I think account recovery deserves the same threat-modeling as login. People retire a phone number, abandon a backup email, or leave a “contact support” route attached to an important account, then assume a strong password or passkey covers them. It doesn’t if recovery can bypass those protections. NIST calls authenticator recovery a weak point in many systems, and human-assisted recovery brings social-engineering risk.
I’m not arguing that recovery should disappear. Losing a phone, changing numbers, or losing credentials is ordinary, and removing every fallback can lock out the legitimate owner. But services should offer a visible recovery audit: which channels can reset access, when each was last used, and what level of trust it carries. A stale number should be hard to ignore. How do you manage your own recovery setup, and where would you draw the line between security and usability?