Hacker News new | ask | show | jobs
by doliveira 1557 days ago
I think the threat model for most of us is online takeovers, not physical ones. Even if you live in a dangerous country like myself, criminals don't care about your email, so I don't think there's much danger in just storing the 2FA backup codes in your wallet. They're only good for when they've already input your password, aren't they?

But I'd appreciate if someone from cybersecurity were to weigh in. What are the best practices for 2FA backup codes?