FYI: 2FA of PayPal is actually just 1FA.
You can reset your password using your 2FA phone number.
In conclusion your money is vulnerable to SMS interception attacks. It has been like that for years.
So, why is 2FA or account recovery via SMS a really bad idea, you ask?
[Thread]
@vidister I noticed the password length problem too...
Thankfully PayPal allows TOTP too for real 2FA
@jakob Yeah, TOTP which is useless since you can bypass it using..... SMS.
@vidister you can actually use TOTP for PayPal - it is totally hidden and as you already mentioned it might even be possible to reset it over SMS (which would obviously invalidate everything). But I haven't checked that yet - see https://chaos.social/@sqozz/101534016476296684 for details
@vidister Actually 0FA, since you don't need a password, and you don't own your phone number.
Most obvious attack vector: Someone could steal your phone. That's why you should enable the pin lock of your sim card. Also adjust your phones privacy settings to hide text message content on your lock screen.