2FA over SMS is stupidly bad. It's worse than TOTP in every aspect including this reason. It is also much less secure. You could start switching accounts to TOTP regardless of this and then decide if you want to switch your number later when you have the option.
TOTP is portable and can be backed up.
I went a little bit off on a tangent, the stupidity of SMS 2FA is a pet peeve of mine.
Only if you don't backup your TOTP tokens. Just like you lose your photos when you lose your phone. One of the main advantages of TOTP is that it is portable and can be backed up.
> I walk to the local phone shop and get a replacement sim for my number with a few of bits of ID and I regain sms access.
Or someone else gets access to your SIM by sim swapping you, which is not as stupidly easy as it used to be, but still SMS remains insecure. Building an authentication system on it is just a bad idea from virtually every angle.
I suggest exporting your password manager && your topt keychain onto an encrypted flash drive. I went through the horrors of having a phone die on me after migrating my topt to a local solution. Having a valid login cookie on bitwarden on my laptop was the only thing that saved me.
You vans I may be able to manage a backup and understand how these codes are generated. The average person does not.
From memory most totp apps don’t even migrate when you move from one phone to another - at least on iPhone. I haven’t done that for 5 years but I seem to remember having to create new entries.
I've moved between three managers in the past two years and all of them supported importing and exporting your full lists. That could be a recent development, though. I admit, I haven't used an apple product in a long time, so you could be right. I don't trust SMS, because I don't trust cleartext over the air. Too many people have too much time on their hands and information is too readily available.
We managed to get given a drug dealer's former landline, and had to get it changed after strange calls in the middle of the night. Then our neighbours got the same number after about a year and had the same issue.
The simplest solution is to change my phone number. But
a) why should I have to? it’s my number, dammit!
b) how many accounts have 2FA? if I changed my number, what if I miss updating one that’s important?
c) it could happen again
If I change my number, however, that is the simplest way to solve the problem. It’s just, do I want to?