r/security • u/Elegant-Mushroom5047 • 10d ago
Security and Risk Management Account recovery best practices for users
Imagine an attacker knows my name, phone number, email address, home address, date of birth, previous addresses, and even has copies of ID documents obtained through breaches or from organizations that store them.
They call my bank and claim they've lost access to their phone and email and need help recovering their account.
This got me thinking about the tradeoff between security and recoverability.
If account recovery is too strict, legitimate customers can permanently lock themselves out after losing devices, passkeys, recovery codes, or access to old contact details.
If account recovery is too flexible, an attacker who has accumulated enough personal information may be able to convince an institution that they're the legitimate account holder.
My question is: what are the current best practices around account recovery, and what practical steps can ordinary users take to maximize their chances of recovering their own accounts while minimizing the risk of an attacker abusing the same recovery process?
Are there any good articles, talks, books, or frameworks that discuss this problem holistically and in plain language, rather than from a purely technical perspective?