Hacker News new | ask | show | jobs
by Koenvh 2167 days ago
In theory, yes, and I think most people here would store their backup codes properly. However, there are many people who don't store them properly, and don't think about it until it's too late. They lose their token, break their phone, or lose access in one of the many other ways.

Sure, you can say "tough luck", but then people will complain, reasonable or not, and Google probably doesn't want that to happen. I think this is a reasonable compromise when it comes to security and usability.

2 comments

i know my life was flashing before my eyes when i logged out of my old phone and then my new phone asked for 2FA coz like a dumbo i stored the 8 codes in google drive...
If I have 15 sites in google authenticator is it such a win that 1/15th of them will allow me to reset without needing the second factor? Backing up the app or backup codes seems needed to scale to widespread 2FA use.