Because it’s multidimensional. Security is one aspect, but the firm exists to generate profit for the shareholders, so the management has to balance these priorities.
The problem is that SMS 2FA is more user friendly.
App based 2FA requires user to download Google Authenticator, copy the key there, copy the resulting number out. It’s a lot of friction. And on top of that users can lose the 2FA key.
SMS is less secure, cloneable, but it reduces friction, which in turn results in more revenue. And without revenue, there will be nothing at all, secure or not.
The problem is that SMS 2FA is more user friendly.
App based 2FA requires user to download Google Authenticator, copy the key there, copy the resulting number out. It’s a lot of friction. And on top of that users can lose the 2FA key.
SMS is less secure, cloneable, but it reduces friction, which in turn results in more revenue. And without revenue, there will be nothing at all, secure or not.