Don’t do 2FA over SMS. Just don’t. That’s a big bag of hurt that is just begging for someone to stand up and come looking for it.
Once you eliminate that, what part is left of your business model?
Once you eliminate that, what part is left of your business model?
In the meantime, try explaining a random user how to setup and use a TOTP for your application, I wish you good luck.
Once every business is able to enable TOTP-based MFA for their applications, it'll be a great day for cyber and my side project will cease existing ¯\_(ツ)_/¯.