Comment by XCSme

14 hours ago

- handle accounts that have lost their second factor in an way appropriate for your business

One-time displayed recovery codes are a standard practice, and most good LLMs will add it by default without even asking for it.

And yeah, I am talking about TOTP apps, I think sms/email is not as secure.