Like many thousands of others (see "Phone number changed - can't log in"), Paypal has blocked my account access by asking to send an SMS to a phone number I don't have access to, because I am overseas and am not receiving texts to that number.
So this question is squarely aimed at the use of 2FA, which is this - what is the point? If you don't trust it, why use it? Seriously, what is the point if you are then going to ask for an SMS? Why is that any more secure? If the phone has been stolen then sending a text will have zero effect, unless the phone has been deactivated. It would need some fairly sophisticated code interception which just isn't going to happen with the average Joe, because it just isn't worth it. So my point is that surely 2FA should be trusted and should be adequate without resorting to something that is clearly affecting thousands of customers? I use face ID on my device, and so does Paypal when I log into the mobile app.
Yes, I know I can call Paypal, but that's not really the point.
... View more