Anecdotal, but still
Anecdotal, but still
2 - You need to add a phone number and receive a SMS challenge, before setting up any other 2FA method
3 - With the Authy app installed on your phone, the token is instead instantly added to your account upon reception of the SMS. This cannot be disabled. Use a very particular combination of steps in the account settings to convince it to let you use a simple offline TOTP app instead.
4 - Use your recovery code every month and repeat the whole thing because somehow all other 2FA methods break simultaneously for all Twilio accounts set up with that phone number.
The experience was so awful I had to delete the App and the account.
Their process is ridiculous and is matched only by the insane password requirements that they recently implemented (I think they required a 18 character password ? Or 24 ?)
However, I am entwined in their ecosystem for all of my texting and calling and message management, etc., so I am forced to deal with it.
In fact, their clownish requirements were the impetus behind the 2FA Mule[1] experiment which I now use across almost all services.
While other techniques and applications might be (somewhat) more secure, the loss of ability to use the same application you already have/use for 2FA is a pretty big annoyance for a lot of people.
I have my 2FA in bitwarden myself... with a pretty long passphrase that I don't use for anything else. It's the master key to the kingdom. There are many sites that I keep with the sms/email codes simply because they either don't offer typical OTP as an option.