Just realized MFA alone won't stop SIM swap attacks, why do we push it so hard?
I read a report from the FTC last month that said SIM swap complaints jumped over 400% since 2018, and the bad guys don't even need your password if they can just convince your carrier to move your number. The scary part is that most of the advice I see online, even in this community, focuses on turning on MFA like it's the golden ticket, but a text message code goes straight to the attacker once they hijack your SIM. On one side, MFA still stops tons of basic credential stuffing, so it's not useless, but on the other side, we're telling people to do the one thing that actually fails in the highest-impact attacks against phone numbers. I found out AT&T and T-Mobile both have account PIN options, but hardly anyone sets them up, and even then employees have bypassed them. So is the push for SMS MFA doing more harm than good, or should we just accept it as a baseline and push harder on carrier-level locks?