|
|
|
|
|
by jesseendahl
610 days ago
|
|
Account recovery flows are generally entirely unaffected by the move from password to passkey. It’s just your login credential. If you lose either a password or a passkey, you do the same thing: reset and set a new one via email recovery. |
|
Resetting 2-factor authentication by proving access to only one factor (email) defeats the purpose of requiring 2 factors. If they can be reset via email, they might as well not exist at all. Even if we assume that nobody other than the user has legitimate access to the emails sent to the user (which is often untrue), emails can be trivially intercepted by a third party.
Not to mention that if I’ve lost access to the device where I am signed in to my email account, I won’t be able to access my email account to reset my passkeys anyway, because access to my email account would also require a passkey that I no longer have.