Two-factor everywhere but my email was the door left open
My email got hit last month because I had 2FA on everything except that one account, and the recovery codes were sitting in my inbox... now I'm paranoid about which backup method actually counts as secure. Anybody else treat their email like the master key and lock it down first?
Backups sitting in your inbox are only a risk if someone already owns that inbox, and if they do, theyre getting past your 2FA on other accounts anyway. The real problem isnt the recovery codes, its that you trusted email as a reset path at all, so maybe lock down the mail account first and stop worrying about the rest.
Feeling you on this, honestly. I had a total meltdown last year when I got a new phone and realized my backup codes were just sitting in my email, which was also the recovery for my bank and everything else. It's like, sure, the email is the weak link, but that doesn't make the codes in there any less scary to think about. Locking down the mail account feels like the one thing you can actually control without losing your mind, so I get why you'd say start there. The rest of it is just a big pile of "hope it never happens" anyway.