SMS verification really sucks. It's hugely helpful because it is an 'open social graph' to use a Zuckerbergism. However, it's not at all designed to do this. It's like the problem with SSL verifying ownership via email - ok at first sight, but then say you run a webmail service and you can register webmaster@, game over without any crypto bother. Or just trojan the webmaster@ mailbox and get control over the guy that runs it and issue a valid cert. Insta-MITM.
Mobile numbers are easy to spoof and easy to port away from people. In most countries telco regulators look at how easy it is to port cell numbers as a badge of honour on how efficient their mobile regulation is. Just like everything, attackers will rush to the easiest point of failure. In this it's SMS and using phone numbers as a trusted identifier.
In the UK you need to get a "PAC code" to change provider, but it's not hard to social engineer that if you went through someones trash and grabbed an old cell bill. The number will be ported in a day or less and even worse, there's no way for you to port it back quickly since you'll have no idea who it's got to. And with it your WhatsApp, etc will all be gone security wise.
All this talk of "oh just enable these super warnings and scan QR codes" is nonsense. People port phone numbers and move phones all the time, these warnings can't be this strong otherwise half your phonebook would false positive.
Mobile numbers are easy to spoof and easy to port away from people. In most countries telco regulators look at how easy it is to port cell numbers as a badge of honour on how efficient their mobile regulation is. Just like everything, attackers will rush to the easiest point of failure. In this it's SMS and using phone numbers as a trusted identifier.
In the UK you need to get a "PAC code" to change provider, but it's not hard to social engineer that if you went through someones trash and grabbed an old cell bill. The number will be ported in a day or less and even worse, there's no way for you to port it back quickly since you'll have no idea who it's got to. And with it your WhatsApp, etc will all be gone security wise.
All this talk of "oh just enable these super warnings and scan QR codes" is nonsense. People port phone numbers and move phones all the time, these warnings can't be this strong otherwise half your phonebook would false positive.