@SwiftOnSecurity And yet, some attacks remain implausible.

TOTP is still safe, as are backup recovery codes.

SMS or phone-based authentication was always built on shifting sands and never should've been trusted.