SMS 2FA

Saw this article, SMS 2FA is not just insecure, it’s also hostile to mountain people. Just the title took me thinking, heck, what a genius way to place it!

I’ve been a traveller for a while, and changing SIM cards frequently was the norm. Never ever in my life, I used a SIM card to call someone.

Except some edge cases, mostly calling taxis, pre taxi apps times.

I hate, absolutely hate, these SMS 2FA. Not a single service of mine is connected to any of my phone numbers. Maybe except my bank, because most banks are stupid. And, well, I guess they’re required by law to do that. My bank — mono bank — is the smartest in Ukraine, it’s similar to Revolut. So it never uses my SIM card number for anything. I believe it’s still a part of my account, but I also believe it’s easy to change my phone number there. And I believe it’s rather the exception than the rule.

I use only TOTP app for that, and great news, all that is what iPhones (and iPads, and macOS too) comes with by default. It’s super simple and super useful. And it adds a huge protection too.