Two-factor authentication and passkeys
Your account has no email address, and that cuts both ways.
- For you
- There is no password reset.
- For an attacker
- There is no recover-by-email path either.
The password is the only thing standing between someone and your account, so a second factor is worth the two minutes.
Authenticator app (TOTP)
Settings → Sign-in → Set up
-
01
Scan the QR code with any authenticator app.
-
02
Enter one code to confirm the clock agrees.
-
03
Save the recovery codes. They are shown exactly once and are not recoverable afterwards, because they are stored hashed, so nobody here can read them back to you.
- A recovery code
- Each one works once. A code you have used is spent.
- A login code
- The same six digits cannot be replayed inside their thirty-second window, even by someone who watched you type it.
Passkeys
Settings → Sign-in → Add a passkey
Your device's own unlock (fingerprint, face, or PIN) becomes the login.
Nothing typeable is exchanged.
That is what makes a passkey resistant to phishing in a way a code is not.
Register more than one if you can: a laptop and a phone, say.
- Laptop
- Phone
A passkey lives on the device that made it, and a single passkey plus a lost device is a bad afternoon.
No SMS, no email
Neither is offered, and that is deliberate. Both are recoverable by someone who controls the phone number or the mailbox, which would quietly undo the reason this account has no email address in the first place.