Problem
Strong authentication often becomes weak at recovery time. The cryptographic ceremony can be excellent while the surrounding account lifecycle remains fragile.
Technical record
This project studies recovery pathways as first-class security surfaces: backup credentials, device loss, helpdesk flows, identity proofing, and user-visible failure modes.
Operational boundary
For deployed authentication systems, the real security boundary includes every path that gets a user back into the account.