|
|
|
|
|
by whatevaa
740 days ago
|
|
Losing access to a service because of device loss is part of threat model for most people (including me). Security isn't binary. Failure to provide adequate recovery should be treated as insecurity. Always do threat modeling when talking about security, otherwise you end up just bike shedding. No joke, I once recovered access to google account by loading a TOTP backup in an app in Android emulator. Otherwise I might have been a bit in trouble. |
|
If I didn’t have my GitHub recovery codes, I would have been in trouble.
Arguably, that’s what those are for. But the key point is that I did a mundane, routine transaction. My house didn’t catch fire, my phone wasn’t stolen, I didn’t act negligently. But I was potentially this ][ close to disaster.