Hacker News new | ask | show | jobs
by lovelearning 1319 days ago
> How do you recover your account if you lose the 2FA device?

All TOTP apps provide backup codes and export options. Store them in my password manager. If my phone gets stolen, I just import them into the new device.

> If the service offers email or SMS recovery then it’s not any better than SMS 2FA.

I've explained this in another reply. Briefly, in some countries, losing SMS-based 2FA is much more of a hassle than losing device-based 2FA because of government and private bureaucratic hurdles.

> all you should need to do is use a randomised password generator and password manager

No complaints there. Unfortunately, my bank forces me to use 2FA and, worse, forces me to use SMS 2FA.