Hacker News new | ask | show | jobs
by Tainnor 1278 days ago
What's the more likely scenario:

1. System reports "print out these recovery codes and deposit them in multiple places so you will never lose access to your account". User John Doe posts his security codes on his Facebook page and gets hacked.

2. System reports "print out these security codes and store them in a safe place". User prints them out and stores them in a drawer, but his house burns down and the user loses access forever.

Both scenarios are shitty, but I think 1 is more likely.

Of course, you could write a detailed guideline on where to store your codes, and that you should share them with some trusted people but not everyone etc. But who's gonna read that?

People who understand security already take threat models into account, but those who don't need very simple guidelines.