What’s the point of 2FA, if there’s a recovery code you can use when you lose ability to use your 2FA device?

669 views

In the end, isn’t that recovery code just the same as a password?

In: 174

17 Answers

Anonymous 0 Comments

“100% guaranteed secure” is an unsolvable problem. When perfect is impossible the only sane goal is to get as close as you can to perfect; so “50% secure” is considered better than “49% secure” (if you don’t take other things, like cost or convenience, into account).

**”2FA + 1FA recovery” is slightly more secure (than “1FA + 1FA recovery”) because you’re not using 1FA as often.**

“2FA + 2FA recovery” would be more secure, and “99FA + 55FA recovery” would be even more secure. However, if you do take things like cost and convenience into account, “more secure” does not imply “better”. This is trivial to prove by making it literally impossible for anyone to log in (which is extremely close to “100% secure” and also extremely useless).

You are viewing 1 out of 17 answers, click here to view all answers.