Hacker News new | ask | show | jobs
by jjav 1203 days ago
> With SMS, I can show my ID to the Verizon rep, get a new phone, and I'm good to go.

Which means that anyone else who can fake an ID is good to go with that verizon rep. Or the rep themselves.

I will always avoid connecting any account to SMS if at all possible, it's the worst of all options.

TOTP is the best, as it is an open standard and doesn't tie you to any device nor any vendor.

> I prefer SMS for 2FA because some authenticator apps get tied to a device.

No need! Just save the TOTP seed in a safe place such as a computer under your control (i.e. not a phone) or even a piece of paper in a safe.