Remix.run Logo
hombre_fatal 9 days ago

The forgot-my-password email link has a customer support load very different from "I can't do 2fa because I lost my device".

And once you set up a customer service pipeline for it, you might accidentally create a backdoor that's far worse than forgot-my-password email verification: https://medium.com/@espringe/amazon-s-customer-service-backd...

Email account access is the closest thing we have to ubiquitous identity on the web. Users that truly lose access to their email account are in a catastrophic situation before they even think of whether they can access your service.