Is SMS 2FA enough for most of the people today? Yes
Is SMS a cost-benefit solution for most uses? Yes
Is SMS 2FA enough for most of the people today? Yes
Is SMS a cost-benefit solution for most uses? Yes
It’s free, and requires a tiny bit of additional configuration to enable. No reason not to offer it.
With large enough numbers, you'll see everything, but you don't even need large numbers to get people whose lives are made more difficult by technology.
It great for keeping people using scripted attacks against a huge list of accounts. It isn’t really to keep people specifically after your account out.
If somebody wants your shit and specifically your shit.... they’ll get it...
How? I don't think Brian Krebs has been hacked, even though he's extremely targeted by hackers (his site is literally the benchmark for performing DDOS attacks on).
This, coupled with a "I know what I'm doing, never let support reset my password" option that disabled changing the user's password for anyone without direct write access to the production database was pretty good for security, I feel.
Configuring the seed, remembering an extra password to use the OTP... For me it's not that hard, but probably my mom will need some help in order to remember all the steps...
I know some services require SMS in order to force collection of user’s phone number, for data selling purposes and to prevent bots.