Whether you can, not whether you meant to
The condition is conditional, and the conditional matters. If a second factor is switched on for the account, then at some arbitrary future moment, at whatever machine you happen to be sitting at, you have to be able to produce the value it asks for. If nothing is switched on, the condition is satisfied by default. So the card is not about whether to enable anything. It is about the gap between deciding to enable it and being able to answer it later.
Switching a factor on is an act of intent that takes a moment. Producing it later is a capability that has to survive everything in between: a machine going away, an application replaced by an update, a device wiped, a file lost with the folder around it. Intent is free and immediate. Capability is a claim about the future, and it is the only one of the two that ever gets tested.
This is why enabling a factor you cannot reproduce is worse than not enabling one. It converts a probability into a certainty. Without it there is some chance somebody with the password gets in, and a fair chance nobody tries. With a factor you cannot reproduce there is no chance that you get in once the current session ends.
What the account has to be before a factor is worth enrolling
One card sits above this one: The account name is used nowhere else. Enrolment binds the factor to a specific account, and the account is identified by its name, so the name is what the enrolment hangs on. Enrol against a handle you will have to abandon and the enrolment goes with it, leaving the whole decision to be taken again on a fresh registration.
The second run is where the damage usually happens. You are repeating work, you have less patience for a setup screen, and you take whatever the form offers rather than the thing you can still produce in a month. A rushed second enrolment is a common route into a lockout, and it starts several cards upstream with a carelessly chosen name. Distances like that are what the Dependency map makes visible.
If nothing has been enrolled, this condition is true now and stays true while you leave it alone. It becomes capable of failing at the moment you switch something on, which is worth knowing before you switch it on.
What an unproducible factor stops
Directly downstream there is one card, You can log in a second time, and this is one of the three parts it is made of. The failure is unusually clean. A missing factor does not make logging in harder, it makes it impossible, and it does so at the point where you have already proved everything else. You will have the address, the name, and the password out of the store described in The password exists somewhere outside your head. The form takes all of it and then asks for the one thing you cannot supply.
| Cannot hold | The reason it cannot |
|---|---|
| You can log in a second time | The prompt arrives after the password has been accepted. Everything else being correct does not shorten the distance to a value you cannot generate, and there is no route around the prompt. |
| The deposit address came from the session you are in | It requires an address produced by a session you are inside. Without one, the only candidates are stored addresses from before, which is the substitution that card exists to rule out. |
| The other side answered before you spent anything | Asking and reading a reply both happen inside the account. From outside there is no way to ask and no way to see whether anyone answered. |
| You can come back tomorrow and still be you | Coming back means reassembling the credential set. A factor tied to a machine that no longer exists is the piece that cannot be rebuilt from anything you kept. |
What makes this heavier than a lost password is that a password is your own doing at the moment of storage, and is prevented by writing something down. A factor is often unproducible for reasons with nothing to do with you: hardware failed, an application was replaced, a folder went. The card asks you to assume that rather than hope otherwise.
There is a second consequence people do not expect. A factor you can only produce on one machine quietly reintroduces the problem that Losing the device does not lose the account exists to prevent. You may have moved the password off the machine and left the factor sitting on it, in which case the account still dies with the hardware.
A lockout caused by a factor is as final as a lost password. No desk can switch it off for you, because the mechanism cannot tell you from anybody else claiming to be you.
How the lockout arrives
It arrives on an ordinary day, in the middle of something else. You open the login, the name and the password go in, and they are accepted. Then a field appears asking for a value. The machine that generated it is not in front of you, or it is and no longer has the application. There is no error to read, because from the form's point of view nothing has gone wrong. It asked a question and you do not have the answer.
The next minutes are spent in the wrong place. People search for a file, then reinstall something in the hope that reinstalling restores state, which it does not, and the reinstall sometimes destroys the last remnant that would have helped. Then they look for a contact route, and there is not one. The confusion lands on the market, the address or the browser, and none of those is involved.
The deliberate logout, and what a pass looks like
Do the test while you are still inside and nothing depends on the answer. Produce the current value now, from the material you would still have if the machine in front of you disappeared this evening. Not from an open page. Then log out on purpose and come back in using only that material. A pass is that you produced the value without touching anything you would lose. A fail has several shapes and they count equally: the generator exists only on the machine you are testing from, the codes offered at enrolment were never saved, or it works today only because nothing has been restarted yet. Untested is a fail as well.
Not an argument for or against turning it on
This card takes no position on whether a second factor is worth having. It says the enabling decision and the producing decision are different, and that only the first is presented to you as a decision. The condition people fold into it is the stored password, which is a copy you retrieve. This one is an answer you generate, and a stored password does nothing for a prompt that wants something else.