They are one-time only (that's why you get 10), but are not time sensitive (like those generated by app/token) so they are longer.
They are one-time only (that's why you get 10), but are not time sensitive (like those generated by app/token) so they are longer.
What other failure mode is there? A solution that's considered to be actually perfect? Regardless, you have to account for Godel.
The correct mode of operation is to always be prepared, without relying on the "perfect" system too much. If system is actually good, "chaos monkeys" may be employed to keep everybody prepared.
It's important to remember that availability is an important aspect of security. If you protect a user primarily concerned with mass-account takeover attacks from a low-probability threat (people intercepting their SMS channel) but introduce a high-probability threat (dropping their phone in the toilet and being locked out of their account forever) you may not have made a good security tradeoff.