Hacker News new | ask | show | jobs
by gruez 2950 days ago
>2) Google still actively encourages users to add a recovery phone number

i would consider the average person to be pretty bad at handling otp backups. how else would you do recovery?

1 comments

You are correct this is a significant usability issue. Personally I use Authy, which performs automatic encrypted backups in case I lose my phone. I then have to remember my Authy recovery password (not stored in my password manager, which is itself secured with a TOTP - hello circular dependency danger!) I also keep a yubikey authorized with all my accounts as second backup.

All these things are beyond what the average person wants to worry about, as you say, but HN readers will find it simple. Personally I'm hoping U2F (Yubikeys) are the future, since your average person certainly understands the concept of a key.