D
2

Two-factor via SMS is still better than nothing, fight me

I used to push everyone I knew toward authenticator apps and hardware keys, reading all the posts about SIM swapping nightmares last year. Then my dad's phone died during a work trip to Phoenix and he was locked out of his bank for 3 days because the app required a device he couldn't access. Has anyone else kept SMS 2FA as a backup even after switching primary methods, or am I just being stubborn about convenience?
1 comments

Log in to join the discussion

Log In
1 Comment
jesse_cooper
My SIM swap story from last year taught me the same lesson a different way. My neighbor lost $4,000 because someone ported his number out, but the fix isn't dropping SMS entirely, it's keeping it as a fallback only. You can set up an authenticator app as your main method and still leave SMS on for recovery, most banks and Google let you do that. The problem is when people treat SMS like it's the only option or like it's worthless. It's weak but it's still a second lock on the door, and being locked out for 3 days is its own kind of loss. So no, you're not being stubborn, you're being practical about what actually works for real people.
8