If there is a way to recover it, that has to be secured too and, there are only a limited number of ways you can do that (and the more that are enabled, the harder it is to secure). Most services with 2FA offer a set of one-time codes that you can write down and store securely at multiple locations (safes in different places, safe deposit box etc). It is not that hard to avoid losing access if you care. If you don't care enough about the account to do this, just accept losing access, cancel the card payment authorisation and, lose it.
Companies should not grant access to accounts with 2FA by letting you call support unless they at least take proper steps to ensure that you are the account owner, which is pretty impractical in most cases (it is either too costly to be worth it or, too hard to do well enough). Demonstrating that you are the account owner to recover it if you have lost 2FA access should at least require a visit, in person, with photo ID being checked with the relevant authorities (for example the passport service examining your passport to check it is not a forgery) and, multiple people who can attest that you are in fact the person in the photo, to recover an account, for which they would presumably have to charge hundreds of dollars. It seems easier to just not offer recovery in most cases.
This guy works in customer service. LOL
If you're sending me a bill, you need to provide a way for me to resolve an issue such as this. "There is not a resolution possible, we will continue billing you in perpetuity thank you good day" is not acceptable. (It's AWS and they do, so maybe it is, but... try building a new service that isn't AWS with that attitude, and see how far it gets you!)
My cloud-hosted business gets shut down, credit score tanks, because of the combination of my butter fingers and your secure authentication scheme! Might as well not employ any CSR drones at all if you're not going to handle this case. Maybe I'm exaggerating, but this is not a great strategy for customer satisfaction or retention.
To the extent that in a dispute situation, who pays the bill =/= whomever holds the keys, my preferred customer service strategy would tend to favor who is paying the bill.
I could see the argument either way on if this is the most optimal solution or not.
not if you want it to provide real security.
I do business with 4 banks and have no less than 4 credit cards, and I'm pretty sure that none of them offer proper 2FA with tokens for the online accounts. Now that you mention it, this is a serious question. Why does Comcast get there before any of the major and/or local banks?
I'll admit, if I can protect my Comcast account and as a result, I never have to speak to another one of their Customer Service Reps, it would be a huge victory! This is probably part of their retention strategy, to be fair.
It's telling that there's no mention of on any document, or interface to Comcast's 2FA settings (that I can find anyway) that speaks to how to use it for protecting the set-top box from ordering Pay-Per-View content.
If I turn on 2FA, I'm pretty sure I won't have the option to use it when ordering PPV. It looks like they have a PIN lock instead. Maybe I can disable PPV and protect it with the second factor?
I honestly have no idea why it's even an option. Are swatters gonna log into my Comcast account, upgrade my XFINITY connection to the maximum bandwidth, and sign me up for all of the premium channels?
Or are they hacking my account so they can pay the bill for me :-D