- phonelines can be hijacked (this article)
- DNS can be hijacked in a similar manner
- SMS can be hijacked (for 2FA via text message)
I guess 2FA using an authenticator app is the way to go for now. Do you guys agree with the removal of backup phone numbers recommended here? Seems reasonable to me but scary; I've lost my phone(s :( ) before. I do have backup codes generated though.