What’s the point of 2FA, if there’s a recovery code you can use when you lose ability to use your 2FA device?

661 views

In the end, isn’t that recovery code just the same as a password?

In: 174

17 Answers

Anonymous 0 Comments

The point of it is that unlike your password, it is auto-generated, long, much more random, and you don’t use it day to day (ideally it’s not even stored on any of your devices, but on paper, printed). This means it won’t be easily stolen by e.g. a keylogger or a phishing attempt.

It’s also a different “factor”. It’s in the “something you have” category, rather than the “something you know”.

You are viewing 1 out of 17 answers, click here to view all answers.