| ▲ | BetterThanSober 2 days ago | |
Device bound is a bad idea especially if in the future sites is designed to be fail secure, you might be able to recover your account but not your data. The provider will then have to take a negative PR risk for something they cannot do People lose their device all the time, there's tons of horror story where people got locked out because they lost their sole method of 2FA and if there is a method to bypass that then it is inherently insecure For the layman yeah it is probably enough | ||