6 ms·
> Never lose your 2FA backup codes or you're locked out of your account forever if you lose your 2FA device In the case of digital infrastructure, I'm actually
by jackson1442 4y ago
> Never lose your 2FA backup codes or you're locked out of your account forever if you lose your 2FA device
In the case of digital infrastructure, I'm actually kinda ok with this. Would be better if it was a policy or if you could prove ownership of the payment account, but at the very least it's much harder to social engineer someone out of an account.
Of course, the lack of support isn't good.
- Nadya 4y agoI'm OK with it when it is official policy or you were warned beforehand that "No really. If you lose this and you're fucked - we will not provide support for account recovery." Precisely for the same security reason of preventing social engineering attacks for otherwise well-secured assets. But, and it is common with most places, you can jump through some hoops and get it removed my support. I still blame myself for losing my backup codes - but being told Support can help and then being ignored is well... annoying to say the least. I use cock.li [0] for my emails. This is the official password recovery process: > I forgot my password! > Passwords are not reset for any reason. Good luck. Many years ago - I forgot my password to my email! It was the kick in the ass I needed to begin using a password manager - and since the email was mostly for memes and not really used it was mostly a positive experience with a positive outcome. I occasionally try to login to the email but so far no luck in remembering my password. :) [0] https://cock.li/help https://cock.li/help
- hotpotamus 4y agoIt seems like a good case for putting an exorbitant charge on it with huge warnings about that upfront. Charge a $1000 recovery fee or something like that and make people check a box agreeing to it. I would imagine thoroughly vetting the request is pretty onerous on DO support (and it should be), but they should make the customer pay for it since it is ultimately the customer's responsibility. This is my greatest fear with my 2FA stuff and why I try to make sure and always have an available backup.