As people use mobiles more and more for not just phone calls (wait, they do that, too?) but as their primary access to the Internet, more and more companies and sites are using your mobile number as not just your ID, but as your authenticator, too.
But increasingly that’s problematic. Combining ID and authentication (this is who I say I am; this is how I prove it) into a single value or point is always theoretically a security risk, and trusting in physical possession of a phone or that phone numbers themselves cannot be stolen is becoming less and less of a certainty.
I don’t have any advice here — not even anything I plan on doing myself aside from trying to be vigilant. But expect security issues around this to get worse before they get better.
Phone Numbers Were Never Meant as ID. Now We’re All At Risk | WIRED
Your phone number was never meant to be your identity. Now that it effectively is, we’re all at risk.
2fa + GV# (instead of actual mob #) is my wrkarnd for now.
No SIM that way.