I also use that SMS service for PayPal.
Does nobody else?
I also use that SMS service for PayPal.
Does nobody else?
For a while, I was trying to encourage adoption by expounding on its benefits, but then one of our users (without two-factor auth) had her account hacked, and I was able to employ the panic around the office to justify making it mandatory for everyone. This caused some pain for a little while (when two-factor auth enforcement is enabled for a Google Apps domain, users without two-factor auth enabled must use a temporary code, which can only be retrieved by a domain admin), and I wouldn't recommend this approach for more than a dozen users or so.
With Google, the list of massive passwords they provide for logging in via POP3 is a useful thing to print off and have secreted at your house somewhere in case your phone gets pinched.
And periodically/regularly tidying up old emails from your inbox (archiving them offline somewhere) is a way to keep the email account a bit safer, as there isn't any info in the mailbox.
I think there should be a 3rd option of just having a second password. Better yet, add a few other options as well.
Two passwords you know is not 2 factor auth