Hacker News new | ask | show | jobs
by LaGrange 2373 days ago
The 2fa has to provide something more than a password to be worthwhile. If it's easily defeated by growing through my copy of Capital then it's not worthwhile. Finally, I don't have a single set of recovery codes, I have at least a dozen by now. By using recovery codes you've turned a somewhat harsh but sometimes-useful security scheme (for situations where loss of access is preferable to 3rd party access) into security theatre. Not that it matters, most services will "restore access" if you answer questions not just your flatmates but even an average doxxer will be able to find out.

Also no, you're not genuinely curious, you're trying to waste someone else's time.

1 comments

But nobody is forcing you to print or use your security codes. If you ignore then and your hardware key is broken/lost you are forever locked out. Which you mention is preferable, sometimes.

So, you are against things. What are you for?