What’s the point of 2FA, if there’s a recovery code you can use when you lose ability to use your 2FA device?

647 views

In the end, isn’t that recovery code just the same as a password?

In: 174

17 Answers

Anonymous 0 Comments

The point of Two Factor is that it *utterly* precludes replay attacks and regular password theft. Yes, you do have a recovery code which permits you to re-set your 2FA device/app, but that code is never transmitted over the wire, so it’s far, far more difficult to capture and decrypt.

You are viewing 1 out of 17 answers, click here to view all answers.