Of course there are much better 2FA options, but for the general public, they are probably too complicated to use.
Everyone understands SMS.
Of course there are much better 2FA options, but for the general public, they are probably too complicated to use.
Everyone understands SMS.
In my strictly personal opinion, responding to a notification that asks if a login attempt is you is clear enough that people need minimal training to make use of it. This might just be me, though.
In my career, I've definitely seen people actively choose SMS over other factors on offer. It was easier for them, and in many cases shouldn't have been offered. Your point about SMS being better than nothing is wise and true and insightful, but it's perhaps not always the question as faced in practice.
Your experience and standards of clarity may be different from mine, obviously.
In all these situations, I've found companies which offer a back up SMS option very valuable since it usually gets delivered.
Unless you're using HOTP to mean HOTP and all extending schemes.
I tend to use TOTP for systems where I'm concerned about offline usage. But again, YMMV.
Obviously banks are a place with a lot of low-value targets and a few very high-value targets, but the cost to implement MFA is the same so they might as well do it.
Hint: if a store ask for a phone number to get a discount, try the local areacode then 634 5789. This is from an old song, and many people seem to have created "anonymous" account with it!