two-factor authentication? not so sure

I recently had a phone die; I had a spare phone but needed a different size sim card for it.

I've read about people with two-factor authentication losing bitcoins via clever social engineering of their phone provider, so I was completely unprepared for what happened when I went to the AT&T store to get it.

I gave them the phone number, they gave me an activated sim card. No ID needed, no questions asked, not even my name.

