I agree with your assertion that the trustworthiness of cryptography based second factor is greater than recovery email, however since no such token has been defined, deduced location overriding recovery email is still a big wtf that should stop.
Public shame (awareness) is perhaps half of the reason, not trying super hard here otherwise I'd pick better time of submission etc :) The other half is amusement, and perhaps hoping some security SME would talk about nuances that I don't know I don't know.
Comments
I agree with your assertion that the trustworthiness of cryptography based second factor is greater than recovery email, however since no such token has been defined, deduced location overriding recovery email is still a big wtf that should stop.
Public shame (awareness) is perhaps half of the reason, not trying super hard here otherwise I'd pick better time of submission etc :) The other half is amusement, and perhaps hoping some security SME would talk about nuances that I don't know I don't know.