Isn't disabled SMS overkill for most casual thread models? As I understand it SMS would require someone to MITM the telecom network OR snoop the local antenna when you receive it on your phone. Which is a danger if you expect, like, nation-state adversaries.
But if I'm, say, protecting my GitHub account against Russian mafia hackers, that still seems perfectly fine?
The bigger problem for SMS-based 2FA are social engineering attacks on the support personnel of mobile network operators. They typically don't have fancy authentication schemes - it's fairly easy to get them to redirect messages to a different SIM or something like that.
I can't speak to current day, but in the past it's been very easy to social engineer telecoms. So especially for high value accounts this shouldn't be used.
But if I'm, say, protecting my GitHub account against Russian mafia hackers, that still seems perfectly fine?