upvote
Completely unrealistic. Stuff happens. Email accounts get closed for no reason. People lose their phones, or have them stolen. Lots of reasons why someone might need an exceptional account recovery process.

Not saying it should be easy or routine, it should not be. But it must be possible.

reply
That's what recovery codes are for. Unfortunately it seems a lot of 2FA is now implemented without recovery codes.
reply
I suspect very few people have good management of recovery codes.

I just save them in my password manager.

As best as I can tell, everyone I work with simply doesn't save them at all and initiates a password reset if they lose their password/2FA.

reply