I have heard rumors that Cap’n Crunch-style blue boxing still works on a handful of systems here and there.
I’m a bigger fan of the schemes that use TOTP/HOTP like Google Authenticator and the like. That way, you don’t have to actually receive a text or email, you just go fire up your authenticator app and enter that code.
My issue with those is that I don’t tote around a cellphone everywhere I go. It would be annoying if I were trying to log into a system and find out that I’m expected to have access to the authenticator app on a device I don’t have with me at the time.
So you’re getting landline calls? I’m sure that’s definitely an edge case of an edge case.
I don’t even have a landline but my phone is not surgically attached to me either. If I’m at home in front of the PC (or laptop) I don’t necessarily have my phone right there next to me but if it’s sending me an email I have access to that on my PC w/o having to get up.
I find that annoying, because I often give out my landline. (In part so I don’t get junk texts, I admit.)
But
Many more people have only a cell phone than only a landline. In fact, many more people have only a cellphone than have any kind of landline. It’s the landline that has become an expensive luxury. I still have one, but I pay more for it than for my cell service. (I do have an expensive cellphone, but there are still very cheap cell phones available.)
Our landline service is bundled with cable TV and internet.
Yes, you can receive phone calls at your house over the Internet. No need (unless for some emergency thing) to pay them to come and install whatever 1970s-vintage hard lines they may still maintain.
Then you can keep a dongle on your keychain
or next to your PC, or run the authenticator app on your PC if you always need it on that PC.
Now many times per day do yo need to authenticate that this comes up? (Some people do need to do that, and they carry a Yubikey or something:)
so no need to type anything
Workplace, for the privilege of remoting in to the PC they issued me (Microsoft RDC): once a day M-F
Credit Union: any time I want to log in for any purpose. Fortunately, phone call to my VoIP phone.
Various Credit Cards: any time I connect to their page using a different browser OR device (method varies)
Morgan Stanley: if they send me something to eSign, they text me a code to my cell
Facebook: any time I connect to their page using different browser OR device OR clean cookies (code to cell)
Amazon: at random they flag my purchase activity, usually want to email me a code which is okay
Various other online vendors: any of the above + one requiring me to scan a freaking QR code
I can sometimes go all day with only the morning 2FA, but it varies and mostly isn’t under my control. PITA.
I’m mostly a fan of 2FA, but i didn’t use Facebook and Amazon has never asked me to do this, that i recently. My banks (and other investment stuff) and my credit cards and my medical apps ask me to reauthorize via 2FA from time to time, as does my very-part-time employer. But I’m happy the financial and medical stuff has 2FA, and i understand why the employer cares, and none of it is often enough to be horribly inconvenient.
I don’t think I’ve ever had someone I’m buying stuff from ask me to prove who i am.