Feels like SMS 2FA logins have become the new norm for some reason.
By contrast I feel like SMS 2FA increasingly is not an option, or at least not the default.
Almost no sites I interact with outside of big tech offer TOTP or FIDO2, which is a real shame.
With email, if an attacker gains access to my email account she can remotely de-auth my mobile device's email client, reset my password for service X, and sign in to service X without my knowledge (assuming I don't notice my email client has stopped working).
With SMS, if they gain access to my email account, I at least get the notice of the attempted login via SMS and can take appropriate action.
I prefer it anyway since I have multiple accounts and they’re not all gmail.
Why don't more apps do that?