SMS is not a second factor
A phone number can be hijacked at the carrier, and that hijack leaves no trace on the victim's side.
Sécurité1 min read
One-time codes over SMS remain the most widely deployed second factor. They are also among the weakest, for a reason that has nothing to do with cryptography: the channel does not belong to the user.
A number can be ported at the carrier, on the strength of information a motivated attacker can assemble. From the network’s point of view the operation is legitimate, and the victim sees nothing until their phone loses signal.
What holds
A passkey or hardware key is bound to the domain that created it. A phishing site cannot use it, even with the user’s consent: the key refuses to sign for an origin that is not its own. That is not a matter of vigilance, it is a property of the protocol.
Where it comes back
Account recovery. That is where most rollouts quietly reintroduce SMS through a back door, undoing what they had just gained.