When Security Teams Still Need SMS OTP - and How Virtual Numbers Fit
The security team gets the ticket around 11pm. Staging is blocked because a third-party OAuth flow only accepts SMS codes, the shared lab phone is in someone else's bag, and half the engineers have already locked personal numbers out of "work stuff." Someone pastes a free public inbox in Slack. The code arrives. The sprint moves. Nobody files that the recovery path for a production-adjacent credential now sits on a site that also hosts ten thousand throwaway signups.