Instead of a friend's email, why not have a second email address of yourself where the PIN is sent. Of course, hopefully the passwords of both emails are different :). Sort of like ATM card and PIN sent in separate mails in the US. I don't think adding a friend's email will be a good idea especially if i want to reset in the middle of the night as someone mentioned.
I think "no password reuse" is an over-optimistic pipe dream for most users; also, it's unlikely that two people will be compromised at once by the same (not specifically targeted) attack; a compromise of all accounts of the same person is much more likely.
Indeed - that is exactly what went wrong in the case of our unfortunate Wired reporter.
Also, there's a big chance of course that if someone has lost the password to a services he uses more or less regularly, he'll also not be able to remember the password of a service (the secondary mail account) he uses almost never ...
Comments
Instead of a friend's email, why not have a second email address of yourself where the PIN is sent. Of course, hopefully the passwords of both emails are different :). Sort of like ATM card and PIN sent in separate mails in the US. I don't think adding a friend's email will be a good idea especially if i want to reset in the middle of the night as someone mentioned.
I think "no password reuse" is an over-optimistic pipe dream for most users; also, it's unlikely that two people will be compromised at once by the same (not specifically targeted) attack; a compromise of all accounts of the same person is much more likely.
Indeed - that is exactly what went wrong in the case of our unfortunate Wired reporter.
Also, there's a big chance of course that if someone has lost the password to a services he uses more or less regularly, he'll also not be able to remember the password of a service (the secondary mail account) he uses almost never ...