The problem is when people forget the “2” part and allow SMS to be a substitute for having the password. That should never be done.
The related problem is that, as a used, it’s hard to tell when some service wants your number for proper 2FA, or when they want it as a separate authentication mechanism they just happen to call “2FA.”
...or when they want it to be able to call or text you with other BS entirely. I hesitate to give my cell number to any company. I have a separate number (formerly a landline, now strictly a voicemail box) that I use specifically for companies.
I gave my cell number to a new dentist recently, thinking "medical office, probably important they be able to reach me." That turned out to be a mistake. They subscribed me to an automated appointment confirmation service, and they also send me a text (from a different number than the confirmation service) after I finish a visit to solicit reviews. This is exactly why I hate giving it out.
1. They draw from fixed unimaginative pools of often-overlapping questions, so that a breach in one company compromises you on multiple others.
2. Unlike a password, the actual secret question is often plaintext
If I had to design a replacement... The user would always be allowed to define custom questions, all questions could be assigned multiple synonymous correct answers (e.g. "Dr. Smith", "Doctor Smith"), and they all go through a one-way hash with salt.
The account has no associated number so it's not a verification at all!
I'm using it with the Titan keys (they're not my favorite, but work) and it works pretty well. I can't do as much 3rd party stuff, but I only keep my Google account (right now) for my old email address that's already forwarded to my new email address, Google Music, and Google Pay, so that doesn't affect me much. If you use a lot of 3rd party apps or get your mail via IMAP and the like, it's going to be more difficult.
A weird thing is that Google doesn't seem to allow for U2F key use without Advanced Protection turned on, which is puzzling to me.
The PSTN and phone system telecom industry in general is not hardened. The more you see the underpinnings of it, as I have, the more it looks like a bunch of 30-year-old bullshit held together with the technological equivalent of duct tape and twine.
SS7 needs to be burnt to the ground, the ashes stomped around on a bit, and shoveled into a dustbin.
This happens to every system eventually if it lives long enough.
a) only a certain elite group of people or companies will be able to use it (in this case, PSTN operators)
b) total trust between all parties using it, so there's no need for provably-hardened cryptography.
both of which are now laughable in a modern network security threat environment.
In this case SS7 was just never designed with the concept that malicious third parties might get access to it, or that it would not be operated by RBOCs (regional bell operating companies), or the international equivalent thereof (national run telcos such as British Telecom, Telecom Italia, etc).
No one is forcing you to use the same number for everything. And don't complain that it's just too expensive and unrealistic to maintain more than one phone number, because that is simply untrue.
Yes, I am aware of NIST's guidelines, regarding SMS as a layer of multi-factor authentication [0]. Those guidelines are for large organizations that dictate user behavior in a top-down hierarchy. Individual security profiles are much more flexible, and don't require the same degree of adherence to recommended practices.
Absolutely minimal 3rd party involvement, I'd say less than most web browsers these days as there really isn't a significant attack surface for the apps.
https://en.wikipedia.org/wiki/HMAC-based_One-time_Password_a...
https://en.wikipedia.org/wiki/Time-based_One-time_Password_a...
https://github.com/google/google-authenticator/wiki/Key-Uri-...
It uses Verisign's VIP app instead of Google Authenticator (or Authy or whatever).
Personally I wouldn't risk it since it could mean risking getting locked out of your account.
Most of these attacks are social engineering.
Paypal’s ceo is head of symantec’s board. Paypal must use symantec software wherever it is available, and their mfa is no exception.
This is still baffling as you say though, because symantecs mfa system does allow for other mechanisms.