3 ms·
SMS is preferred as the technology is fairly decoupled from internet services, for example it's more than likely that a number of people have exactly the same p
by iSloth 13y ago
SMS is preferred as the technology is fairly decoupled from internet services, for example it's more than likely that a number of people have exactly the same password for service XYZ, as they do for their eMail service. So it's not really providing that much more security than single factor, just another hoop for the hacker to jump through.
Even if your not stupid enough to use the same password for both services, you might still be susceptible to key loggers, malware etc... meaning again that SMS would be a better option.
It's fairly easy to forge an SMS originating number to make a text message look like it's from someone else, however 2-factor generally is sending (terminating) a text message to a known number, this is much more secure.
It's almost impossible to intercept a terminating SMS, this is down to how SMS are routed over mobile networks and the SIM card registration process. Basically you would need the private encryption keys of the mobile operator to clone the SIM card and create a fake registration for that number, or 'root/admin' access to the current network that subscriber is on.