The simplest solution is to change my phone number. But
a) why should I have to? it’s my number, dammit!
b) how many accounts have 2FA? if I changed my number, what if I miss updating one that’s important?
c) it could happen again
If I change my number, however, that is the simplest way to solve the problem. It’s just, do I want to?
TOTP is portable and can be backed up.
I went a little bit off on a tangent, the stupidity of SMS 2FA is a pet peeve of mine.
I walk to the local phone shop and get a replacement sim for my number with a few of bits of ID and I regain sms access. Totp access is gone forever.
It’s clearly not worse that totp in every way.
> I walk to the local phone shop and get a replacement sim for my number with a few of bits of ID and I regain sms access.
Or someone else gets access to your SIM by sim swapping you, which is not as stupidly easy as it used to be, but still SMS remains insecure. Building an authentication system on it is just a bad idea from virtually every angle.
You vans I may be able to manage a backup and understand how these codes are generated. The average person does not.
From memory most totp apps don’t even migrate when you move from one phone to another - at least on iPhone. I haven’t done that for 5 years but I seem to remember having to create new entries.
https://www.cbsnews.com/news/ted-kennedys-airport-adventure/