Earlier quoted context omitted.
There are a numbers of things here that are true. * Applications that take a phone number for one reason (2FA or otherwise) and also use it as a single factor for account reset are less secure in the case of number recyling. * Applications that do 2FA via SMS do not necessarily do account resets via SMS * 2FA over SMS is more secure than just having a password to secure an account. I am sorry your girlfriend had this…
Ok, makes sense. Thank you for the kind response and I approve of most of it. I think we will have to agree to disagree on the last * though. I think that statement is very much 'it depends.' I apologize for going in circles one more time... but by not providing 2FA SMS, it is impossible to f'ck it up or be abused. Right?
There’s a lot more at play here, and “just don’t” isn’t a nuanced enough answer to 2FA by SMS.