The Voice Line / the line
how a voice is identified
The account you open by talking
A telephone account has no login to type. The caller is identified by something said aloud - a passcode, the answer to a question, or the fact of calling from a registered number. This page sets out how that works and why a credential that travels as speech is weaker than one that travels as a secret.
Desk spec
- passcode
- spoken
- security question
- one
- registered number
- if set
- second check
- large bets
- typed secret
- none
- verified callers
- 1,240 of 1,800
the price read aloudThe spoken price, obtained after a hold. Across 1,200 matched bets it was worse than the screen in 408 and worse by a mean 2.7%.
the recordingThe record of what was said, kept for a fixed window. Of 96 disputes it decided 71, and 46 of those against the caller.
the channel costHold time plus call time. A mean 9.5 minutes on the line, or 4.75 where a number is billed at 0.50 a minute.
Direct answer
A telephone betting account identifies the caller by something said aloud: a passcode, the answer to a security question, or a call from a number already registered to the account. There is no typed secret, so the credential is audible to anyone in the room, and a large instruction is held for a second check rather than taken on one answer.
| check | what it is | what defeats it |
|---|---|---|
| spoken passcode | a code said aloud to the line | anyone who has heard it, or a listener in the room |
| security question | an answer the account holder set | a fact that can be looked up |
| registered number | a number bound to the account | a number that can be ported or spoofed |
| second check | a repeat before a large instruction | the same wrong answer given twice |
| 1 of 1,800 sampled calls was refused at the line | 99.9% passed | |
two credentials, one account
screen account
typed secret, hashed, never displayed
an attacker needs the secret
voice account
spoken passcode, said into a room
an attacker needs to be in the room,
or to have listened once
so the voice credential is audible
and the typed credential is not
The line is not insecure by definition - a registered number plus a spoken passcode plus a repeat is three checks. The point is which checks exist and what each one is.