When is too much MFA a security risk, SMS, Email, Authenticators, Pass Keys, FIDO2/hardware keys, blows my mind!!!

Hi all, long post but looking for honest experiences and opinions.

Quick background: I started with SMS 2FA (yes, I know it is weak), moved to free authenticator apps (Microsoft and Google) for my primary email and finance apps, and recently added a YubiKey (PIN + touch).

After many sketchy 2FA requests and rouge main email login attempts, I opted to delete my primary emails and split my accounts into multiple email aliases, hoping this would tighten things up going forwards.

My question: Am I making things weaker by keeping too many backup routes?
I am thinking of simplifying to one strong hardware key and one backup key (roughly $80 main + $30 backup) with offline recovery keys per account.

Should I remove lower-security recovery options like SMS, email recovery, 2FA and pass keys alltogehter or is that too brittle if I lose access?

What I care about: Phone theft, phishing resistance, recovery if I lose a device, and avoiding the attack surface from multiple recovery paths. I plan to register at least two FIDO2 keys for critical accounts and keep recovery codes offline, but I am unsure whether to keep pass keys and an authenticator app as a fallback??????

Do you all have offline copies of your Google, Microsoft, and Apple account recovery keys, not to mention all the other key accounts that have offline backup account recovery keys?

Have you ever used them, and have they saved your account?

I would love to hear your experiences: Has a hardware key ever stopped a phishing attempt for you, or has MFA been bypassed despite having keys or authenticators?

If you lost / damaged a hardware key, how painful was recovery and what did you change afterward?

What hardware keys do you use, have you used biometric hardware keys, what would you recommend?

Do you think a primary hardware key plus one backup is enough, or do you keep additional fallbacks, and why?

Real, specific stories are most useful. Thanks in advance!

reddit.com
u/doyzer9 — 1 day ago

PSA: If You’re Using Lebara UK with uSwitch/Comparison‑Site Deals, Read This Before You Get Burned

I have had help to format and constructing this post, however the data is factual and I wanted to share a detailed breakdown of my recent experience with Lebara UK, specifically around uSwitch promotional deals, “new customer” eligibility, and customer‑service failures. This isn’t a rant, it ia actually VERY SHORT forensic summary that might save others a lot of time.

Please share your experience.

1. The Promo Trap: “New Customer Only” (But Not Disclosed Clearly)

I bought a Lebara promo via uSwitch.
The order was processed with a £2.50 postage.
The sim arrived, not linked to the uswitch deal and ZERO information.
Nowhere in the journey did it say:

  • “New customers only”, or
  • What counts as a “new customer”.

Three weeks later, Lebara told me the offer was for "NEW CUSTOMER ONLY" I can only assume they deamed me ineligible because I had previously bought SIMs (for my partner and daughters) using my name/email. As the order was for a new phone with a different number i did not see the problem, and the customer service preson was vague at best to the rules?

This rule is:

  • Not disclosed
  • Not defined
  • Not consistent with past behaviour

2. Customer Support Is… Rough

Across multiple interactions:

  • Agents didn’t read previous messages
  • I had to repeat the same info over and over
  • Every reply was “I’ll escalate this”
  • No one actually escalated anything
  • No proactive communication
  • Eventually they blamed uSwitch

It took three weeks to get a simple answer to why is my sim not assigned to the deal i order...

3. Misleading Advice About Porting

I asked if:

>

Agent said yes. (the call was recoreded around 4.30pm today so Lebara can verify this.)

But multiple reports show:

  • Porting back an old number removes promotional deals automatically.

So the advice was wrong.

4. How Widespread Is This?

Based on review data (2025–2026):

  • 15–25% of negative reviews mention promo/activation failures
  • 70–80% of all sentiment is negative for support
  • Resolver gives Lebara 1/5
  • BritainReviews shows 27% would buy again

Most complaints involve:

  • Promo failures
  • Porting issues
  • Roaming problems
  • SIM activation delays
  • Billing disputes
  • Support loops

5. Why Ratings Look High Anyway

Lebara’s high ratings mostly come from:

  • People who buy a cheap SIM
  • Activate it
  • Never contact support

If you’re doing anything more complex — multi‑SIM, porting, uSwitch deals, roaming — the experience is very different.

6. TL;DR

  • Promo rules are unclear and inconsistently enforced
  • Support is slow, repetitive, and often misinformed
  • Blame is pushed to uSwitch even when the issue is internal
  • Porting back old numbers can kill promos
  • Complex cases get stuck in escalation loops

If you’re considering a uSwitch/third‑party Lebara deal, take screenshots of everything, and be prepared for a fight if anything goes wrong.

reddit.com
u/doyzer9 — 11 days ago

Uswitch UK sim deals are not linked to the sim recieved from Lebara.

I / family have had several uswitch Lebara deals in the past, and many are still working fine. I have now tried three times to purchases deals via uswitch and each time the sim is not connected to the deal. First time i thought is was because i took a couple of weeks to activate the sim, second time the sim took ages to arrive and i signed up with another company. This time the sim arrived in 3 days and i could not link it to my account, Lebara cs rasied a ticket to fix this (still not fixed and nobody "got back to me", I also turns out that yet again the uswitch deail is not associated to the sim... FFS. CS said they will sort and someout will reach out to me.... I am still waiting. Is this a common issue with Lebara deals, it used to be so easy..... Has anyone else had the same issues and how long, and how much effort did it take to resolve. I even paid 2.49 for the sim to be posted, wtf....

reddit.com
u/doyzer9 — 25 days ago