117 points by keymasta 3 days ago | 126 comments | View on ycombinator
ticulatedspline 3 days ago |
sampullman 3 days ago |
You can get a replacement SIM though and use it with a new phone, so the phone number recovery option should work.
mrj 3 days ago |
If I wake up in a bathtub missing a kidney I can still get to my passwords and 2fa sources stored with it. Some accounts require SMS (annoyingly) so I'd have to buy a phone but the auth and credit card numbers I need to do that are in Vaultwarden, too.
I don't have good solutions now for OP (other than buy a new phone through your carrier and transfer the number). But everyone else do think through your personal DRP. Generate backup codes and put them somewhere safe, too.
SoftTalker 3 days ago |
Consider it a learning experience.
joshmn 3 days ago |
We've all been reduced to a passphrase.
When I've lobbed this scenario to the security managers/employees at these companies, they all give me a really great answer:
Q: What happens if a sitting senator gets mugged and they have their printed 2fa codes sitting in their wallet?
A: They have a special number they can call.
beej71 3 days ago |
emaro 2 days ago |
happyopossum 3 days ago |
I'm sorry you're dealing with this - hopefully everyone else here can take it as a cautionary tale.
luka 3 days ago |
j1elo 3 days ago |
This kind of posts are a valuable trigger for all others who are reading it. To the author: good luck, I hope you sort your situation soon! I'm now headed to check my accounts for what recovery options I left in there.
splitwheel 3 days ago |
wccrawford 3 days ago |
That's already a lot and anything easier would allow people to just take over accounts that they don't have a right to.
karim79 2 days ago |
I got burned by Google authenticator in the past and had to jump through hoops to regain access to my accounts (non Google ones). It was painful. I learned the hard way I suppose.
runjake 3 days ago |
Other than that, I copy/pasted your post into Claude and it had some good ideas.
tamimio 3 days ago |
throw7 2 days ago |
"For your security, you can't call Google for help to sign into your account. We don’t work with any service that claims to provide account or password support. Do not give out your passwords or verification codes."
for the future: https://support.google.com/accounts/answer/7684753
TacticalCoder 2 days ago |
As a techie you should have known better: you first learn how 2FA using TOTP works. You understand what happens when you create an entry in Google Authenticator (or whatever app). You reproduce the procedure: you verify that you end up with the same 6-digit numbers.
If you've got a partner, you register your secret keys for each service on your partner's device and vice-versa.
Then you've got backups of your secret keys on paper, in a safe at your bank. Next to each secret key there's a checkbox: "Successfully initialized from this secret key?".
When those TOTP became ubiquitous (way, way, way before Yubikeys or passkeys were a thing), 2FA was a godsend compared to just passwords.
I understood they were here to stay for years, and years. And then more years.
So I learned how they worked.
When later on QR code generalized to initialize those (IIRC it wasn't a thing in the early days of 2FA TOTP: you'd just always get the secret key as characters, not as a QR code), I refused to ever scan a QR code: I always first decode the QR code (for the services only showing the secret key as a QR code, without also showing it as text), extract a copy of the secret key and then register it from my copy.
Stuff like that.
Now... As most services are deeply broken and have completely insecure practices you just say "I lost my 2FA, I want to reset it" and because they're clueless when it comes to security, they'll allow you to reset it. If someone hacks your email, they pretty much can reset every single of your account (at least those tied to that email).
jeroenhd 3 days ago |
Actually keeping your recovery options recent is the trick. Print out your recovery codes or store them somewhere safe. Check regularly (yearly, maybe more often) that there's a way to access your critical accounts.
For Google, you can also grab the cheapest Android phone you can find, sign in, and maybe boot it once a month or so to keep the tokens active.
If you've set up your account to only accept one source of 2FA and you lose thst source of 2FA, you lose your account. Same happens when you set up your account to only accept your password and then lose your password. If you lose your recovery email/2FA backup codes, you lose access, unless you're special enough to convince customer support that you are who you claim you are and not just a bot trying to hack you.
If you've lost your account and haven't set up any recovery mechanisms, you're probably out of luck. Your best bet will be looking for an old browser session with enough trust from Google's side to get access without reconfirming your 2FA trust.
SAI_Peregrinus 3 days ago |
Even if they had customer support, if that customer support had a backdoor to unlock your account it would be regularly used by malicious parties to steal people's accounts & data.
mococa 3 days ago |
stefan_ 3 days ago |
Using the iPhone backup to setup a new phone is a good reminder every time that not half of the stuff comes back correctly..
phildougherty 3 days ago |
thrownaway561 3 days ago |
bshaughn 2 days ago |
ifh-hn 2 days ago |
mqtx 3 days ago |
MotoriX 1 day ago |
lyfeninja 2 days ago |
autoexec 3 days ago |
Gengar 2 days ago |
xpct 1 day ago |
pards 3 days ago |
I use Proton Authenticator now [0]
Authy used to do this, then they enshittified their app and bricked the desktop version.
trinsic2 1 day ago |
adi_kurian 3 days ago |
protocolture 2 days ago |
After that we both created a set of one time codes and stored them offline.
sharts 1 day ago |
haellsigh 3 days ago |
ezfe 3 days ago |
mixmastamyk 3 days ago |
tonymet 3 days ago |
I would send a paper letter to the Google legal contact. It's the only way to get escalated support.
I agree the covenant for account recovery has been broken. Every 6 months, a new artifact is expected to access the account, without adequate preparation for the recovery.
flerchin 2 days ago |
Apreche 3 days ago |
ck2 3 days ago |
your only hope to get your google account back is to convince your phone carrier to transfer your old phone number to a new phone that you control
cute_boi 2 days ago |
Google Employee, can you please fix your shit? Losing phone number doesn't mean you have to lose everything....
vasemkhan328 2 days ago |
anothereng 2 days ago |
dailyfreetools about 23 hours ago |
laurennorthwood 3 days ago |
Transformanshen 1 day ago |
agentwang 2 days ago |
xyst 2 days ago |
call sergey brin \s
pholypilz 2 days ago |
> once you're phone is gone, you are completely over with society?
yes, I'm waiting for the Black-Mirror episode where someone drops their phone and basically dies, can't contact anyone, can't unlock or start their car, can't get an uber, can't pay for anything, can't navigate without gps, can't log into anything etc.