meantime, another proof SMS as two-factor authentication are insecure - in addition to the fact they could be intercepted by a LOT of parties, Mitto AG, Twitter's 2FA provider, sold user location to surveillance companies when they used SMS to login to Twitter (as you need to know the closest cell tower to deliver the text/place a call)
https://wz.ax/sms-spying-2fa
Post #716
441