Conversation

Replying to
That's an odd way of making recovery codes since they should be one-time use and shouldn't be as weak as TOTP codes. Should just be random. At this point, it's hard to see anything other than FIDO2 security key support as not being terrible. TOTP isn't great even when done well.
1
7
Replying to and
A recovery code is presumably not time sensitive and TOTP codes are super weak even with the time constraint. They better have incredibly aggressive brute force mitigations for those. It's really best if sites support more convenient + much more secure security key approach.
1