Conversation

Replying to
That's an odd way of making recovery codes since they should be one-time use and shouldn't be as weak as TOTP codes. Should just be random. At this point, it's hard to see anything other than FIDO2 security key support as not being terrible. TOTP isn't great even when done well.
1
7
Replying to and
I like the way it works on a Google account with Advanced Protection: only security keys with at least 2 dedicated keys and ability to use the TEE/HSM in phones as additional security keys. If you want more backups you add more keys. No recovery codes or easy support backdoor.
1
6