Hacker News new | past | comments | ask | show | jobs | submit login

What if they've had their mobile phone stolen and can't do 2-factor auth and that's why they're calling?



Security traded for convenience, back to square one.


Isn't this scenario why Gmail's 2-factor authorization gives you a set of one-time passwords?


What if you lose them?

At some point, there has to be a way to get back into your account. Probably, going through slow and hard to hack methods like the postal system.


Well, continuing to use Gmail as an example, there is an account recovery system, which IIRC asks for a bunch of details to try and determine if you are the account owner (account creation date, names of labels used, etc.) If Google or a third party would provide a list of these details, then you could collate that info as additional insurance against your posited scenario.


There's inevitably going to be someone who loses them or never prints them out in the first place.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: