Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

We can’t trust users to not re use a password, why do we expect they will go through the effort of storing / understanding recovery codes?


It’s easier to print things and you have clear instructions telling you why it’s important.

The key here is thinking about relative risk: many people get compromised by reusing passwords or being phished every day compared to the number of people who simultaneously lose all of their devices and recovery codes.


It's not easier to print things. Only about 60% of the population has a printer and that number is going down, not up.


One confound is that many people don’t own a personal printer because they have access to one at their library, job, friend’s home, etc. and that’s fine for something you do once and likely never use over your lifetime.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: