4 ms·
Every article about 2FA lists the primary email account as the most important account to secure with 2FA, precisely because it can be used to reset all other pa
by evouga 4y ago
Every article about 2FA lists the primary email account as the most important account to secure with 2FA, precisely because it can be used to reset all other passwords. And yet interestingly when I Google "why use 2FA?" the entire first page of results lists only spurious reasons (protection against phishing, brute-force cracking, social engineering, password reuse) and not the actual reason 2FA is potentially useful for securing a single-use, strong password (protection from keylogging and MITM attacks).
The thought experiment in the linked article makes it clear that using "something you own" as the second factor for your primary email account is not a good idea. I'm not sure what the best solution is, but I agree that the risk of having your single, strong email password intercepted is lower than that of losing your stuff.
- atleta 4y agoLooking at one everyone say, using backup codes and asking friends to store them (preferably on a USB drive in an encrypted password store) can be a good solution. I don't think most people need to worry about criminals (or the state) tracking down their connections and extort the backup keys from them. I would never enter my email password into anyone else's computer, though. And this is also true for all of the other important passwords too.
- Avamander 4y agoOr just print those keys out. You have other documents you are securing physically, why not those as well. Saves so much trouble and you're not keeping everything digitally in one basket.