It’s insane that providers can do this.<p>I note, however, that this attack seems to only be possible on VOIP routable numbers, and it’s my experience that banks, etc, will not allow you to use VOIP routable numbers for 2FA.<p>That’s definitely not the case for a naive implementation of sms 2fa as would be done by likely any dev using Twilio, etc.<p>Also, don’t forget that NIST deprecated SMS 2FA over 5 years ago. Here’s their reasoning: <a href="https://www.nist.gov/blogs/cybersecurity-insights/questionsand-buzz-surrounding-draft-nist-special-publication-800-63-3" rel="nofollow">https://www.nist.gov/blogs/cybersecurity-insights/questionsa...</a>