling the number as a trust signal: what carriers could offer banks instead of SMS

Selling the number as a trust signal: what carriers could offer banks instead of SMS

There is a woman in a carrier retail store in Leeds verifying a customer's passport and address to activate a line. That interaction is the most rigorous consumer identity event in the entire digital economy, and the carrier's commercial expression of it is charging a bank a fraction of a penny to deliver a six-digit code.

What could carriers offer banks instead of SMS?

A signal about the line rather than a code delivered to it. Carriers know when a SIM changed, when a number was ported, and how long the current holder has held it. Selling that as a verifiable attestation is worth more than continuing to sell a delivery channel that is being attacked.

Key takeaways
  • Existing carrier identity APIs attest to attributes — SIM tenure, swap recency, device binding. Relying parties increasingly need attestation of an act.
  • The A2P delivery product is being deprecated by the relying parties who buy it, on security grounds, which is an unusual and terminal market position.
  • Moving from attribute attestation to act attestation requires carriers to accept a liability position they have historically avoided, and that is the real obstacle.

Start with the shop floor

SMS one-time codeA bearer secretNo context about the lineVulnerable to swap and interceptionRelayable in real timeSigned line attestationLast SIM change dateLast port dateTenure of current holderSigned, verifiable offlinevs
One is a shared secret in transit; the other is a signed statement about the line.

The identity work happens at the counter. A person arrives, presents documents, has them checked against a physical face, signs a contract, and walks out with a line. In much of the world that interaction is regulated, recorded and retained.

Then the customer goes home and their bank sends them a six-digit code over that line, and the carrier earns a fraction of a penny for carrying it.

The gap between the value of the first event and the price of the second is the entire business problem, and it has been visible for a decade.

What carriers currently sell

The existing identity product line is genuinely useful and worth crediting. Silent network authentication verifies that a device on the mobile network holds the number in question. SIM swap APIs report the recency of a profile change. Tenure signals report how long a number has been held. Number verification confirms possession without a code.

Every one of those is an attribute. They describe a state of the world — this SIM has been in place for eighteen months, this number is on this device — and they are consumed as risk signals feeding a decision engine.

What relying parties are moving toward

Risk signals are losing ground for high-consequence decisions, for the same reason everywhere: an attacker who controls the number satisfies every attribute test. Tenure is long, the SIM has not been swapped recently, the device holds the number — all true, all irrelevant, because the attacker is the one holding it.

What a bank actually needs at the moment of a payment is an attestation of an act: this named customer, using a credential only they hold, confirmed this specific transfer.

Product typeQuestion answeredSurvives number takeover?
SMS OTP deliveryWas a code delivered to this number?No
Silent network authenticationDoes this device hold this number?No
SIM swap recencyHas the profile changed recently?Partially — only detects the swap
Act attestationDid this human authorise this transaction?Yes

The product a carrier could build

Carriers are well positioned for act attestation and almost nobody is doing it. The components exist:

  1. Issue a device-bound credential to the subscriber at the identity-verified moment — in store, or through the app after a verified activation.
  2. Expose an API through which a relying party requests an authorisation for a specific action, rendered in plain language.
  3. The subscriber confirms on their device. The carrier returns a signed receipt bound to the rendered action.
  4. Price per authorisation, not per message.

The economics are the attractive part. A payment authorisation is worth orders of magnitude more to a bank than a message delivery, and the marginal cost is comparable.

The obstacle nobody wants to name

It is not technical and it is not commercial. It is liability.

A carrier delivering a message is a conduit. A carrier attesting that a named human authorised a transaction has made a representation that a relying party will act on and litigate over. That is a materially different legal position, and carrier legal departments have spent thirty years avoiding exactly it.

There are workable answers — attesting to the cryptographic fact rather than to the human's intent, contractual limitation, and the observation that the receipt is verifiable independently so the carrier is not the trusted party in a dispute. But any carrier product strategy that does not address liability in its first page is not a strategy.

Why the window is finite

Two things are happening simultaneously. Relying parties are moving away from SMS for high-assurance use on security grounds, which shrinks the existing product. And device platform vendors are shipping their own credential infrastructure, which does not require a carrier at all.

Carriers hold one asset the platform vendors do not: a regulated, documented, in-person identity verification event. That asset does not expire, but its commercial expression currently does, and there is no obvious third window.

Why the attestation is the better product

Commercial and security comparison
DimensionSMS codesLine attestation
What the bank learnsA code arrivedWhen the line last changed hands
Defeated by SIM swapCompletelyReveals it
Value per queryFallingRising as codes are abandoned
Carrier positionA commodity channelA signal only carriers hold

Objections and honest limits

“Banks already buy SIM-swap signals.” Some do, through intermediaries, as a risk score. The argument is for a signed attestation the bank can verify and retain as evidence, rather than a score it must trust.

“Privacy regulators will object.” A date is less disclosive than a message containing a code, and the subscriber can be the one who authorises the attestation. Designed that way, it is a privacy improvement rather than a cost.

Designing the attestation

  1. Signed by the carrier, verifiable offline. So the bank retains evidence rather than a score.
  2. Minimal: dates and tenure, not content. Less disclosive than the SMS it replaces.
  3. Subscriber-authorised where possible. Which improves the privacy posture and the legal one.
  4. Retained by the relying party. So a later dispute is a retrieval.

Terms used here

Line attestation
A signed statement about a subscriber line's recent history rather than a message sent to it.
Tenure
How long the current holder has had the number, which is the single most useful anti-swap signal.
Bearer secret
Something whose possession alone grants access, which is what makes a one-time code relayable.

Frequently asked questions

Is this not what mobile identity consortia already do? Consortium products have focused on attribute attestation and network-level authentication. Act attestation — a signed receipt bound to a specific rendered transaction — is a different product and is not, to our knowledge, offered at scale.

Would relying parties pay per authorisation? Banks already pay far more than message rates for fraud tooling that performs worse. The pricing question is real but it is not the binding constraint.

What about subscribers who change carriers? A credential issued by a carrier and bound to a device need not die with the service relationship, but the commercial and governance design for that is genuinely unsettled.

Does this compete with bank-issued passkeys? Partly. The carrier's differentiator is the in-person verified enrolment and reach across relying parties that will never each run their own enrolment.

Why is an attestation better than a code? A code is a bearer secret in transit. An attestation is a signed statement about the line that reveals the swap rather than being defeated by it.

Is this more privacy-invasive? Less. A date is less disclosive than a message containing a code, and the subscriber can authorise the attestation.

Why would carriers do this? It is a signal only they hold, its value rises as codes are abandoned, and it repositions them above a commodity channel.

Where this fits in Manav

Manav puts the authorising party back in the loop for the changes that matter, with a signature bound to the specific change and verifiable by a counterparty without calling you.

See change authorisation →

Sources and further reading