Hacker News new | ask | show | jobs
by balladeer 2724 days ago
As of now there’s not much you can do other than educating your users.

Maybe add a workflow that checks whether they have the backup code or not and if not prompt them to note it down again. Maybe on second login/usage after setting up 2FA. If they still don’t do it just revert to email reset.

There isn’t much you can do if the user isn’t security conscious and doesn’t intend to be.

Is it a particular demographic? I’d assume this is an issue faced by most of the apps with 2FA.