[1]: https://www.nytimes.com/2019/09/05/technology/sim-swap-jack-...
[1]: https://www.nytimes.com/2019/09/05/technology/sim-swap-jack-...
Twitter was requiring phone numbers for a while for account verification and I had mine attached from pre-history, but have obviously removed it after people have been pointing this out as an attack vector.
Scary stuff, had to give sooo much personal information over the course of months to recover a single account.
Not sure a solution, maybe have a wifi only phone that I only turn on for Auth?
You did write them down like the site told you to, right?
Even if a site doesn't offer backup codes, you can extract the TOTP secret from the QR code, or most authenticator apps, quite easily, and then write it down.
It's more secure to only save the backup codes though since they have a limited number of uses, while the TOTP secret has unlimited uses.
Luckily it is some lame work account that someone else can unlock to get me back in. I couldn't believe that the backup codes provided are now obsolete!
I have a near-20-year Google account I can't access because I lost the 2FA number. I have the username, password and recovery email. But that isn't enough, apparently.
For extra assurance get a hardware key that supports NFC so it can be used with your phone (and some laptops) even if it can’t be plugged in for some reason.
Multi-pronged 2FA also enables things like being able to remove a key from your account without issue if for example one turns up missing while traveling.
You can even save the QR code and enroll a new device later if you want.
You could even save it in an application like KeepassXC. Then you turn on the TOTP mode and presto, you have another TOTP device
That way you can easily re add the 2fa token to a replacement device.
Hell, if I just lose my wallet and would be forced to reissue the IDs and SIM (retaining the number!) it would take weeks to be back 'online'.