Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Do you have an alternative proposal for letting users back into their accounts when they inevitably lose their passkey? Because if you don't, this isn't a serious answer.


Password, not passkey. Recovery codes should be setup on account creation, but recovery of the password manager itself is what is required, and that usually has its own recovery mechanism.

Social key recovery is an underutilized solution as well.


How do you do account recovery when you lose a password or MFA token?

Of course, any website's auth system is as weak (or strong) as their recovery process. Different sites will implement this differently.


Typically by email, which OP says "don't do".




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: