username and phone is not security factor.
password is 1FA.
SMS is 2FA (not a great one, but still). Coinbase failed at 2FA. 2FA is critically important; that's why it exists.
password is 1FA.
SMS is 2FA (not a great one, but still). Coinbase failed at 2FA. 2FA is critically important; that's why it exists.
Not sure why you discount username and phone either. Each of these is an additional layer of security simply by being more information an attacker needs to collect and associate. Coinbase doesn't publish a list of usernames. And how would someone associate phone numbers back to them?
It’s unfortunate how much is out there.