The other two doorsA credential is only as strong as the day you replace it
Every credential has three moments: the day it is enrolled, the thousands of times it is used, and the day it is lost and replaced. Almost all the attention goes to the middle one.
If somebody can register a new authenticator from a session protected by nothing but a password, an attacker holding that password can register theirs — and now they have a phishing-resistant credential, issued by you. If the way back in after losing a phone is a security question, then that question is the real authentication method, because it is the one that will be attacked.
Both are journeys on the same canvas as the login, which is the point: they get designed, reviewed and versioned instead of being improvised once. And because identity verification is available as a step in the same flow, proving the actual person — document plus liveness — is on the table: the strongest answer there is to "I have lost the only thing that identified me".
- Enrol a second credential while the user is already proven, not after they are locked out
- Never let the recovery path be weaker than the login path it restores
- When no credential is left, verify the person with a document and a liveness check rather than asking what they remember
- Administrator-issued codes that are single-use, time-boxed and logged