> Why does it have to be 6 digits?
See https://www.rfc-editor.org/rfc/rfc4226#section-4 and https://www.rfc-editor.org/rfc/rfc4226#appendix-E.1
> Especially if it expires in like 5 minutes?
Usually it's 60 seconds. See https://www.rfc-editor.org/rfc/rfc6238#section-5.2
> And why can't we have some sort of centralised solution to all this?
So, Single Sign On (SSO)? Who do you trust to run the SSO services? Google, Microsoft, Facebook? Bring your own SSO (this used to be a thing that some sites supported, but it was too complex for the average user and too much support burden for the average site).
> The authenticator apps are probably worse than SMS in terms of the interface.
Worse how? These apps solve a different threat model (documented in the 2 RFCs mentioned above. Particularly note:
* HOTP Intro: https://www.rfc-editor.org/rfc/rfc4226#section-2
* TOTP Intro: https://www.rfc-editor.org/rfc/rfc6238#section-1
> I am starting to think the amount of manpower wasted on this globally is way more than the fraud preventing in terms of economic cost.
How would you quantify that waste vs the threat mitigated?
---
The general answer to why 2FA at all is that password hygiene is generally pretty terrible. Pretty much every "normal" (non developer / security professional) when you talk about passwords will say some form of "I use a different password for my bank, from the services I don't care about" [unspoken... which all share the same password]. My guess is that most people don't even do that. 2FA prevents the problem of I know Joe's password for ServiceA, so I can also get into Joe's account on Service{B..ZZZ}
---
The landscape of 2FA auth for each service that you rely on pretty much looks like:
* Use your own password storage
* without 2FA
* with 2FA (TOTP/SMS/email)
* Use Google/Facebook/Twitter/...
* accept whatever the user has setup for 2FA
* Use a third party service (e.g. Auth0)
* U2F / WebAuthN - newer stuff happening. I don't know a lot about these to talk much about them
---
Being security aware and practicing security hygiene is hard, but personally I'd prefer not to be the low hanging fruit when it comes to security breaches.