Backup Recovery Codes without any 2FA Method enabled #4202
markusheinemann
started this conversation in
Ideas
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
Hello,
I've been playing around with Ory Kratos for some time now. I noticed that it is possible to have backup recovery codes as the only second factor. Here is an example, how I went into this situation:
After I logged in again, I was asked straight for the backup recovery code as second factor. Unfortunately, I didn't write the backup codes down and locked myself out. Thankfully, this only happened on my local Kratos environment.
After giving it some thought, I'm not sure if it is a expected behavior to have only the Backup Codes as second factor. I would expect one of these two things:
In the docs I found this section:
Before I'm raising an Issue I want to discuss if the current behavior is expected or not. What do you think?
Beta Was this translation helpful? Give feedback.
All reactions