> Advocate for apps and hardware keys all you want, don't dump on an extemely valuable technology, please. The worst possible situation would be for someone to "take your advice" and refuse to use any 2FA at all.
It was your interpretation that I advise people to not use any 2FA at all. I won't honor the request to not dump on SMS, as I am perfectly happy to dump on an "extremely valuable technology" on technical demerits, on the grounds of security while simultaneously acknowledging highly debatable, highly questionable positive merits on grounds of user-experience, which more often than not oppose each other. Why do you construct a single-faceted single-shot ability for us to evaluate SMS? It sucks and it also doesn't, and saying it sucks isn't going to entirely destroy its already-terrible reputation amongst technicals. I would much rather have a message sent to my email address since that is harder to lose than a text message or phone number, and it costs me far less per month.