logoalt Hacker News

basilikumyesterday at 12:46 AM1 replyview on HN

TOTP is pretty standard. Give the user backup codes and just use normal recovery methods. For most things that might be email. For a bank it's probably identity verification.


Replies

freddie_mercuryyesterday at 3:14 AM

The vast majority of Vietnamese I know do not have an email account.

So that would be a dumb thing for a Vietnamese bank to use as a recovery method.