Hacker News new | ask | show | jobs
by nine_k 2142 days ago
2FA with some rescue codes printed and kept in your wallet / safe box seems like a reasonably bulletproof setup (hi GitHub!), but not every important site offers this.
2 comments

Yes, that's decent. I also like services that allow you register multiple 2FA devices for an account. e.g. my back up phone not only serves as my back up phone, but also my back up 2FA device. I believe rackspace allows this.
Printing them and carrying them in a wallet that could be lost or stolen seems like asking for trouble.
Unless you're a victim of a targeted attack, and the perpetrators know your accounts and go to immediately hijack them, it's a non-issue. You just generate and print new rescue codes, and the old codes become invalid.
I keep all my secure codes in my password manager.