Unfortunately, most sites do not allow you to turn off SMS recovery even if they offer other 2FA options.
Security is only as strong as the weakest link, and SMS is very weak.
Unfortunately, most sites do not allow you to turn off SMS recovery even if they offer other 2FA options.
Security is only as strong as the weakest link, and SMS is very weak.
Overall the situation isn’t great.
You can save the QR code that was used during setup to repeat the onboarding at any time. You can also use Authy, 1Password, or another service that lets you store the one-time password somewhere else. Or use U2F devices when possible.
It was a pain for all of them, but it was worst for the ones that I had no other auth systems set up. (Or the ones that had my old phone number for SMS still, even though I thought I'd changed it everywhere.)
In the end, there's still no good system for real security. You're either stuck with a device you might lose (or someone might steal), or stuck with an account that you might cancel (or someone might steal). Or use biometrics which are just not ready for prime time.
When you’re at Google scale, all of these methods have real world flaws.
So the likelihood of moving to a new phone without those codes transferred is very high. Not exactly an easy experience.