“Two-step verification at login — user name/pw, then a code from the text msg the system sends to the user’s mobile phone. NOT email,...”
My mobile phone, unsurprisingly, accepts TXTs, but I have seen a couple of FR posters who claim they don’t have such.
No matter, I generally dislike 2FA. In most cases I view it as a extra burden on users, more oriented to securing the website (like this proposal) than benefiting the visitor.
Good. When the website’s gone because no improvements were made, one or two people will be happy.