Compared to what? Better than not having it? Yes. Better than committing a 4,096Kb PK to memory and confirming all interactions with mental arithmetic? No.
The article says "We found 17 websites on which user accounts can be compromised based on a SIM swap alone", that seems like a pretty clear indication that it can be worse than nothing. I happen to think the benefits of SMS 2FA, even when working as intended, are negligible. It seems like a bad idea to waste the finite amount of developer good will we have asking services to implement it. Literally the only attack th…
2FA requires you to have 2 factors at the same time. e.g. When I log onto amazon from a new browser with valid username+password it additionally requires me to confirm via my phone number.
1or1FA (e.g. reset your password via SMS if you forget your password) is just increasing the attack area on 1FA (would be more secure without it).
Problem it's trying to solve, is that it's conventionally unacceptable to lock people out of their accounts.