If MFA is turned Off, where are the backup shares stored?

Hi,
I wanted to make MFA optional for users but had a couple of questions in scenarios where MFA is OFF/Optional:

  1. On App A, MFA is optional and skipped by a user, where is the 2nd and 3rd share stored and retrieved? Does web3auth store it in a custodial way?
  2. On App A, MFA is optional. When a user with MFA turned off, turns it on later, How is the key managed in this transition?
  3. If App A has MFA mandatory, and App B has MFA Off, and user who earlier used App A, logins to app B on a different device, will app B ask for MFA?


Originally posted by: ReclaimD

Check the discussion at: https://github.com/orgs/Web3Auth/discussions/782