Hacker News new | ask | show | jobs
by chii 983 days ago
If the email is busted open, then it would already have been possible to do a a forgot password recovery (which i presume uses emails).

Therefore, backup codes are no less secure than that.