Hey there, does Ory have plan or maybe don’t want to provide Backup code for account recovery?
Not a fan of the one time code send by email, I would like to ditch email to avoid account take over with email compromission.
average-summer-11775
02/03/2024, 8:17 AM
Ok just seen that the Lookup secret does that for the second factors. So if i’m not allowing password, and disabling recovery. I can have a Passkey only login with lookup secret in case of loss, I will test that.
average-summer-11775
02/03/2024, 9:11 AM
Apparently it’s not possible to do account recovery with lookup secret.
average-summer-11775
02/03/2024, 9:12 AM
I can signin 1FA with Passkey, and 2FA with Lookup Secret but would not able to use it as recovery
average-summer-11775
02/03/2024, 9:40 AM
Ok I just get it, when password auth is disabled, the recovery codes are mandatory to reset Passkey.
That means it asks for it as a 2FA after entering the one time code received by email with the account recovery