What's the purpose of 2fa recovery codes?

Oh, they’re very handy. I, and I’ve talked to several other folks who, for whatever reason, lost access to their 2FA codes/seeds.

Not going to go into incidents at work, but I’ll say what happened to me. Back… several years ago (I want to say about 10), my phones battery caught on fire. All my data, was lost. At that time, I was using a proprietary app, and it did require an account. I assumed that the app would automatically back up (that was its selling point), it did not. That feature had to be enabled, which I didn’t know (so, I essentially created the account for nothing). Several accounts were completely unrecoverable (including an old important email), but I could save a few, thanks to those codes.

Should also mention that some folks do not save their 2FA seeds to an app, but save them to a hardware key (eg: a Yubikey). These devices are prone to loss, theft, and so on. Recovery codes, again, come in handy.

5 Likes