As others have said, it is not that SMS 2FA is insecure; it is that thieves have figured out how to defeat it using SIM jacking and a bit of facebooking and googling. It is now trivial to figure out your home town, your favorite pet, etc. Also as others have said, the current alternatives have their problems. What if you lose all your Yubi keys? What if your phone was accidentally wiped and you never got around to ba…
It is 100% insecure, and been exploited for nearly a decade.
1. Anybody with access to raw SS7 network can basically click a finger, and have you traffic rerouted
2. GSM interception gear is widely available
The person who invented "SMS verification" was a round idiot