← Back to context

Comment by SoftTalker

1 hour ago

Completely unrealistic. Stuff happens. Email accounts get closed for no reason. People lose their phones, or have them stolen. Lots of reasons why someone might need an exceptional account recovery process.

Not saying it should be easy or routine, it should not be. But it must be possible.

That's what recovery codes are for. Unfortunately it seems a lot of 2FA is now implemented without recovery codes.