This phone verification shit is so awful. I have two friends who moved overseas and disconnected their cellphone plans without thinking about their MFA situation. Today I have to enforce MFA at the small company I'm working at, and just a month prior I held a cybersecurity seminar for them and explained that "phone MFA is… okay… but you should really use verification apps." But I didn't realize that you can't even en…
So I have used Authy, which apparently is somehow protocol compatible with Google Authenticator, and you can back up your tokens with a password. I got a new phone, installed the app, entered the password, and all my tokens were there.
Nothing mysterious. Authy and Google Authenticator simply implement the same standard, RFC 6238.