What are Recovery Codes?
When you set up two-factor authentication (2FA), you are usually given a set of backup or recovery codes. These are high-value credentials. If you lose your phone or security key, these codes are the only way back into your account.
Long-Term Storage
Hush is for temporary transmission, not long-term storage. For long-term storage, a dedicated password manager configured with strong master passwords and 2FA is generally appropriate.
While storing codes in a text file or taking a screenshot might seem convenient, cloud-synced notes and photo libraries can inadvertently create extra copies of these codes across multiple devices. While cloud storage isn't automatically unsafe, it increases the risk that an old, forgotten copy could be compromised in a breach.
Emergency Sharing and Out-of-Band Passphrases
If you need to share a set of codes with a spouse or business partner in an emergency, do not send them in a plain email or text message where they will sit in the chat history permanently.
Instead, use a one-time encrypted link via Hush. To add an extra layer of security, use Out-of-Band (OOB) sharing: 1. Add a passphrase to the Hush link. 2. Send the Hush link via one communication channel (e.g., email). 3. Send the passphrase via a completely different channel (e.g., a phone call or SMS).
Know the Limits
When sharing recovery codes via Hush, understand the honest limits: - No Guaranteed Recovery: Sending a code does not guarantee account recovery if the recipient loses the link or the service itself has other recovery policies. - Expiry: The link will expire. - Interception: If someone intercepts the link (and passphrase) and opens it first, the intended recipient will not be able to view it. - Screenshots: The recipient can still take a screenshot or copy the codes once revealed. - Compromised Devices: Malware on the recipient's device can capture the codes.