Stop advertising recovery options as 'Security'
Just got another mail to add recovery options to my account in order to increase 'security' or 'safety'. I don't know in which dimension adding another attack vector to the account increases account security in any way. Yes, regular users forget passwords but that doesn't mean you have to advocate for watering down account security on a mass scale, because:
- users who usually forget their passwords also squander around with recovery keys
- users who use other means of recovery (additional e-mail accounts and so on), also usually have bad account security for those recovery methods.
Please rephrase this properly and also note that recovery options are always an added security risk.
1
vote