Hacker News new | ask | show | jobs
by alt227 508 days ago
All of these things can be mitigated by a little care and attention by yourself.

What you are really saying is you want a way to be able to recover your account thats easy, quick, and you dont need to think about it. Unfortunately strong security will never be any of those things.

2 comments

Any concept of "strong security" that doesn't consider losing access to be a security issue is, at best, amateur.

If a state actor can't access your email, but you also can't access your email (and receive notices of login attempts, password reset attempts, server intrusions, etc.), then you absolutely do not have a good security posture.

It doesn't matter how you want to describe it, keeping recovery keys available is an ongoing maintenance burden that most people aren't going to do perfectly. It's not appropriate to blame users for reasonably foreseeable problems with a fragile system and lock them out of their bank passwords.