Mobile Carrier is one of the biggest weak points for many 2FA.<p>Unfortunately, most of the sites I use do not leverage U2F or TOTP, and I'm forced to use SMS for 2FA.<p>Is there any mobile carrier that is more security and privacy centric? Such that someone can’t just impersonate me and gain access to my SMS through the phone carriers?
I believe the insecurity of SMS comes from the design of mobile network protocols. Not from individual carrier’s implementation.<p>Can you change online services if you’re that paranoid? Can you compartmentalize in a fashion that if one site is compromised the rest will remain intact? The main services I would be concerned about are financial institutions and the e-mail accounts tied to them. Switching banks in the US is relatively easy. Also, good password practices would limit exposure to risk.
As others have said, the protocols are kind of crap, but it sounds like your concern is more about account takeover through customer service.<p>Maybe Project Fi? I don't know that they're better, but Google takes security pretty seriously, and you can probably lock down your Google account.<p>There's still a risk with phone number portability where someone tricks another carrier into porting your number somewhere else, and I kind of doubt that even Fi does anything here.