Renewably5311 wrote:
OTP bots take account takeover to a whole new level. While most websites nowadays have implemented passkeys or hardware keys, some still rely on sending OTP using text messages. I mostly use hardware keys whenever possible, then authenticator apps. If and when multi-factor authentication uses SMS, I've found there is a choice between text messages or e-mail. I always choose the latter. I chose SMS/text message as a last resort when no other option is present.