Hacker News new | ask | show | jobs
by shushpanchik 985 days ago
Emailing backup codes doesn't sound like a good idea. You give the keys to the kingdom to email provider or anyone who would be able to access your mailbox.
1 comments

If the email is busted open, then it would already have been possible to do a a forgot password recovery (which i presume uses emails).

Therefore, backup codes are no less secure than that.