What’s the point of 2FA, if there’s a recovery code you can use when you lose ability to use your 2FA device?

641 views

In the end, isn’t that recovery code just the same as a password?

In: 174

17 Answers

Anonymous 0 Comments

The idea is that the second factor, such as requesting a confirmation code via your email, isn’t actually known to the attacker, so they have no way to get a recovery code.

If they have you logging in with your email address, then also use that email address for 2FA confirmation, that’s just badly designed.

You are viewing 1 out of 17 answers, click here to view all answers.