[tantek]SMS << Why SMS 2FA is a lie: in practice they make SMS a *one* (not two) factor auth by itself via SMS account recovery (e.g. AppleID, Twitter, FB, etc.) and this violates point two here: https://twitter.com/cookedj/status/1143587203047731203