Earlier quoted context omitted.
So don't allow password reset over SMS. Email is hardly beter than sms, and we do password resets over email.
"Email is hardly better than SMS" is an absurd claim. As has been written SMS is not secure, easily hijacked, and potentially transmitted in the clear. By contrast email can be made arbitrarily secure nowadays via e.g. DANE/STS-MTA, and it's entirely up to an email provider how secure mailbox access is. Saying that "email is hardly better than SMS" when the former can be secured via DNSSEC/DANE and where the mailbox…
Thats basically fantasy territory for an average user. If you consider the real world" abundant phishing, etc. then you will realise that in practice there is very little daylight between them.