I'm so glad I'm out of the family tech support "business"; if only firing real customers were so easy...
Alternatively, use a physical token as the 2nd factor, then no recovery number is required.
T-Mobile sells me out once a year - I don't even give them my real name, they must get it from my credit card or something. This year I used a fake name "authorized user" card, still waiting to see if that keeps my latest number out of the databases or not, around nine months to go.
My T-Mobile number was simjacked last year, though afterwards once I reclaimed my number they let me set up a "secret word" that the person calling in has to give them and I haven't had any problems since.
It's disgusting to think about the record sharing, and I doubt it even protects against SIM swapping (or does it?).
Looking at that link, pretty much none of the major US banks (Bank of America, US Bank, Wells Fargo, PNC, Chase, etc.) seem to support software 2FA token solutions (e.g., Google Authenticator, Authy, etc.). Not gonna lie, this is abysmal.
For credit cards with awful security, they don't care because the money they get from making it easy to sign up and use their services is far, far greater than the costs of dealing with fraud.
How accurate is this hypothesis of mine? It really can't be an education thing because I'm sure these companies have great engineers working there, both at the lower ranks and (at least sometimes) in upper management.
Fidelity has a brokerage account, free checks, free ATM withdrawals via debit card, maybe also your 401k, free money wires, automatic investment etc.
The only thing they don't have are branches where you can deposit cash, but that's really never necessary - in an extreme case you can open another bank account, deposit cash, transfer to fidelity and immediately close it.
I'm not sure why anyone uses a bank other than Fidelity.
* I just tried to login with the first 8 characters of my password and it was not successful. * Also this password is autogenerated and contains plenty of special characters. * Their 2FA system no longer depends on the concatenation of password + token.
Also this reminds me of another HN discussion[1], which basically boiled down to the question of "Do you really think the only thing the bank does to log people on is to check the username and password?" I certainly hope not.
They use normal TOTP for 2FA so it'll work with whatever authentication software you use.
However they follow the modern tech trend of not having live tech support; you have to email them for support. But I've heard response times have gotten better recently.
I moved most of my money into RH for the interest, but still maintain Chase checking and credit card accounts. For sonething as important as banking, there's no substitute to having tons of physical locations with humans. For example I recently went to the bank to deposit tax refunds, which were not 'normal' checks. I don't think you can even deposit normal checks into RH. And I trust Chase's fraud protection systems more than RH.
Put a few hundred thousand in the bank and you'll get all that stuff for free!
https://debtfreegeek.org/2017/09/22/become-usaa-member-even-...
https://www.usaa.com/inet/wc/investments-update?akredirect=t...