I really want to know, why has everyone moved to SMS 2F"A"? What was wrong with authenticator applications? Were they really THAT user unfriendly?
my phone recently just died. only two years old. all my authenticator stuff is gone. sms is fine, I just move the sim to a new phone
How SMS fraud works and how to guard against it
31–40 of 107 posts
Re: How SMS fraud works and how to guard against it
#32I really want to know, why has everyone moved to SMS 2F"A"? What was wrong with authenticator applications? Were they really THAT user unfriendly?
Yes, that's pretty user unfriendly.
It's a lot more common to lose your phone than lose your phone number.
Re: How SMS fraud works and how to guard against it
#33I really want to know, why has everyone moved to SMS 2F"A"? What was wrong with authenticator applications? Were they really THAT user unfriendly?
People lose their phones and then your authenticator app doesn't work anymore, even if you restore from backup. And then the recovery mechanism is often a giant pain. Yes, that's pretty user unfriendly. It's a lot more common to lose your phone than lose your phone number.
Re: How SMS fraud works and how to guard against it
#34Re: How SMS fraud works and how to guard against it
#35Earlier quoted context omitted.
I prefer SMS for 2FA because some authenticator apps get tied to a device. I'm worried about losing my phone and being locked out. With SMS, I can show my ID to the Verizon rep, get a new phone, and I'm good to go.
Only downside is the verizon rep giving your sim to someone who deepfaked your voice.
Re: How SMS fraud works and how to guard against it
#36Earlier quoted context omitted.
I don't think that folks so much "moved" to SMS 2FA as much as were with it from the start. SMS 2FA is so ingrained in the finance/fintech industry that it's pretty rare for me to see a financial company offer the option to set up an Authenticator 2FA. Also, there is always some part of the consumer population that is still not on a smartphone and even if they are, they may not be "app-savvy" where they know how to i…
I prefer SMS for 2FA because some authenticator apps get tied to a device. I'm worried about losing my phone and being locked out. With SMS, I can show my ID to the Verizon rep, get a new phone, and I'm good to go.
Re: How SMS fraud works and how to guard against it
#37I really want to know, why has everyone moved to SMS 2F"A"? What was wrong with authenticator applications? Were they really THAT user unfriendly?
Because lots of us upgrade phones every couple years, or have dropped a phone and had it break, or get water in it or something. It's all too easy to realize after the fact you needed to transfer something between the old phone to the new phone to keep the authenticator working. Sometimes that's not available (phone damaged), or don't realize you need it until after you've already sent the phone in for trade in. So y…
This is just a matter of using one of the many TOTP authenticators which allow backups of the keys.
If people drop or lose their phones, do they lose all their contacts, photos, passwords? I bet not. I am pretty sure this is a solved problem by now.
Moreover, even if you do lose the keys, that's what account recovery processes are for.
Re: How SMS fraud works and how to guard against it
#38I really want to know, why has everyone moved to SMS 2F"A"? What was wrong with authenticator applications? Were they really THAT user unfriendly?
my phone recently just died. only two years old. all my authenticator stuff is gone. sms is fine, I just move the sim to a new phone
Obviously not something anyone who respects their privacy would subject themselves to, but it seems to me like the easy path leads to these things being backed up.
Obviously if google has your 2FA keys and you were using 2FA keys to log into your google account then you would need to recover your account, but you would be stuck in the same situation as if you had damaged/lost your SIM (e.g. if you lose your phone).
Re: How SMS fraud works and how to guard against it
#39It pains me to say this since Bank of America sucks, but their system now supports adding a Yubikey for login, nearly as good as Schwab before they stopped issuing physical TOTP tokens in 2020.
Re: How SMS fraud works and how to guard against it
#40I really want to know, why has everyone moved to SMS 2F"A"? What was wrong with authenticator applications? Were they really THAT user unfriendly?
my phone recently just died. only two years old. all my authenticator stuff is gone. sms is fine, I just move the sim to a new phone