3 ms·
What you say is right and that is how password managers work. However, human habit is that people generally keep their password in their heads. The point of giv
by thecodrr 5y ago
What you say is right and that is how password managers work. However, human habit is that people generally keep their password in their heads. The point of giving a secondary key is that:
1. Since it is longer, the user is forced to store it in a file or some other place
2. The message behind "recovery key" is different to the "password" so users react different to it. Giving it more value and attention.
3. Encryption keys are still rare in clients so it stands out and the user again gives it more attention.
With that said, it is entirely possible that the user won't save the key or lose it. In which case, nothing can be done.
It isn't an ideal solution to account recovery problem but so far I have found this to be the only solution if you are going the zero-knowledge route.