Not All Second Factors Are Equal
Your second factor arrives by text. Who else can receive it?
The idea
A second factor sent over SMS can be intercepted or moved to another SIM, while an app code or hardware key cannot.
In the real world
An attacker persuades a carrier to transfer a number and receives the codes.
Going deeper
Having two-factor enabled describes a range of very different protections. An SMS code depends on the phone network's identity checks, which can be defeated by persuading a carrier to move a number to a new SIM.
App-generated codes and hardware keys remove that dependency, since the secret lives on the device rather than being delivered to a number. Hardware keys additionally resist phishing, because they verify the site's identity and will not release a credential to a lookalike domain. Moving important accounts off SMS is a small change that closes a well-documented attack.
Where it stops applying
SMS two-factor is still substantially better than none, and for low-value accounts it is a reasonable trade against the friction of setup.
Why it matters
It shows that having two-factor enabled is not one setting but a range of very different protections.
Try this today
Move one important account from SMS codes to an authenticator app.
Test yourself
An account is protected by SMS codes and is taken over without the phone ever leaving the owner's hand. How?
Show the answer
The number itself was moved to another SIM by convincing the carrier, so the codes were delivered to the attacker. The second factor depended on the phone network's identity checks rather than on the device, which is the weakness an app or key removes.
Learn this in the feed Answering from memory, then again days later, is what makes it stick.