For everyone else, it would be a cascading series of installation and password and app switching and immediacy problems. This would create a great deal of frustration, and ultimately a call to family tech support (me) or the service provider if human tech support is an option which is not the case for many companies such as Google and social media firms.
The other issue is that many smartphone owners don't have a computer they would back things up to. Just "cloud".
So, yeah, there's no way I could get her to use an Authenticator app. (Also, there's, "...all these apps scare me.", which isn't a bad thing considering the first (and last) app she installed on her Android phone was a malicious 'flashlight' app that kept displaying some sort of crypto ads.)
- How's grandma doing? Is she gonna be okay?
- Well, let me ask you, does she complain much?
- All the time!
- Then grandma's doing fine. It's when she stops complaining - then, it's time to be concerned.
As a data point, USAA (which is not the biggest bank, of course, but it is not tiny either) has supported TOTP for years. There are probably others, but at least some banks support relatively modern security.
The head security guy at USAA and I had a talk where he explained in some detail how it all went down. He was refreshingly honest, and they didn't balk at getting our funds restored, but still -- humans are often the weakest link when they can defeat all of your security precautions. Probably the bank shouldn't give phone reps that much authority, and always require a dedicated security team response for such unusual situations.
I'm worried about losing my phone and being locked out.
With SMS, I can show my ID to the Verizon rep, get a new phone, and I'm good to go.
The biggest downside is if the site isn't set up correctly it is a long trek into Settings to get the code and it makes the site seem less trustworthy.
Which means that anyone else who can fake an ID is good to go with that verizon rep. Or the rep themselves.
I will always avoid connecting any account to SMS if at all possible, it's the worst of all options.
TOTP is the best, as it is an open standard and doesn't tie you to any device nor any vendor.
> I prefer SMS for 2FA because some authenticator apps get tied to a device.
No need! Just save the TOTP seed in a safe place such as a computer under your control (i.e. not a phone) or even a piece of paper in a safe.
[1] https://en.wikipedia.org/wiki/Signalling_System_No._7
[2] https://web.archive.org/web/20201219144441/https://www.thebu...