Another thing to keep in mind is that most phones will display the content of SMS messages on the lock screen, even if the phone is locked. That means that if your phone is stolen, hackers can easily take control of accounts such as PayPal that use SMS verification as the only way of establishing one's identity.
Agreed. It's usually buried in the device settings and also in Messenger and Hangouts. Signal gives you a few different options as well. But it should be more visible to all users, not just those of us that dig through settings.
True, but possession per se, even if unauthorized, is what a "something you have" factor is all about. Adding a knowledge or biometric factor on top (your phone's unlock mechanism) is a bonus.
Granted, the unauthorized porting issue makes it a faulty possession factor in the first place.
This exact scenario happened last week to a friend of mine, I wrote a little article about it: http://gregschlom.com/misc/2017/01/29/hacking-paypal-account...